Home › Microsoft Patch Tuesday › September 2024

Microsoft Patch Tuesday, September 2024

·

Microsoft's September 2024 security release, published September 10, 2024: 45 updates fixing 71 CVEs, ranked by confirmed exploitation, ransomware use, and severity. Provided by Senserva.

45
Updates (KBs)
71
CVEs fixed
4
On the CISA KEV list
1
Critical updates

Actively exploited CVEs (CISA KEV)

CVE-2024-38014Microsoft Windows Installer Improper Privilege Management VulnerabilityExploited
CVE-2024-38217Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure VulnerabilityExploited
CVE-2024-43461Microsoft Windows MSHTML Platform Spoofing VulnerabilityExploited
CVE-2024-38226Microsoft Publisher Protection Mechanism Failure VulnerabilityExploited

Other high-risk CVEs (CVSS 8.8+)

CVE-2024-43491Microsoft Windows Update Remote Code Execution VulnerabilityCVSS 9.8
CVE-2024-38260Windows Remote Desktop Licensing Service Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-43455Windows Remote Desktop Licensing Service Spoofing VulnerabilityCVSS 8.8
CVE-2024-38259Microsoft Management Console Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-38018Microsoft SharePoint Server Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-37338Microsoft SQL Server Native Scoring Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-37335Microsoft SQL Server Native Scoring Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-37340Microsoft SQL Server Native Scoring Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-37339Microsoft SQL Server Native Scoring Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-26186Microsoft SQL Server Native Scoring Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-26191Microsoft SQL Server Native Scoring Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-37965Microsoft SQL Server Elevation of Privilege VulnerabilityCVSS 8.8

Products fixed this month

Windows Server 2008 R2 for x64-based Systems Service Pack 1 (3)Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) (3)Windows Server 2022 (2)Windows Server 2022 (Server Core installation) (2)Windows Server 2022, 23H2 Edition (Server Core installation) (2)Windows Server 2008 for 32-bit Systems Service Pack 2 (2)Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) (2)Windows Server 2008 for x64-based Systems Service Pack 2 (2)Windows Server 2012 (2)Windows 11 Version 22H2 for ARM64-based Systems (2)

Every update in this release

All 45 update articles, worst first: anything on the CISA KEV list, then by highest CVSS. Each row links our page for the update, Microsoft's support article, and the Update Catalog for a standalone download.

UpdateSeverityMax CVSSCVEs fixedProductsAlso
KB5043083 ExploitedCritical9.824Windows 10 for 32-bit Systems, Windows 10 for x64-based SystemsSupport · Catalog
KB5043050 ExploitedHigh8.836Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1809 for 32-bit SystemsSupport · Catalog
KB5042881 ExploitedHigh8.837Windows Server 2022, Windows Server 2022 (Server Core installation)Support · Catalog
KB5042880 ExploitedHigh8.837Windows Server 2022, Windows Server 2022 (Server Core installation)Support · Catalog
KB5043051 ExploitedHigh8.837Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 10 Version 1607 for 32-bit SystemsSupport · Catalog
KB5043138 ExploitedHigh8.822Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)Support · Catalog
KB5043055 ExploitedHigh8.837Windows Server 2022, 23H2 Edition (Server Core installation)Support · Catalog
KB5043135 ExploitedHigh8.818Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2Support · Catalog
KB5043087 ExploitedHigh8.818Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2Support · Catalog
KB5043092 ExploitedHigh8.819Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Support · Catalog
KB5043125 ExploitedHigh8.820Windows Server 2012, Windows Server 2012 (Server Core installation)Support · Catalog
KB5043067 ExploitedHigh8.829Windows 11 version 21H2 for x64-based Systems, Windows 11 version 21H2 for ARM64-based SystemsSupport · Catalog
KB5043064 ExploitedHigh8.829Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based SystemsSupport · Catalog
KB5043076 ExploitedHigh8.829Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based SystemsSupport · Catalog
KB5043080 ExploitedHigh8.828Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based SystemsSupport · Catalog
KB5043049 ExploitedHigh8.82Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Windows Server 2012Support · Catalog
KB5043129 ExploitedHigh8.818Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Support · Catalog
KB5002566 ExploitedHigh7.31Microsoft Publisher 2016 (32-bit edition), Microsoft Publisher 2016 (64-bit edition)Support · Catalog
KB5002624High8.85Microsoft SharePoint Enterprise Server 2016Support · Catalog
KB5002639High8.85Microsoft SharePoint Server 2019Support · Catalog
KB5002640High8.85Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5042217High8.812Microsoft SQL Server 2017 for x64-based Systems (GDR)Support · Catalog
KB5042214High8.812Microsoft SQL Server 2019 for x64-based Systems (GDR)Support · Catalog
KB5042215High8.812Microsoft SQL Server 2017 for x64-based Systems (CU 31)Support · Catalog
KB5042211High8.811Microsoft SQL Server 2022 for x64-based Systems (GDR)Support · Catalog
KB5042749High8.811Microsoft SQL Server 2019 for x64-based Systems (CU 28)Support · Catalog
KB5042578High8.811Microsoft SQL Server 2022 for x64-based Systems (CU 14)Support · Catalog
KB5042207High8.82Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)Support · Catalog
KB5042209High8.82Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature PackSupport · Catalog
KB5046058High8.81Microsoft SQL Server 2017 for x64-based Systems (GDR)Support · Catalog
KB5046056High8.81Microsoft SQL Server 2019 for x64-based Systems (GDR)Support · Catalog
KB5046063High8.81Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)Support · Catalog
KB5046061High8.81Microsoft SQL Server 2017 for x64-based Systems (CU 31)Support · Catalog
KB5046057High8.81Microsoft SQL Server 2022 for x64-based Systems (GDR)Support · Catalog
KB5046059High8.81Microsoft SQL Server 2022 for x64-based Systems (CU 15)Support · Catalog
KB5046060High8.81Microsoft SQL Server 2019 for x64-based Systems (CU 28)Support · Catalog
KB5042528High8.81Microsoft Dynamics 365 Business Central 2023 Release Wave 1Support · Catalog
KB5042529High8.81Microsoft Dynamics 365 Business Central 2024 Release Wave 1Support · Catalog
KB5042530High8.81Microsoft Dynamics 365 Business Central 2023 Release Wave 2Support · Catalog
KB5002634High7.82Microsoft Visio 2016 (32-bit edition), Microsoft Visio 2016 (64-bit edition)Support · Catalog
KB5002601High7.81Microsoft Office Online ServerSupport · Catalog
KB5002605High7.81Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)Support · Catalog
KB5043254High7.61Microsoft Dynamics 365 (on-premises) version 9.1Support · Catalog
KB5040442High7.31Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems, Windows 11 Version 23H2 for x64-based SystemsSupport · Catalog
KB5040438High7.31Windows Server 2022, 23H2 Edition (Server Core installation)Support · Catalog
Take this release to your AI

Composed from the September 2024 release data above. Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Now see your own patch state.

Senserva reads your Microsoft 365, Intune, Defender, and Entra ID environment and turns this release into your list: every update still missing, on every device, ranked by what attackers are actually exploiting. The 650+ configuration checks come with it.

1Find it2Fix it3Prove it
Start my free patch auditAll you do is register.
Reference: Microsoft CVE and vulnerability management, ranked by real-world risk, and the Microsoft patching guide.
Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative Microsoft advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.