CSIRT Toscana

Aggiornamenti Mensili Microsoft (AL01/241113/CSIRT-ITA)

Data:
13 Novembre 2024 07:58

Sintesi

Microsoft ha rilasciato gli aggiornamenti di sicurezza mensili che risolvono un totale di 158 nuove vulnerabilità, di cui 4 di tipo 0-day.

Rischio

Stima d’impatto della vulnerabilità sulla comunità di riferimento: GRAVE/ROSSO (77,94/100)1.

Tipologia

  • Security Feature Bypass
  • Remote Code Execution
  • Information Disclosure
  • Elevation of Privilege
  • Spoofing
  • Defense in Depth
  • Denial of Service

Prodotti e versioni affette

  • .NET and Visual Studio
  • Airlift.microsoft.com
  • Azure CycleCloud
  • Azure Database for PostgreSQL
  • LightGBM
  • Microsoft Exchange Server
  • Microsoft Graphics Component
  • Microsoft Office Excel
  • Microsoft Office Word
  • Microsoft PC Manager
  • Microsoft Virtual Hard Drive
  • Microsoft Windows DNS
  • Role: Windows Hyper-V
  • SQL Server
  • TorchGeo
  • Visual Studio
  • Visual Studio Code
  • Windows Active Directory Certificate Services
  • Windows CSC Service
  • Windows Defender Application Control (WDAC)
  • Windows DWM Core Library
  • Windows Kerberos
  • Windows Kernel
  • Windows NT OS Kernel
  • Windows NTLM
  • Windows Package Library Manager
  • Windows Registry
  • Windows Secure Kernel Mode
  • Windows SMB
  • Windows SMBv3 Client/Server
  • Windows Task Scheduler
  • Windows Telephony Service
  • Windows Update Stack
  • Windows USB Video Driver
  • Windows VMSwitch
  • Windows Win32 Kernel Subsystem

Azioni di mitigazione

In linea con le dichiarazioni del vendor, si raccomanda di procedere all’aggiornamento dei prodotti impattati attraverso l’apposita funzione di Windows Update.

Identificatori univoci vulnerabilità

CVE-ID
CVE-2024-49900 CVE-2024-49965 CVE-2024-49030 CVE-2024-50016
CVE-2024-43452 CVE-2024-49014 CVE-2024-50000 CVE-2024-49002
CVE-2024-43633 CVE-2024-49895 CVE-2024-49021 CVE-2024-43643
CVE-2024-43620 CVE-2024-43631 CVE-2024-49962 CVE-2024-50003
CVE-2024-49892 CVE-2024-49031 CVE-2024-49051 CVE-2024-49033
CVE-2024-49950 CVE-2024-49868 CVE-2024-43629 CVE-2024-49966
CVE-2024-43459 CVE-2024-49870 CVE-2024-49967 CVE-2024-49883
CVE-2024-49009 CVE-2024-49997 CVE-2024-49008 CVE-2024-49963
CVE-2024-49761 CVE-2024-43639 CVE-2024-43626 CVE-2024-49032
CVE-2024-43630 CVE-2024-48996 CVE-2024-48998 CVE-2024-43645
CVE-2024-48994 CVE-2024-43623 CVE-2024-49010 CVE-2024-43635
CVE-2024-49993 CVE-2024-49987 CVE-2024-49012 CVE-2024-43449
CVE-2024-49973 CVE-2024-49027 CVE-2024-49983 CVE-2024-49936
CVE-2024-43646 CVE-2024-49960 CVE-2024-50005 CVE-2024-43644
CVE-2024-49953 CVE-2024-49959 CVE-2024-49026 CVE-2024-43637
CVE-2024-43638 CVE-2024-43627 CVE-2024-49977 CVE-2024-50012
CVE-2024-43634 CVE-2024-48995 CVE-2024-49976 CVE-2024-43642
CVE-2024-49017 CVE-2024-49028 CVE-2024-49958 CVE-2024-49901
CVE-2024-49890 CVE-2024-49889 CVE-2024-43640 ADV240001
CVE-2024-43621 CVE-2024-49924 CVE-2024-43602 CVE-2024-49011
CVE-2024-49996 CVE-2024-49978 CVE-2024-49004 CVE-2024-49961
CVE-2024-49001 CVE-2024-49882 CVE-2024-49991 CVE-2024-43498
CVE-2024-49980 CVE-2024-49044 CVE-2024-43624 CVE-2024-49000
CVE-2024-49018 CVE-2024-43598 CVE-2024-43628 CVE-2024-49989
CVE-2024-43530 CVE-2024-49016 CVE-2024-49930 CVE-2024-49005
CVE-2024-49019 CVE-2024-50093 CVE-2024-43447 CVE-2024-50013
CVE-2024-49015 CVE-2024-49049 CVE-2024-43636 CVE-2024-49867
CVE-2024-43450 CVE-2024-49884 CVE-2024-49975 CVE-2024-49988
CVE-2024-49894 CVE-2024-49957 CVE-2024-49982 CVE-2024-49995
CVE-2024-5535 CVE-2024-43462 CVE-2024-49043 CVE-2024-48997
CVE-2024-49007 CVE-2024-49046 CVE-2024-49929 CVE-2024-43451
CVE-2024-48999 CVE-2024-49903 CVE-2024-50002 CVE-2024-50006
CVE-2024-43641 CVE-2024-49048 CVE-2024-49955 CVE-2024-49986
CVE-2024-49056 CVE-2024-50001 CVE-2024-50007 CVE-2024-38255
CVE-2024-38264 CVE-2024-43622 CVE-2024-49006 CVE-2024-49992
CVE-2024-48993 CVE-2024-49003 CVE-2024-49013 CVE-2024-43499
CVE-2024-49040 CVE-2024-49881 CVE-2024-50008 CVE-2024-38203
CVE-2024-49985 CVE-2024-49029 CVE-2024-43625 CVE-2024-49050
CVE-2024-49981 CVE-2024-49039 CVE-2024-50015 CVE-2024-49931
CVE-2024-49969 CVE-2024-49954

Riferimenti

https://msrc.microsoft.com/update-guide/releaseNote/2024-Nov

https://msrc.microsoft.com/update-guide (NB: filtro: patch tuesday – November 2024)

1La presente stima è effettuata tenendo conto di diversi parametri, tra i quali: CVSS, disponibilità di patch/workaround e PoC, diffusione dei software/dispositivi interessati nella comunità di riferimento.

Il presente articolo è un prodotto originale di csirt.gov.it, riproposto qui a solo scopo di aumentarne la visibilità.