July 2024 Patch Tuesday Unleashes a Torrent of Updates

to a pair of cowboy fighter pilots (ahem, naval aviators) in Top Gun. Less well known, but still Alive And Kicking (like the song released the same year by Simple Minds), the TIFF image file format also was introduced that year by Aldus Corporation, now known as Adobe.

This CVE addresses a critical, easily exploitable vulnerability specific to this 38-year-old file format. A specially-crafted, malicious TIFF file, uploaded to a vulnerable server, could have triggered the server that receives the file to execute malicious code embedded in the TIFF file. Patch your servers to take them out of the danger zone.

CVE-2024-38032 – Microsoft Xbox Remote Code Execution Vulnerability

Users of the Xbox gaming console who also happen to have a wireless adapter, and connect wirelessly to their local network, should beware of strangers lurking on their network who can attack these devices. The (so far) hypothetical threat is that someone who is connected to your wireless network can send a malicious network packet to the Xbox, one that could execute an arbitrary command. The attacker has to be connected to the same network as the Xbox, so it’s another good reason not to invite any threat actors to your WLAN party.



Important severity
CVE-2024-20701Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-21303Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-21308Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-21317Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-21331Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-21332Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-21333Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-21335Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-21373Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-21398Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-21414Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-21415Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-21425Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-21428Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-21449Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-28928Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-35256Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-35271Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-35272Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-37318Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-37319Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-37320Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-37321Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-37322Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-37323Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-37324Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-37326Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-37327Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-37328Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-37329Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-37330Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-37331Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-37332Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-37333Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-37334Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-37336Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-38087Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-38088Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

 

Azure (5 CVEs)

Important severity
CVE-2024-35261Azure Network Watcher VM Extension Elevation of Privilege Vulnerability
CVE-2024-35266Azure DevOps Server Spoofing Vulnerability
CVE-2024-35267Azure DevOps Server Spoofing Vulnerability
CVE-2024-38086Azure Kinect SDK Remote Code Execution Vulnerability
CVE-2024-38092Azure CycleCloud Elevation of Privilege Vulnerability

 

SharePoint (4 CVEs)

Critical severity
CVE-2024-38023Microsoft SharePoint Server Remote Code Execution Vulnerability
Important severity
CVE-2024-32987Microsoft SharePoint Server Information Disclosure Vulnerability
CVE-2024-38024Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2024-38094Microsoft SharePoint Remote Code Execution Vulnerability

 

Office 365 (2 CVEs)

Important severity
CVE-2024-38021Microsoft Office Remote Code Execution Vulnerability
Moderate severity
CVE-2024-38020Microsoft Outlook Spoofing Vulnerability

 

Microsoft Dynamics 365 (on-prem)

Important severity
CVE-2024-30061Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

 

Microsoft Defender for IoT (1 CVE)

Important severity
CVE-2024-38089Microsoft Defender for

Comments

Popular posts from this blog

CVE-2023-26369 Adobe acrobat update

US court holds Israeli spyware liable for hacking Meta’s WhatsApp