Home › Microsoft Patch Tuesday › November 2024

Microsoft Patch Tuesday, November 2024

·

Microsoft's November 2024 security release, published November 12, 2024: 35 updates fixing 78 CVEs, ranked by confirmed exploitation, ransomware use, and severity. Provided by Senserva.

Still active now. 1 CVE from this release is on the Senserva hot list today (as of 2026-10-08), still ranked among the most dangerous vulnerabilities right now by confirmed exploitation, ransomware use, EPSS, and severity. See the current hot list.
35
Updates (KBs)
78
CVEs fixed
2
On the CISA KEV list
1
Ransomware-linked
9
Critical updates

Actively exploited CVEs (CISA KEV)

CVE-2024-49039Windows Task Scheduler Elevation of Privilege VulnerabilityCVSS 8.8ExploitedRansomware Hot now
CVE-2024-43451NTLM Hash Disclosure Spoofing VulnerabilityCVSS 6.5Exploited

Other high-risk CVEs (CVSS 8.8+)

CVE-2024-43639Windows KDC Proxy Remote Code Execution VulnerabilityCVSS 9.8
CVE-2024-43627Windows Telephony Service Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-43628Windows Telephony Service Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-43620Windows Telephony Service Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-43621Windows Telephony Service Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-43622Windows Telephony Service Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-43624Windows Hyper-V Shared Virtual Disk Elevation of Privilege VulnerabilityCVSS 8.8
CVE-2024-43635Windows Telephony Service Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-38255SQL Server Native Client Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-43459SQL Server Native Client Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-43462SQL Server Native Client Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-48994SQL Server Native Client Remote Code Execution VulnerabilityCVSS 8.8

Products fixed this month

Windows Server 2008 for 32-bit Systems Service Pack 2 (3)Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) (3)Windows Server 2008 for x64-based Systems Service Pack 2 (3)Windows Server 2022 (2)Windows Server 2022 (Server Core installation) (2)Windows 11 Version 24H2 for ARM64-based Systems (2)Windows 11 Version 24H2 for x64-based Systems (2)Windows Server 2025 (2)Windows Server 2008 R2 for x64-based Systems Service Pack 1 (2)Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) (2)

Every update in this release

All 34 update articles, worst first: anything on the CISA KEV list, then by highest CVSS. Each row links our page for the update, Microsoft's support article, and the Update Catalog for a standalone download.

UpdateSeverityMax CVSSCVEs fixedProductsAlso
KB5046616 Exploited RansomwareCritical9.834Windows Server 2022, Windows Server 2022 (Server Core installation)Support · Catalog
KB5046698 Exploited RansomwareCritical9.834Windows Server 2022, Windows Server 2022 (Server Core installation)Support · Catalog
KB5046615 Exploited RansomwareCritical9.828Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5046618 Exploited RansomwareCritical9.832Windows Server 2022, 23H2 Edition (Server Core installation)Support · Catalog
KB5046617 Exploited RansomwareCritical9.833Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025Support · Catalog
KB5046696 Exploited RansomwareCritical9.833Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025Support · Catalog
KB5046612 Exploited RansomwareCritical9.825Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016Support · Catalog
KB5046682 ExploitedCritical9.822Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)Support · Catalog
KB5046613 Exploited RansomwareHigh8.828Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based SystemsSupport · Catalog
KB5046633 Exploited RansomwareHigh8.831Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based SystemsSupport · Catalog
KB5046665 Exploited RansomwareHigh8.821Windows 10 for 32-bit Systems, Windows 10 for x64-based SystemsSupport · Catalog
KB5046661 ExploitedHigh8.819Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2Support · Catalog
KB5046639 ExploitedHigh8.819Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2Support · Catalog
KB5046687 ExploitedHigh8.820Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Support · Catalog
KB5046705 ExploitedHigh8.820Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Support · Catalog
KB5046630 ExploitedMedium6.51Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2Support · Catalog
KB5046697Critical9.820Windows Server 2012, Windows Server 2012 (Server Core installation)Support · Catalog
KB5046857High8.831Microsoft SQL Server 2017 for x64-based Systems (GDR)Support · Catalog
KB5046859High8.831Microsoft SQL Server 2019 for x64-based Systems (GDR)Support · Catalog
KB5046855High8.830Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)Support · Catalog
KB5046856High8.830Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature PackSupport · Catalog
KB5046858High8.831Microsoft SQL Server 2017 for x64-based Systems (CU 31)Support · Catalog
KB5046860High8.831Microsoft SQL Server 2019 for x64-based Systems (CU 29)Support · Catalog
KB5046062High8.81Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature PackSupport · Catalog
KB5002648High7.81Microsoft Office Online ServerSupport · Catalog
KB5002653High7.85Microsoft Excel 2016 Click-to-Run (C2R) for 32-bit editions, Microsoft Excel 2016 Click-to-Run (C2R) for 64-bit editions, Microsoft Excel 2016 (32-bit edition)Support · Catalog
KB5002642High7.82Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)Support · Catalog
KB5046861High7.82Microsoft SQL Server 2022 for x64-based Systems (GDR)Support · Catalog
KB5046862High7.82Microsoft SQL Server 2022 for x64-based Systems (CU 15)Support · Catalog
KB5049233High7.51Microsoft Exchange Server 2019 Cumulative Update 13, Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server 2016 Cumulative Update 23Support · Catalog
KB5002619High7.51Microsoft Word 2016 (32-bit edition), Microsoft Word 2016 (64-bit edition)Support · Catalog
KB5002654High1Microsoft SharePoint Enterprise Server 2016Support · Catalog
KB5002650High1Microsoft SharePoint Server 2019Support · Catalog
KB5002651High1Microsoft SharePoint Server Subscription EditionSupport · Catalog
Take this release to your AI

Composed from the November 2024 release data above. Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Now see your own patch state.

Senserva reads your Microsoft 365, Intune, Defender, and Entra ID environment and turns this release into your list: every update still missing, on every device, ranked by what attackers are actually exploiting. The 650+ configuration checks come with it.

1Find it2Fix it3Prove it
Start my free patch auditAll you do is register.
Reference: Microsoft CVE and vulnerability management, ranked by real-world risk, and the Microsoft patching guide.
Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative Microsoft advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.