Skip to main content

Microsoft Releases January 2024 Security Updates

Scheduled updates for Microsoft products, including security updates for forty-eight vulnerabilities with two rated as critical

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Scheduled updates for Microsoft products, including security updates for forty-eight vulnerabilities with two rated as critical


Affected platforms

The following platforms are known to be affected:

The following platforms are also known to be affected:

  • Windows Hyper-V
  • Windows Authentication Methods
  • NET and Visual Studio
  • .NET Core & Visual Studio
  • .NET Framework
  • Azure Storage Mover
  • Microsoft Bluetooth Driver
  • Microsoft Devices
  • Microsoft Edge (Chromium-based)
  • Microsoft Identity Services
  • Microsoft Office SharePoint
  • Microsoft Virtual Hard Drive
  • Remote Desktop Client
  • SQLite
  • Unified Extensible Firmware Interface
  • Visual Studio
  • Windows AllJoyn API
  • Windows BitLocker
  • Windows Cloud Files Mini Filter Driver
  • Windows Collaborative Translation Framework
  • Windows Common Log File System Driver
  • Windows Cryptographic Services
  • Windows Group Policy
  • Windows Kernel
  • Windows Kernel-Mode Drivers
  • Windows Libarchive
  • Windows Local Security Authority Subsystem Service (LSASS)
  • Windows Message Queuing
  • Windows Nearby Sharing
  • Windows ODBC Driver
  • Windows Online Certificate Status Protocol (OCSP) SnapIn
  • Windows Scripting
  • Windows Server Key Distribution Service
  • Windows Subsystem for Linux
  • Windows TCP/IP
  • Windows Themes
  • Windows Win32 Kernel Subsystem
  • Windows Win32K

Threat details

Introduction

Microsoft has released security updates to address forty-eight vulnerabilities, including two critical vulnerabilities.

CVE-2024-20700 is a remote code execution (RCE) vulnerability in Windows Hyper-V which could allow an unauthenticated attacker to remotely execute code on the target system. CVE-2024-20674 is an authentication bypass vulnerability in Windows Kerberos which an authenticated attacker could exploit by establishing a man-in-the-middle (MitM) attack or other local network spoofing technique, then sending a malicious Kerberos message to the client victim machine to spoof itself as the Kerberos authentication server.


Remediation advice

Affected organisations are encouraged to review Microsoft’s January 2024 Security Update Summary and apply the relevant updates.



Last edited: 10 January 2024 12:51 pm