Trinetri logo
Updated monthly

Microsoft Patch Tuesday
October 2024

Microsoft's October 2024 Patch Tuesday fixes 123 vulnerabilities across Windows, Developer Tools and Microsoft Office - 7 rated Critical, 5 publicly disclosed before the patch shipped, 2 already exploited in the wild. Patch CVE-2024-43572 first.

Released October 8, 2024, 10:00 PT2 actively exploited5 publicly disclosed68 KB articles to deploy

October 2024 Patch Tuesday at a glance

123
Microsoft CVEs
excl. Edge & Azure Linux
7
Critical
6% of the release
2
Actively exploited
CVE-2024-43572
5
Publicly disclosed
known before the patch
9.8
Highest CVSS
CVE-2024-43468
68
KB articles
what you actually deploy

Why this number differs from other roundups. Microsoft's October 2024 release document lists 869 entries. 714 are Azure Linux (Mariner) OS package updates and 32 are republished Chromium fixes for Edge - neither is a Microsoft product vulnerability. The 123 above is the real Patch Tuesday set. See the breakdown →

The numbers

What’s in this release

Where the 869 entries actually come from

Most roundups quote a single number. These are three unrelated release streams.

123 Microsoft products714 Azure Linux (Mariner)32 Edge (Chromium)

Severity

Microsoft channel only · 123 CVEs

October 2024 severity breakdown
Critical7
Important114
Moderate1
Low0
Unrated1

Impact type

What an attacker gains if it works

October 2024 impact breakdown
Remote Code Execution44
Elevation of Privilege29
Denial of Service26
Information Disclosure8
Spoofing7
Security Feature Bypass7
Tampering1
Other1

Most-affected components

Where this month’s fixes concentrate - filter by any of them in the table below

Windows Mobile Broadband15Windows Routing and Remote Access Service (RRAS)12Windows Kernel6Microsoft Graphics Component4Role: Windows Hyper-V4Microsoft Office3OpenSSH for Windows3Windows EFI Partition3.NET and Visual Studio2.NET, .NET Framework, Visual Studio2BranchCache2Microsoft Simple Certificate Enrollment Protocol2
Every patch

Browse all 869 entries

Sorted by risk by default: exploited first, then publicly disclosed, then severity, then CVSS. Search by CVE, title, component or KB number.

Showing 123 of 123
123 Microsoft vulnerabilities in the October 2024 Patch Tuesday, sortable by severity, CVSS and exploit status.
TitleStatusKB
ImportantCVE-2024-43572Microsoft Management Console Remote Code Execution VulnerabilityRCE7.8ExploitedDisclosedMicrosoft Management Console5044273 +14
ModerateCVE-2024-43573Windows MSHTML Platform Spoofing VulnerabilitySpoofing6.5ExploitedDisclosedWindows MSHTML Platform5044273 +9
ImportantCVE-2024-43583Winlogon Elevation of Privilege VulnerabilityEoP7.8DisclosedMore likelyWinlogon5044280 +16
ImportantCVE-2024-6197Hackerone: CVE-2024-6197 Freeing stack buffer in utf8asn1strRCE8.8DisclosedWindows cURL Implementation5044273 +6
ImportantCVE-2024-20659Windows Hyper-V Security Feature Bypass VulnerabilityBypass7.1DisclosedRole: Windows Hyper-V5044273 +6
ImportantCVE-2024-43509Windows Graphics Component Elevation of Privilege VulnerabilityEoP7.8More likelyMicrosoft Graphics Component5044273 +14
ImportantCVE-2024-43556Windows Graphics Component Elevation of Privilege VulnerabilityEoP7.8More likelyMicrosoft Graphics Component5044273 +14
ImportantCVE-2024-43560Microsoft Windows Storage Port Driver Elevation of Privilege VulnerabilityEoP7.8More likelyWindows Storage Port Driver5044273 +10
ImportantCVE-2024-43502Windows Kernel Elevation of Privilege VulnerabilityEoP7.1More likelyWindows Kernel5044273 +1
ImportantCVE-2024-43581Microsoft OpenSSH for Windows Remote Code Execution VulnerabilityRCE7.1More likelyOpenSSH for Windows5044273 +6
ImportantCVE-2024-43615Microsoft OpenSSH for Windows Remote Code Execution VulnerabilityRCE7.1More likelyOpenSSH for Windows5044273 +6
ImportantCVE-2024-43609Microsoft Office Spoofing VulnerabilitySpoofing6.5More likelyMicrosoft Office5002635
UnratedCVE-2024-43610Copilot Studio Information Disclosure VulnerabilityOther7.4More likelyCopilot Studio
CriticalCVE-2024-43468Microsoft Configuration Manager Remote Code Execution VulnerabilityRCE9.8Microsoft Configuration Manager
CriticalCVE-2024-43488Visual Studio Code extension for Arduino Remote Code Execution VulnerabilityRCE8.8Visual Studio Code
CriticalCVE-2024-43582Remote Desktop Protocol Server Remote Code Execution VulnerabilityRCE8.1Windows Remote Desktop5044273 +7
ImportantCVE-2024-38124Windows Netlogon Elevation of Privilege VulnerabilityEoP9.0Windows Netlogon5044277 +9
ImportantCVE-2024-38179Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege VulnerabilityEoP8.8Azure Stack
ImportantCVE-2024-38212Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityRCE8.8Windows Routing and Remote Access Service (RRAS)5044277 +9
ImportantCVE-2024-38265Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityRCE8.8Windows Routing and Remote Access Service (RRAS)5044277 +9
ImportantCVE-2024-43453Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityRCE8.8Windows Routing and Remote Access Service (RRAS)5044277 +9
ImportantCVE-2024-43517Microsoft ActiveX Data Objects Remote Code Execution VulnerabilityRCE8.8Microsoft ActiveX5044273 +14
ImportantCVE-2024-43518Windows Telephony Server Remote Code Execution VulnerabilityRCE8.8Windows Telephony Server5044273 +14
ImportantCVE-2024-43519Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution VulnerabilityRCE8.8Microsoft WDAC OLE DB provider for SQL5044273 +14
ImportantCVE-2024-43532Remote Registry Service Elevation of Privilege VulnerabilityEoP8.8RPC Endpoint Mapper Service5044273 +14
Your move

