
Microsoft patched 149 CVEs in its April 2024 Patch Tuesday release, with three rated critical, 142 rated as important, and two rated as moderate. 2 of the Zeroday vulnerabilities are fixed in this release.
- 31 Elevation of Privilege Vulnerabilities
- 28 Security Feature Bypass Vulnerabilities
- 67 Remote Code Execution Vulnerabilities
- 13 Information Disclosure Vulnerabilities
- 7 Denial of Service Vulnerabilities
- 3 Spoofing Vulnerabilities
SmartScreen Prompt Security Feature Bypass Vulnerability
CVE-2024-29988 with a CVSSv3 score of 8.8, is a security feature bypass vulnerability in Microsoft Defender SmartScreen. An attacker could exploit this vulnerability by convincing a target to open a specially crafted file using social engineering tactics such as an external link or malicious attachment sent over email, instant messages, or social media.
This flaw was reported to Microsoft by some of the same researchers that disclosed CVE-2024-21412, an Internet Shortcut Files security feature bypass that was associated with a DarkGate campaign using fake installer files impersonating Apple iTunes, Notion, NVIDIA, and others.
CVE-2024-29988 is a bypass for the CVE-2024-21412 flaw and was reported by Peter Girnus of Trend Micro’s Zero Day Initiative and Google’s Threat Analysis Group Dmitrij Lenz and Vlad Stolyarov. CVE-2024-21412 was itself a bypass for another Defender SmartScreen vulnerability tracked as CVE-2023-36025, patched during the November 2023 Patch Tuesday and exploited as a zero-day to drop Phemedrone malware.
Proxy Driver Spoofing Vulnerability
CVE-2024-26234 with a CVSSv3 score of 8.8, described as a proxy driver spoofing vulnerability, was issued to track a malicious driver signed using a valid Microsoft Hardware Publisher Certificate that was found by Sophos X-Ops in December 2023 and reported by team lead Christopher Budd.
This malicious file was labeled as “Catalog Authentication Client Service” by “Catalog Thales,” likely an attempt to impersonate Thales Group. However, further investigation revealed that it was previously bundled with a marketing software called LaiXi Android Screen Mirroring.
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
CVE-2024-29990 with a CVSSv3 score of 9.0, is an EoP vulnerability in the Azure Kubernetes Service Confidential Containers (AKSCC). Exploitation of this flaw hinges on the preparation of a target environment by an attacker. Successful exploitation would enable an attacker to “steal credentials and affect resources beyond the security scope managed by AKSCC.” This includes taking over both “confidential guests and containers beyond the network stack it might be bound to.”
Microsoft ODBC Driver, WDAC OLE DB Driver and OLE DB Driver for SQL Server Remote Code Execution Vulnerability
There are 41 CVEs affecting multiple drivers for SQL Server, the Open Database Connectivity (ODBC) driver, WDAC OLE DB Driver and OLE DB driver. All were rated as Exploitation Less Likely according to the Microsoft Exploitability Index, with none being publicly disclosed or exploited in the wild. A full list of the CVEs is included in the table below.
Secure Boot Security Feature Bypass Vulnerability
Microsoft patched 24 CVEs in Windows Secure Boot during this month release. All are rated as Exploitation Less Likely. A full list of the CVEs is included in the table below.
