Weekly digest
Week 24, 2024 (10–16 Jun)
A heavy week: 64 new CVEs, well above the recent average of about 24. Severity skewed high: 2 critical and 38 high, 63% of the total. 5 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. microsoft was the most-affected vendor with 48.
New this week, ranked by depth score
The 12 that matter most of the 64 published.
CVE-2024-30088High· 7.0CISA KEVPoCWindows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
CVE-2024-35250High· 7.8CISA KEVPoCWindows Kernel-Mode Driver Elevation of Privilege Vulnerability
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2024-30080Critical· 9.8Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2024-30085High· 7.8PoCWindows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2024-36265Critical· 9.8** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: from 0.8.0. An attacker can bypass authentication by sending specially crafted REST…
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: from 0.8.0. An attacker can bypass authentication by sending specially crafted REST…
CVE-2024-30090High· 7.0PoCMicrosoft Streaming Service Elevation of Privilege Vulnerability
Microsoft Streaming Service Elevation of Privilege Vulnerability
CVE-2024-35249High· 8.8Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
CVE-2024-30103High· 8.8Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2024-30097High· 8.8Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability
Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability
CVE-2024-30078High· 8.8Windows Wi-Fi Driver Remote Code Execution Vulnerability
Windows Wi-Fi Driver Remote Code Execution Vulnerability
CVE-2024-30068High· 8.8Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
CVE-2024-36586High· 8.8AdGuardHome privilege escalation vulnerability
AdGuardHome privilege escalation vulnerability
Most-affected vendors
By CVEs published in the period.