Trinetri logo
Updated monthly

Microsoft Patch Tuesday
August 2024

Microsoft's August 2024 Patch Tuesday fixes 93 vulnerabilities across Windows, Microsoft Office and Azure - 11 rated Critical, 4 publicly disclosed before the patch shipped, 6 already exploited in the wild. Patch CVE-2024-38189 first.

Released August 13, 2024, 10:00 PT6 actively exploited4 publicly disclosed82 KB articles to deploy

August 2024 Patch Tuesday at a glance

93
Microsoft CVEs
excl. Edge & Azure Linux
11
Critical
12% of the release
6
Actively exploited
CVE-2024-38189
4
Publicly disclosed
known before the patch
9.8
Highest CVSS
CVE-2024-38199
82
KB articles
what you actually deploy

Why this number differs from other roundups. Microsoft's August 2024 release document lists 298 entries. 169 are Azure Linux (Mariner) OS package updates and 36 are republished Chromium fixes for Edge - neither is a Microsoft product vulnerability. The 93 above is the real Patch Tuesday set. See the breakdown →

Priority order

Patch these first

Ranked by exploitation reality, not score alone. This month's exploited flaw is rated Important - a severity-sorted list would bury it.

Patch today

Exploited in the wild

Confirmed attacks are already happening. Emergency change window.

CVE-2024-38189Microsoft Project Remote Code Execution VulnerabilityImportantCVSS 8.8RCEKB5002561CVE-2024-38107Windows Power Dependency Coordinator Elevation of Privilege VulnerabilityImportantCVSS 7.8EoPKB5041160CVE-2024-38193Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportantCVSS 7.8EoPKB5041160CVE-2024-38178Scripting Engine Memory Corruption VulnerabilityImportantCVSS 7.5RCEKB5041160CVE-2024-38106Windows Kernel Elevation of Privilege VulnerabilityImportantCVSS 7.0EoPKB5041160CVE-2024-38213Windows Mark of the Web Security Feature Bypass VulnerabilityModerateCVSS 6.5BypassKB5039211

Patch this week

Publicly disclosed

Details are already public. Working exploits typically follow within days.

CVE-2024-38199Windows Line Printer Daemon (LPD) Service Remote Code Execution VulnerabilityImportantCVSS 9.8RCEKB5041160CVE-2024-38202Windows Update Stack Elevation of Privilege VulnerabilityImportantCVSS 7.3EoPKB5044273CVE-2024-21302Windows Secure Kernel Mode Elevation of Privilege VulnerabilityImportantCVSS 6.7EoPKB5041580CVE-2024-38200Microsoft Office Spoofing VulnerabilityImportantCVSS 6.5SpoofingKB5002570
The numbers

What’s in this release

Where the 298 entries actually come from

Most roundups quote a single number. These are three unrelated release streams.

93 Microsoft products169 Azure Linux (Mariner)36 Edge (Chromium)

Severity

Microsoft channel only · 93 CVEs

August 2024 severity breakdown
Critical11
Important80
Moderate2
Low0

Impact type

What an attacker gains if it works

August 2024 impact breakdown
Elevation of Privilege38
Remote Code Execution29
Information Disclosure8
Spoofing7
Denial of Service6
Security Feature Bypass4
Tampering1

Most-affected components

Where this month’s fixes concentrate - filter by any of them in the table below

Windows Routing and Remote Access Service (RRAS)6Windows Kernel5Windows Kernel-Mode Drivers5Microsoft Streaming Service3Windows IP Routing Management Snapin3Windows Secure Boot3.NET and Visual Studio2Azure Connected Machine Agent2Azure IoT SDK2Azure Stack2Microsoft Dynamics2Microsoft Local Security Authority Server (lsasrv)2
Every patch

Browse all 298 entries

Sorted by risk by default: exploited first, then publicly disclosed, then severity, then CVSS. Search by CVE, title, component or KB number.