Patch Tuesday Summary
| CVE Title | CVE ID | Severity |
| Microsoft Defender for IoT Remote Code Execution Vulnerability | CVE-2024-29053 | Critical |
| Microsoft Defender for IoT Remote Code Execution Vulnerability | CVE-2024-21323 | Critical |
| Microsoft Defender for IoT Remote Code Execution Vulnerability | CVE-2024-21322 | Critical |
| .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | CVE-2024-21409 | Important |
| Azure CycleCloud Elevation of Privilege Vulnerability | CVE-2024-29993 | Important |
| Azure AI Search Information Disclosure Vulnerability | CVE-2024-29063 | Important |
| Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability | CVE-2024-28917 | Important |
| Azure Compute Gallery Elevation of Privilege Vulnerability | CVE-2024-21424 | Important |
| Azure Migrate Remote Code Execution Vulnerability | CVE-2024-26193 | Important |
| Azure Monitor Agent Elevation of Privilege Vulnerability | CVE-2024-29989 | Important |
| Intel: CVE-2024-2201 Branch History Injection | CVE-2024-2201 | Important |
| SmartScreen Prompt Security Feature Bypass Vulnerability | CVE-2024-29988 | Important |
| Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | CVE-2024-29990 | Important |
| Microsoft Brokering File System Elevation of Privilege Vulnerability | CVE-2024-28905 | Important |
| Microsoft Brokering File System Elevation of Privilege Vulnerability | CVE-2024-28907 | Important |
| Microsoft Brokering File System Elevation of Privilege Vulnerability | CVE-2024-26213 | Important |
| Microsoft Brokering File System Elevation of Privilege Vulnerability | CVE-2024-28904 | Important |
| Microsoft Defender for IoT Elevation of Privilege Vulnerability | CVE-2024-29055 | Important |
| Microsoft Defender for IoT Elevation of Privilege Vulnerability | CVE-2024-29054 | Important |
| Microsoft Defender for IoT Elevation of Privilege Vulnerability | CVE-2024-21324 | Important |
| Microsoft Install Service Elevation of Privilege Vulnerability | CVE-2024-26158 | Important |
| Microsoft Excel Remote Code Execution Vulnerability | CVE-2024-26257 | Important |
| Outlook for Windows Spoofing Vulnerability | CVE-2024-20670 | Important |
| Microsoft SharePoint Server Spoofing Vulnerability | CVE-2024-26251 | Important |
| Microsoft WDAC SQL Server ODBC Driver Remote Code Execution Vulnerability | CVE-2024-26214 | Important |
| Microsoft WDAC OLE DB Provider for SQL Server Remote Code Execution Vulnerability | CVE-2024-26244 | Important |
| Microsoft WDAC OLE DB Provider for SQL Server Remote Code Execution Vulnerability | CVE-2024-26210 | Important |
| Windows DNS Server Remote Code Execution Vulnerability | CVE-2024-26233 | Important |
| Windows DNS Server Remote Code Execution Vulnerability | CVE-2024-26231 | Important |
| Windows DNS Server Remote Code Execution Vulnerability | CVE-2024-26227 | Important |
| Windows DNS Server Remote Code Execution Vulnerability | CVE-2024-26223 | Important |
| Windows DNS Server Remote Code Execution Vulnerability | CVE-2024-26221 | Important |
| Windows DNS Server Remote Code Execution Vulnerability | CVE-2024-26224 | Important |
| Windows DNS Server Remote Code Execution Vulnerability | CVE-2024-26222 | Important |
| Windows Hyper-V Denial of Service Vulnerability | CVE-2024-29064 | Important |
| Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28937 | Important |
| Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28938 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-29044 | Important |
| Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28935 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28940 | Important |
| Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28943 | Important |
| Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28941 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28910 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28944 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28908 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28909 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-29985 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28906 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28926 | Important |
| Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28933 | Important |
| Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28934 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28927 | Important |
| Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28930 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-29046 | Important |
| Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28932 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-29047 | Important |
| Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28931 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-29984 | Important |
| Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28929 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28939 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28942 | Important |
| Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-29043 | Important |
| Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28936 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-29045 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28915 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28913 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28945 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-29048 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28912 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28914 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-29983 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-28911 | Important |
| Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | CVE-2024-29982 | Important |
| Windows Authentication Elevation of Privilege Vulnerability | CVE-2024-29056 | Important |
| Windows Authentication Elevation of Privilege Vulnerability | CVE-2024-21447 | Important |
| BitLocker Security Feature Bypass Vulnerability | CVE-2024-20665 | Important |
| libarchive Remote Code Execution Vulnerability | CVE-2024-26256 | Important |
