HomeMicrosoft Patch Tuesday › December 2024

Microsoft Patch Tuesday, December 2024

·

Microsoft's December 2024 security release, published December 10, 2024: 45 updates fixing 69 CVEs, ranked by confirmed exploitation, ransomware use, and severity. Provided by Senserva.

45
Updates (KBs)
69
CVEs fixed
1
On the CISA KEV list
23
Critical updates

Actively exploited CVEs (CISA KEV)

CVE-2024-49138Windows Common Log File System Driver Elevation of Privilege VulnerabilityCVSS 7.8Exploited

Other high-risk CVEs (CVSS 8.8+)

CVE-2024-49112Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityCVSS 9.8
CVE-2024-49085Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-49086Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-49102Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-49104Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-49125Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-49080Windows IP Routing Management Snapin Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-49117Windows Hyper-V Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-49093Windows Resilient File System (ReFS) Elevation of Privilege VulnerabilityCVSS 8.8

Products fixed this month

Windows 10 Version 1809 for 32-bit Systems (16)Windows 10 Version 1809 for x64-based Systems (16)Windows Server 2019 (16)Microsoft SharePoint Enterprise Server 2016 (6)Microsoft SharePoint Server 2019 (5)Microsoft SharePoint Server Subscription Edition (5)Microsoft Office 2019 for 32-bit editions (3)Microsoft Office 2019 for 64-bit editions (3)Microsoft 365 Apps for Enterprise for 32-bit Systems (3)Microsoft Office 2016 (32-bit edition) (2)

Every update in this release

All 27 update articles, worst first: anything on the CISA KEV list, then by highest CVSS. Each row links our page for the update, Microsoft's support article, and the Update Catalog for a standalone download.

UpdateSeverityMax CVSSCVEs fixedProductsAlso
KB5048661 ExploitedCritical9.855Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048652 ExploitedCritical9.846Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048685 ExploitedCritical9.846Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048667 ExploitedCritical9.857Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048794 ExploitedCritical9.858Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048653 ExploitedCritical9.856Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048654 ExploitedCritical9.841Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048800 ExploitedCritical9.842Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048703 ExploitedCritical9.823Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048671 ExploitedCritical9.832Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048710 ExploitedCritical9.823Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048744 ExploitedCritical9.823Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048695 ExploitedCritical9.824Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048676 ExploitedCritical9.824Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048699 ExploitedCritical9.828Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5048735 ExploitedCritical9.827Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5002659High8.25Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5002544High8.24Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5002657High8.25Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5002664High8.24Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5002658High8.24Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB4475587High7.82Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
KB5002661High7.82Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition), Microsoft SharePoint Enterprise Server 2016Support · Catalog
KB2920716High7.81Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)Support · Catalog
KB5002660High7.81Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
KB5002641High7.81Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
KB5002652High1Microsoft Project 2016 (32-bit edition), Microsoft Project 2016 (64-bit edition)Support · Catalog
Take this release to your AI

Composed from the December 2024 release data above. Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Now see your own patch state.

Senserva reads your Microsoft 365, Intune, Defender, and Entra ID environment and turns this release into your list: every update still missing, on every device, ranked by what attackers are actually exploiting. The 650+ configuration checks come with it.

1Find it2Fix it3Prove it
Start my free patch auditAll you do is register.
Reference: Microsoft CVE and vulnerability management, ranked by real-world risk, and the Microsoft patching guide.
Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative Microsoft advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.