Microsoft released security updates for 90 vulnerabilities across its product portfolio, including 24 remote code execution flaws and nine rated critical. The August patch bundle addressed severe issues in Microsoft Dynamics 365, Microsoft Copilot Studio, Azure Health Bot, Windows TCP/IP, Windows Reliable Multicast Transport Driver, Windows Network Virtualization, and Linux boot components grub2 and shim.
Microsoft and CSIRT.SK said six vulnerabilities were already being exploited in the wild: CVE-2024-38189, CVE-2024-38178, CVE-2024-38193, CVE-2024-38106, CVE-2024-38107, and CVE-2024-38213. Among the most serious patched bugs were CVE-2024-38063, which allows unauthenticated remote code execution in Windows TCP/IP via crafted IPv6 packets, and CVE-2024-38140, which enables unauthenticated remote code execution in the Windows Reliable Multicast Transport Driver when PGM is enabled; defenders were urged to deploy the updates immediately.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Microsoft issued its August 2024 security updates, fixing 90 vulnerabilities across its product portfolio, including 24 remote code execution flaws. The update included fixes for six vulnerabilities reported as actively exploited in the wild, among them CVE-2024-38189, CVE-2024-38178, CVE-2024-38193, CVE-2024-38106, and CVE-2024-38107.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.