| Windows Cryptographic Services Security Feature Bypass Vulnerability | CVE-2024-26228 | Important |
| Windows Cryptographic Services Remote Code Execution Vulnerability | CVE-2024-29050 | Important |
| Windows Defender Credential Guard Elevation of Privilege Vulnerability | CVE-2024-26237 | Important |
| DHCP Server Service Denial of Service Vulnerability | CVE-2024-26212 | Important |
| DHCP Server Service Denial of Service Vulnerability | CVE-2024-26215 | Important |
| DHCP Server Service Remote Code Execution Vulnerability | CVE-2024-26195 | Important |
| DHCP Server Service Remote Code Execution Vulnerability | CVE-2024-26202 | Important |
| Windows Distributed File System (DFS) Remote Code Execution Vulnerability | CVE-2024-29066 | Important |
| Windows Distributed File System (DFS) Information Disclosure Vulnerability | CVE-2024-26226 | Important |
| Windows DWM Core Library Information Disclosure Vulnerability | CVE-2024-26172 | Important |
| Windows File Server Resource Management Service Elevation of Privilege Vulnerability | CVE-2024-26216 | Important |
| HTTP.sys Denial of Service Vulnerability | CVE-2024-26219 | Important |
| Windows rndismp6.sys Remote Code Execution Vulnerability | CVE-2024-26253 | Important |
| Windows rndismp6.sys Remote Code Execution Vulnerability | CVE-2024-26252 | Important |
| Windows Kerberos Denial of Service Vulnerability | CVE-2024-26183 | Important |
| Windows Kerberos Elevation of Privilege Vulnerability | CVE-2024-26248 | Important |
| Windows Kernel Elevation of Privilege Vulnerability | CVE-2024-20693 | Important |
| Windows SMB Elevation of Privilege Vulnerability | CVE-2024-26245 | Important |
| Windows CSC Service Elevation of Privilege Vulnerability | CVE-2024-26229 | Important |
| Windows Kernel Elevation of Privilege Vulnerability | CVE-2024-26218 | Important |
| Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | CVE-2024-26209 | Important |
| Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | CVE-2024-26232 | Important |
| Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | CVE-2024-26208 | Important |
| Windows Mobile Hotspot Information Disclosure Vulnerability | CVE-2024-26220 | Important |
| Proxy Driver Spoofing Vulnerability | CVE-2024-26234 | Important |
| Windows Remote Access Connection Manager Information Disclosure Vulnerability | CVE-2024-28902 | Important |
| Windows Remote Access Connection Manager Information Disclosure Vulnerability | CVE-2024-28900 | Important |
| Windows Remote Access Connection Manager Information Disclosure Vulnerability | CVE-2024-28901 | Important |
| Windows Remote Access Connection Manager Information Disclosure Vulnerability | CVE-2024-26255 | Important |
| Windows Telephony Server Elevation of Privilege Vulnerability | CVE-2024-26230 | Important |
| Windows Telephony Server Elevation of Privilege Vulnerability | CVE-2024-26239 | Important |
| Windows Remote Access Connection Manager Information Disclosure Vulnerability | CVE-2024-26207 | Important |
| Windows Remote Access Connection Manager Information Disclosure Vulnerability | CVE-2024-26217 | Important |
| Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | CVE-2024-26211 | Important |
| Remote Procedure Call Runtime Remote Code Execution Vulnerability | CVE-2024-20678 | Important |
| Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | CVE-2024-26200 | Important |
| Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | CVE-2024-26179 | Important |
| Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | CVE-2024-26205 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-29061 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-28921 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-20689 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-26250 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-28922 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-29062 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-20669 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-28898 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-20688 | Important |
| Lenovo: CVE-2024-23593 Zero Out Boot Manager and drop to UEFI Shell | CVE-2024-23593 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-28896 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-28919 | Important |
| Lenovo: CVE-2024-23594 Stack Buffer Overflow in LenovoBT.efi | CVE-2024-23594 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-28923 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-28903 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-26189 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-26240 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-28924 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-28897 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-28925 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-26175 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-28920 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-26194 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-26180 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-26171 | Important |
| Secure Boot Security Feature Bypass Vulnerability | CVE-2024-26168 | Important |
| Windows Storage Elevation of Privilege Vulnerability | CVE-2024-29052 | Important |
| Windows Telephony Server Elevation of Privilege Vulnerability | CVE-2024-26242 | Important |
| Windows Update Stack Elevation of Privilege Vulnerability | CVE-2024-26236 | Important |
| Windows Update Stack Elevation of Privilege Vulnerability | CVE-2024-26235 | Important |
| Windows USB Print Driver Elevation of Privilege Vulnerability | CVE-2024-26243 | Important |
| Microsoft Virtual Machine Bus (VMBus) Denial of Service Vulnerability | CVE-2024-26254 | Important |
| Win32k Elevation of Privilege Vulnerability | CVE-2024-26241 | Important |
| Azure Private 5G Core Denial of Service Vulnerability | CVE-2024-20685 | Moderate |
| Azure Identity Library for .NET Information Disclosure Vulnerability | CVE-2024-29992 | Moderate |


