Microsoft Releases January 2024 Security Updates
Scheduled updates for Microsoft products, including security updates for forty-eight vulnerabilities with two rated as critical
Summary
Scheduled updates for Microsoft products, including security updates for forty-eight vulnerabilities with two rated as critical
Affected platforms
The following platforms are known to be affected:
The following platforms are also known to be affected:
- Windows Hyper-V
- Windows Authentication Methods
- NET and Visual Studio
- .NET Core & Visual Studio
- .NET Framework
- Azure Storage Mover
- Microsoft Bluetooth Driver
- Microsoft Devices
- Microsoft Edge (Chromium-based)
- Microsoft Identity Services
- Microsoft Office SharePoint
- Microsoft Virtual Hard Drive
- Remote Desktop Client
- SQLite
- Unified Extensible Firmware Interface
- Visual Studio
- Windows AllJoyn API
- Windows BitLocker
- Windows Cloud Files Mini Filter Driver
- Windows Collaborative Translation Framework
- Windows Common Log File System Driver
- Windows Cryptographic Services
- Windows Group Policy
- Windows Kernel
- Windows Kernel-Mode Drivers
- Windows Libarchive
- Windows Local Security Authority Subsystem Service (LSASS)
- Windows Message Queuing
- Windows Nearby Sharing
- Windows ODBC Driver
- Windows Online Certificate Status Protocol (OCSP) SnapIn
- Windows Scripting
- Windows Server Key Distribution Service
- Windows Subsystem for Linux
- Windows TCP/IP
- Windows Themes
- Windows Win32 Kernel Subsystem
- Windows Win32K
Threat details
Introduction
Microsoft has released security updates to address forty-eight vulnerabilities, including two critical vulnerabilities.
CVE-2024-20700 is a remote code execution (RCE) vulnerability in Windows Hyper-V which could allow an unauthenticated attacker to remotely execute code on the target system. CVE-2024-20674 is an authentication bypass vulnerability in Windows Kerberos which an authenticated attacker could exploit by establishing a man-in-the-middle (MitM) attack or other local network spoofing technique, then sending a malicious Kerberos message to the client victim machine to spoof itself as the Kerberos authentication server.
Remediation advice
Affected organisations are encouraged to review Microsoft’s January 2024 Security Update Summary and apply the relevant updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 10 January 2024 12:51 pm