What your IT team should do

The same five steps every month, in the order that reduces risk fastest.

Test the known-issue candidates

Check the Windows release health dashboard before promoting past ring 1, and have the rollback path written down before you need it. Kernel, networking and authentication fixes are the ones that historically break things.

12 Patch Management Best Practices for 2026

Verify installed state, then evidence it

Confirm the patch is actually present on each endpoint rather than trusting that "deployment succeeded". Keep the resulting report - it is the artefact auditors ask for, and reconstructing it later is far more work than capturing it now.

Patch Management: The Complete Guide

Trinetri does steps two through five automatically - detecting the 68 KB articles across every endpoint, staging them in rings, verifying installed state and producing the compliance evidence. See patch management →

Patch Tuesday FAQ

Patch Tuesday falls on the second Tuesday of every month, with updates going live at 10:00 a.m. Pacific Time. Microsoft introduced the practice in October 2003, following the Blaster worm, to cut distribution costs and give administrators a predictable cadence instead of patches arriving at random. The 10:00 a.m. timing is deliberate: it leaves a full working week to remediate before the weekend. Internally Microsoft calls it the "B" release; optional "C" and "D" preview releases follow later in the month. The next Patch Tuesday is September 8, 2026.

Microsoft fixed 123 vulnerabilities in October 2024, across Windows, Developer Tools, Microsoft Office and Azure. 7 are rated Critical, 5 were publicly disclosed before the patch shipped, and 2 were already being exploited. Note that Microsoft's release document lists 869 entries in total, but 714 of those are Azure Linux package updates and 32 are republished Chromium fixes for Edge, which is why other sources sometimes quote a much larger number.

Exploit Wednesday is the day after Patch Tuesday. Attackers compare the newly released patches against the previous version to locate the flaw each one fixes, then build working exploits from that difference - often within 24 to 48 hours. It is the reason the deployment window matters as much as the patch itself: every hour a Critical remote code execution fix sits undeployed is an hour of measurable exposure.

A workable target for most organisations: actively exploited vulnerabilities within 24 hours, publicly disclosed ones within 72 hours, remaining Critical fixes within seven days, and everything else within the month. CISA's Known Exploited Vulnerabilities catalogue sets binding deadlines for US federal agencies and is a reasonable benchmark for everyone else. Stage the rollout in rings rather than deploying everywhere at once, so a regression is caught on a pilot group instead of in production.

An out-of-band update is a patch released outside the monthly cycle because the risk will not wait for the next Patch Tuesday. Microsoft issues them for actively exploited flaws with no mitigation - most famously during the WannaCry outbreak in 2017, when it took the unusual step of patching versions of Windows that were already out of support.

Yes. Adobe aligned its releases with Patch Tuesday in November 2012, and both SAP's Security Patch Day and Oracle's quarterly Critical Patch Updates are coordinated to the same week. Part of the reason is defensive: staggered releases let attackers reverse-engineer one vendor's patch to find the same underlying flaw in another's still-unpatched product. For IT teams it means the second Tuesday is rarely just a Microsoft problem.

Edge is built on Chromium, so most of its security fixes originate with the Chromium project and are republished by Microsoft under their own CVE identifiers. They ship on Chromium's cadence rather than the Patch Tuesday cycle, and they are delivered by Edge's own updater rather than Windows Update. Counting the 32 Edge entries alongside Microsoft product fixes would inflate the headline number and imply work for your Windows Update rings that does not exist.

Stop the sprawl. Eliminate the guesswork.

Ready to See Autonomous Endpoint Management in Action?

Experience how Trinetri transforms endpoint chaos into clarity. Try the 30 minute demo session, our experts will walk you through how AI-powered automation, real-time visibility, and unified control can secure your entire hybrid environment, without the overhead.