Showing 93 of 93
93 Microsoft vulnerabilities in the August 2024 Patch Tuesday, sortable by severity, CVSS and exploit status.
TitleStatusKB
ImportantCVE-2024-38189Microsoft Project Remote Code Execution VulnerabilityRCE8.8ExploitedMicrosoft Office Project5002561
ImportantCVE-2024-38107Windows Power Dependency Coordinator Elevation of Privilege VulnerabilityEoP7.8ExploitedWindows Power Dependency Coordinator5041160 +10
ImportantCVE-2024-38193Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEoP7.8ExploitedWindows Ancillary Function Driver for WinSock5041160 +14
ImportantCVE-2024-38178Scripting Engine Memory Corruption VulnerabilityRCE7.5ExploitedWindows Scripting5041160 +10
ImportantCVE-2024-38106Windows Kernel Elevation of Privilege VulnerabilityEoP7.0ExploitedWindows Kernel5041160 +8
ModerateCVE-2024-38213Windows Mark of the Web Security Feature Bypass VulnerabilityBypass6.5ExploitedWindows Mark of the Web (MOTW)5039211 +10
ImportantCVE-2024-38199Windows Line Printer Daemon (LPD) Service Remote Code Execution VulnerabilityRCE9.8DisclosedLine Printer Daemon Service (LPD)5041160 +14
ImportantCVE-2024-38202Windows Update Stack Elevation of Privilege VulnerabilityEoP7.3DisclosedWindows Update Stack5044273 +6
ImportantCVE-2024-21302Windows Secure Kernel Mode Elevation of Privilege VulnerabilityEoP6.7DisclosedWindows Secure Kernel Mode5041580 +8
ImportantCVE-2024-38200Microsoft Office Spoofing VulnerabilitySpoofing6.5DisclosedMicrosoft Office5002570 +1
CriticalCVE-2024-38063Windows TCP/IP Remote Code Execution VulnerabilityRCE9.8More likelyWindows TCP/IP5041571 +14
ImportantCVE-2024-38144Kernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityEoP8.8More likelyMicrosoft Streaming Service5041160 +14
ImportantCVE-2024-38125Kernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityEoP7.8More likelyMicrosoft Streaming Service5041160 +14
ImportantCVE-2024-38133Windows Kernel Elevation of Privilege VulnerabilityEoP7.8More likelyWindows Kernel5041160 +6
ImportantCVE-2024-38141Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEoP7.8More likelyWindows Ancillary Function Driver for WinSock5041160 +10
ImportantCVE-2024-38147Microsoft DWM Core Library Elevation of Privilege VulnerabilityEoP7.8More likelyWindows DWM Core Library5041160 +5
ImportantCVE-2024-38150Windows DWM Core Library Elevation of Privilege VulnerabilityEoP7.8More likelyWindows DWM Core Library5041160 +5
ImportantCVE-2024-38163Windows Update Stack Elevation of Privilege VulnerabilityEoP7.8More likelyWindows Update Stack5042320 +2
ImportantCVE-2024-38196Windows Common Log File System Driver Elevation of Privilege VulnerabilityEoP7.8More likelyWindows Common Log File System Driver5041160 +14
ImportantCVE-2024-38148Windows Secure Channel Denial of Service VulnerabilityDoS7.5More likelyWindows Transport Security Layer (TLS)5041160 +4
ImportantCVE-2024-38198Windows Print Spooler Elevation of Privilege VulnerabilityEoP7.5More likelyWindows Print Spooler Components5041160 +14
CriticalCVE-2024-38140Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution VulnerabilityRCE9.8Reliable Multicast Transport Driver (RMCAST)5041160 +14
CriticalCVE-2024-38175Azure Managed Instance for Apache Cassandra Elevation of Privilege VulnerabilityEoP9.6Azure Managed Instance for Apache Cassandra
CriticalCVE-2024-38109Azure Health Bot Elevation of Privilege VulnerabilityEoP9.1Azure Health Bot
CriticalCVE-2024-38159Windows Network Virtualization Remote Code Execution VulnerabilityRCE9.1Windows Network Virtualization5041773
Your move

What your IT team should do

The same five steps every month, in the order that reduces risk fastest.

