HomeMicrosoft Patch Tuesday › December 2024

Microsoft Patch Tuesday, December 2024

·

Microsoft's December 2024 security release, published December 10, 2024: 45 updates fixing 69 CVEs, ranked by confirmed exploitation, ransomware use, and severity. Provided by Senserva.

45
Updates (KBs)
69
CVEs fixed
1
On the CISA KEV list
23
Critical updates

Actively exploited CVEs (CISA KEV)

CVE-2024-49138Windows Common Log File System Driver Elevation of Privilege VulnerabilityCVSS 7.8Exploited

Other high-risk CVEs (CVSS 8.8+)

CVE-2024-49112Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityCVSS 9.8
CVE-2024-49085Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-49086Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-49102Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-49104Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-49125Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-49080Windows IP Routing Management Snapin Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-49117Windows Hyper-V Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-49093Windows Resilient File System (ReFS) Elevation of Privilege VulnerabilityCVSS 8.8

Products fixed this month

Windows 10 Version 1809 for 32-bit Systems (16)Windows 10 Version 1809 for x64-based Systems (16)Windows Server 2019 (16)Microsoft SharePoint Enterprise Server 2016 (6)Microsoft SharePoint Server 2019 (5)Microsoft SharePoint Server Subscription Edition (5)Microsoft Office 2019 for 32-bit editions (3)Microsoft Office 2019 for 64-bit editions (3)Microsoft 365 Apps for Enterprise for 32-bit Systems (3)Microsoft Office 2016 (32-bit edition) (2)

Every update in this release

All 27 update articles, worst first: anything on the CISA KEV list, then by highest CVSS. Each row links our page for the update, Microsoft's support article, and the Update Catalog for a standalone download.

UpdateSeverityMax CVSSCVEs fixedProductsAlso
KB5048661 ExploitedCritical9.855Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048652 ExploitedCritical9.846Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048685 ExploitedCritical9.846Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048667 ExploitedCritical9.857Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048794 ExploitedCritical9.858Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048653 ExploitedCritical9.856Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048654 ExploitedCritical9.841Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048800 ExploitedCritical9.842Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048703 ExploitedCritical9.823Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048671 ExploitedCritical9.832Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048710 ExploitedCritical9.823Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048744 ExploitedCritical9.823Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048695 ExploitedCritical9.824Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048676 ExploitedCritical9.824Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048699 ExploitedCritical9.828Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048735 ExploitedCritical9.827Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5002659High8.25Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5002544High8.24Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5002657High8.25Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5002664High8.24Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5002658High8.24Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB4475587High7.82Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
KB5002661High7.82Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition), Microsoft SharePoint Enterprise Server 2016Support · Catalog
KB2920716High7.81Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)Support · Catalog
KB5002660High7.81Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
KB5002641High7.81Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
KB5002652High1Microsoft Project 2016 (32-bit edition), Microsoft Project 2016 (64-bit edition)Support · Catalog
Take this release to your AI

Composed from the December 2024 release data above. Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Now see the same thing in your own tenant.

Siemserva by Senserva reads your Microsoft 365, Intune, Defender, and Entra ID environment and returns every missing update ranked by what is actually being exploited, alongside all 650+ configuration checks.

1Find it2Fix it3Prove it
Start my free auditAll you do is register.
Reference: Microsoft CVE and vulnerability management, ranked by real-world risk, and the Microsoft patching guide.
Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative Microsoft advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.