Skip to main content

Microsoft Releases May 2024 Security Updates

Scheduled updates for Microsoft products, including security updates for 60 vulnerabilities

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Scheduled updates for Microsoft products, including security updates for 60 vulnerabilities


Affected platforms

The following platforms are known to be affected:

The following platforms are also known to be affected:

  • Microsoft Bing
  • Windows Mark of the Web (MOTW)
  • Microsoft Edge (Chromium-based)
  • Windows DWM Core Library
  • Windows Cryptographic Services
  • Windows Cloud Files Mini Filter Driver
  • Windows Remote Access Connection Manager
  • Microsoft Intune
  • Windows DHCP Server
  • Windows Deployment Services
  • Azure Migrate
  • Power BI
  • Windows Mobile Broadband
  • Microsoft Windows Search Component
  • Microsoft Dynamics 365 Customer Insights
  • Windows Task Scheduler
  • Microsoft Windows SCSI Class System File
  • Windows Common Log File System Driver
  • Windows Kernel
  • Windows NTFS
  • Windows Win32K – ICOMP
  • Windows Win32K – GRFX
  • Windows CNG Key Isolation Service
  • Microsoft Office Excel
  • Microsoft WDAC OLE DB provider for SQL
  • Microsoft Brokering File System
  • Windows Routing and Remote Access Service (RRAS)
  • Windows Hyper-V
  • Windows MSHTML Platform

Threat details

Introduction

Microsoft has released security updates to address 60 vulnerabilities, including two that are actively exploited.

CVE-2024-30040 and CVE-2024-30051 exploited in the wild

Microsoft has detected exploits for vulnerabilities CVE-2024-30040 and CVE-2024-30051.

  • CVE-2024-30040 Windows MSHTML Platform Security Feature Bypass Vulnerability. An attacker could gain code execution through convincing a user to open a malicious document, at which point the attacker could execute arbitrary code in the context of the user.
  • CVE-2024-30051 Windows DWM Core Library Elevation of Privilege Vulnerability. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

Remediation advice

Affected organisations are encouraged to review Microsoft’s May 2024 Security Update Summary and apply the relevant updates.


Last edited: 15 May 2024 2:14 pm