Home › Microsoft Patch Tuesday › October 2024

Microsoft Patch Tuesday, October 2024

·

Microsoft's October 2024 security release, published October 8, 2024: 45 updates fixing 103 CVEs, ranked by confirmed exploitation, ransomware use, and severity. Provided by Senserva.

Still active now. 1 CVE from this release is on the Senserva hot list today (as of 2026-10-08), still ranked among the most dangerous vulnerabilities right now by confirmed exploitation, ransomware use, EPSS, and severity. See the current hot list.
45
Updates (KBs)
103
CVEs fixed
3
On the CISA KEV list
1
Ransomware-linked
10
Critical updates

Actively exploited CVEs (CISA KEV)

CVE-2024-43468Microsoft Configuration Manager SQL Injection VulnerabilityExploited Hot now
CVE-2024-43573Microsoft Windows MSHTML Platform Spoofing VulnerabilityExploited
CVE-2024-43572Microsoft Windows Management Console Remote Code Execution VulnerabilityExploited

Other high-risk CVEs (CVSS 8.8+)

CVE-2024-38124Windows Netlogon Elevation of Privilege VulnerabilityCVSS 9.0
CVE-2024-43518Windows Telephony Server Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-43519Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-43532Remote Registry Service Elevation of Privilege VulnerabilityCVSS 8.8
CVE-2024-6197Hackerone: CVE-2024-6197 Freeing stack buffer in utf8asn1strCVSS 8.8
CVE-2024-43608Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-43607Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-38265Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-43453Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-38212Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-43517Microsoft ActiveX Data Objects Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-43549Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8

Products fixed this month

Windows Server 2022 (2)Windows Server 2022 (Server Core installation) (2)Windows Server 2022, 23H2 Edition (Server Core installation) (2)Windows Server 2008 for 32-bit Systems Service Pack 2 (2)Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) (2)Windows Server 2008 for x64-based Systems Service Pack 2 (2)Windows Server 2008 R2 for x64-based Systems Service Pack 1 (2)Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) (2)Windows 10 Version 21H2 for 32-bit Systems (2)Windows 10 Version 21H2 for x64-based Systems (2)

Every update in this release

All 43 update articles, worst first: anything on the CISA KEV list, then by highest CVSS. Each row links our page for the update, Microsoft's support article, and the Update Catalog for a standalone download.

UpdateSeverityMax CVSSCVEs fixedProductsAlso
KB29166583 ExploitedCritical9.81Microsoft Configuration Manager 2303, Microsoft Configuration Manager 2309, Microsoft Configuration Manager 2403Support · Catalog
KB5044277 ExploitedCritical9.077Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1809 for 32-bit SystemsSupport · Catalog
KB5044281 ExploitedCritical9.065Windows Server 2022, Windows Server 2022 (Server Core installation)Support · Catalog
KB5044288 ExploitedCritical9.083Windows Server 2022, 23H2 Edition (Server Core installation)Support · Catalog
KB5044293 ExploitedCritical9.056Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 10 Version 1607 for 32-bit SystemsSupport · Catalog
KB5044320 ExploitedCritical9.032Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2Support · Catalog
KB5044306 ExploitedCritical9.032Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2Support · Catalog
KB5044356 ExploitedCritical9.036Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Support · Catalog
KB5044321 ExploitedCritical9.036Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Support · Catalog
KB5044342 ExploitedCritical9.046Windows Server 2012, Windows Server 2012 (Server Core installation)Support · Catalog
KB5044343 ExploitedCritical9.049Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)Support · Catalog
KB5044273 ExploitedHigh8.856Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based SystemsSupport · Catalog
KB5044280 ExploitedHigh8.861Windows 11 version 21H2 for x64-based Systems, Windows 11 version 21H2 for ARM64-based SystemsSupport · Catalog
KB5044285 ExploitedHigh8.862Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based SystemsSupport · Catalog
KB5044284 ExploitedHigh8.863Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based SystemsSupport · Catalog
KB5044286 ExploitedHigh8.833Windows 10 for 32-bit Systems, Windows 10 for x64-based Systems, Microsoft .NET Framework 4.6/4.6.2 on Windows 10 for 32-bit SystemsSupport · Catalog
KB5045993High8.14.NET 8.0 installed on Windows, .NET 8.0 installed on Linux, .NET 8.0 installed on Mac OSSupport · Catalog
KB5002643High7.81Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)Support · Catalog
KB5002645High7.81Microsoft SharePoint Enterprise Server 2016Support · Catalog
KB5002647High7.81Microsoft SharePoint Server 2019Support · Catalog
KB5002649High7.81Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5047621High7.83Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based SystemsSupport · Catalog
KB5045998High7.53.NET 6.0 installed on Linux, .NET 6.0 installed on Windows, .NET 6.0 installed on Mac OSSupport · Catalog
KB5044021High7.52Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016Support · Catalog
KB5044095High7.52Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1, Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1Support · Catalog
KB5044085High7.52Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1, Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1Support · Catalog
KB5044096High7.52Microsoft .NET Framework 4.8 on Windows Server 2012, Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation), Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012Support · Catalog
KB5044097High7.52Microsoft .NET Framework 4.8 on Windows Server 2012 R2, Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation), Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2Support · Catalog
KB5044089High7.52Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019Support · Catalog
KB5044099High7.52Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022 (Server Core installation), Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022Support · Catalog
KB5044092High7.52Microsoft .NET Framework 3.5 AND 4.8 on Windows 11 version 21H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 11 version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 version 21H2 for x64-based SystemsSupport · Catalog
KB5044090High7.52Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based SystemsSupport · Catalog
KB5044091High7.52Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for 32-bit SystemsSupport · Catalog
KB5044033High7.52Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 22H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 22H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for ARM64-based SystemsSupport · Catalog
KB5044028High7.52Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022, 23H2 Edition (Server Core installation)Support · Catalog
KB5044098High7.52Microsoft .NET Framework 4.6.2 on Windows Server 2008 for 32-bit Systems Service Pack 2, Microsoft .NET Framework 4.6.2 on Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Microsoft .NET Framework 4.6.2 on Windows Server 2008 for x64-based Systems Service Pack 2Support · Catalog
KB5044086High7.52Microsoft .NET Framework 4.6.2 on Windows Server 2008 for 32-bit Systems Service Pack 2, Microsoft .NET Framework 4.6.2 on Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Microsoft .NET Framework 4.6.2 on Windows Server 2008 for x64-based Systems Service Pack 2Support · Catalog
KB5044030High7.52Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for x64-based SystemsSupport · Catalog
KB5002635Medium6.51Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)Support · Catalog
KB5046399Medium6.41Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation)Support · Catalog
KB5046398Medium6.41Windows 11 version 21H2 for x64-based Systems, Windows 11 version 21H2 for ARM64-based SystemsSupport · Catalog
KB5046400Medium6.41Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based SystemsSupport · Catalog
KB5045536Medium5.51Microsoft Visual Studio 2015 Update 3Support · Catalog
Take this release to your AI

Composed from the October 2024 release data above. Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Now see your own patch state.

Senserva reads your Microsoft 365, Intune, Defender, and Entra ID environment and turns this release into your list: every update still missing, on every device, ranked by what attackers are actually exploiting. The 650+ configuration checks come with it.

1Find it2Fix it3Prove it
Start my free patch auditAll you do is register.
Reference: Microsoft CVE and vulnerability management, ranked by real-world risk, and the Microsoft patching guide.
Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative Microsoft advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.