Test the known-issue candidates

Check the Windows release health dashboard before promoting past ring 1, and have the rollback path written down before you need it. Kernel, networking and authentication fixes are the ones that historically break things.

12 Patch Management Best Practices for 2026

Verify installed state, then evidence it

Confirm the patch is actually present on each endpoint rather than trusting that "deployment succeeded". Keep the resulting report - it is the artefact auditors ask for, and reconstructing it later is far more work than capturing it now.

Patch Management: The Complete Guide

Trinetri does steps two through five automatically - detecting the 82 KB articles across every endpoint, staging them in rings, verifying installed state and producing the compliance evidence. See patch management →

Stop the sprawl. Eliminate the guesswork.

Ready to See Autonomous Endpoint Management in Action?

Experience how Trinetri transforms endpoint chaos into clarity. Try the 30 minute demo session, our experts will walk you through how AI-powered automation, real-time visibility, and unified control can secure your entire hybrid environment, without the overhead.

Patch Tuesday FAQ

Patch Tuesday falls on the second Tuesday of every month, with updates going live at 10:00 a.m. Pacific Time. Microsoft introduced the practice in October 2003, following the Blaster worm, to cut distribution costs and give administrators a predictable cadence instead of patches arriving at random. The 10:00 a.m. timing is deliberate: it leaves a full working week to remediate before the weekend. Internally Microsoft calls it the "B" release; optional "C" and "D" preview releases follow later in the month. The next Patch Tuesday is October 13, 2026.

Microsoft fixed 93 vulnerabilities in August 2024, across Windows, Microsoft Office, Azure and Developer Tools. 11 are rated Critical, 4 were publicly disclosed before the patch shipped, and 6 were already being exploited. Note that Microsoft's release document lists 298 entries in total, but 169 of those are Azure Linux package updates and 36 are republished Chromium fixes for Edge, which is why other sources sometimes quote a much larger number.

Exploit Wednesday is the day after Patch Tuesday. Attackers compare the newly released patches against the previous version to locate the flaw each one fixes, then build working exploits from that difference - often within 24 to 48 hours. It is the reason the deployment window matters as much as the patch itself: every hour a Critical remote code execution fix sits undeployed is an hour of measurable exposure.

A workable target for most organisations: actively exploited vulnerabilities within 24 hours, publicly disclosed ones within 72 hours, remaining Critical fixes within seven days, and everything else within the month. CISA's Known Exploited Vulnerabilities catalogue sets binding deadlines for US federal agencies and is a reasonable benchmark for everyone else. Stage the rollout in rings rather than deploying everywhere at once, so a regression is caught on a pilot group instead of in production.

An out-of-band update is a patch released outside the monthly cycle because the risk will not wait for the next Patch Tuesday. Microsoft issues them for actively exploited flaws with no mitigation - most famously during the WannaCry outbreak in 2017, when it took the unusual step of patching versions of Windows that were already out of support.

Yes. Adobe aligned its releases with Patch Tuesday in November 2012, and both SAP's Security Patch Day and Oracle's quarterly Critical Patch Updates are coordinated to the same week. Part of the reason is defensive: staggered releases let attackers reverse-engineer one vendor's patch to find the same underlying flaw in another's still-unpatched product. For IT teams it means the second Tuesday is rarely just a Microsoft problem.

Edge is built on Chromium, so most of its security fixes originate with the Chromium project and are republished by Microsoft under their own CVE identifiers. They ship on Chromium's cadence rather than the Patch Tuesday cycle, and they are delivered by Edge's own updater rather than Windows Update. Counting the 36 Edge entries alongside Microsoft product fixes would inflate the headline number and imply work for your Windows Update rings that does not exist.