Microsoft has released its September 2024 Patch Tuesday updates, addressing a total of 79 vulnerabilities across various Microsoft products. This includes four zero-day vulnerabilities that were actively exploited and one that was publicly disclosed. The September 2024 Patch Tuesday updates aim to strengthen the security of Windows systems by patching critical and important vulnerabilities.
Microsoft’s September 2024 Patch Tuesday updates
Vulnerability breakdown
- Total vulnerabilities: 79
- Critical vulnerabilities: 6
- Important vulnerabilities: 71
- Zero-day vulnerabilities: 4
- Publicly disclosed vulnerabilities: 1
4 Zero-Day vulnerabilities
- CVE-2024-38014: Windows Installer Elevation of Privilege Vulnerability, allowing attackers to gain SYSTEM privileges on Windows systems.
- CVE-2024-38217: Windows Mark of the Web Security Feature Bypass Vulnerability, enabling attackers to bypass Smart App Control and Mark of the Web security warnings using a technique called LNK stomping.
- CVE-2024-38226: Microsoft Publisher Security Feature Bypass Vulnerability, allowing attackers to bypass Office macro policies used to block untrusted or malicious files.
- CVE-2024-43491: Microsoft Windows Update Remote Code Execution Vulnerability, a servicing stack flaw that allows remote code execution, primarily affecting Windows 10, version 1507, and certain LTSB editions.
Windows 11 and Windows 10 updates
- Windows 11 updates: KB5043076 for versions 23H2 and 22H2, and KB5043080 for version 24H2, which include various improvements and bug fixes, including:
-
- Android Devices in Windows Share: Enhanced sharing capabilities between Windows 11 and linked Android devices.
- Narrator: Faster response times for scan mode in Narrator.
- Voice Access: Enhanced dictation and editing capabilities.
- Widgets Board: New APIs for third-party developers to create widget feeds, with some existing widgets being removed or changed.
-
- Windows 10 updates: KB5043064 for version 22H2, which includes bug fixes, notably addressing a memory leak issue in Bluetooth devices.
Installation and download information
Automatic: Updates are installed automatically on non-managed Windows systems.
Manual: Users can manually check for updates via Windows Update or download updates from Microsoft’s download site.
Down the updates from the Microsoft Update Catalog for your PC:
- Windows 10 Version 22H2: KB5043064
- Windows 11 Version 22H2: KB5043076
- Windows 11 Version 23H2: KB5043076
- Windows 11 Version 24H2: KB5043080
The September 2024 Patch Tuesday updates underscore the importance of regular security updates in protecting Windows systems from potential threats. Users are advised to install these updates promptly to mitigate the risks associated with the patched vulnerabilities. The inclusion of additional features such as enhanced sharing capabilities with Android devices, improvements in Narrator and Voice Access, and updates to the Widgets Board further enhance the user experience. By staying updated with the latest September 2024 Patch Tuesday updates, users can ensure the security and functionality of their Windows 10 and Windows 11 systems.
Discover more from Microsoft News Today
Subscribe to get the latest posts sent to your email.