
September Microsoft Patch Tuesday. 107 CVEs, 28 of which were added since August MSPT. 6 vulnerabilities with signs of exploitation in the wild:
Remote Code Execution – Windows Update (CVE-2024-43491)
Elevation of Privilege – Windows Installer (CVE-2024-38014)
Security Feature Bypass – Windows Mark of the Web (CVE-2024-38217), Microsoft Publisher (CVE-2024-38226), Chromium (CVE-2024-7965)
Memory Corruption – Chromium (CVE-2024-7971)
3 more with private exploits:
Authentication Bypass – Azure (CVE-2024-38175)
Security Feature Bypass – Windows Mark of the Web (CVE-2024-43487)
Elevation of Privilege – Windows Storage (CVE-2024-38248)
Other interesting vulnerabilities:
Remote Code Execution – Microsoft SQL Server (CVE-2024-37335 and 5 more CVEs)
Remote Code Execution – Windows NAT (CVE-2024-38119)
Elevation of Privilege – Windows Win32k (CVE-2024-38246, CVE-2024-38252, CVE-2024-38253)

Hi! My name is Alexander and I am a Vulnerability Management specialist. You can read more about me here. Currently, the best way to follow me is my Telegram channel @avleonovcom. I update it more often than this site. If you haven’t used Telegram yet, give it a try. It’s great. You can discuss my posts or ask questions at @avleonovchat.
А всех русскоязычных я приглашаю в ещё один телеграмм канал @avleonovrus, первым делом теперь пишу туда.