ZeroHour
Security Affairspublished ()ingested @securityaffairs

Microsoft urges customers to fix Windows RCE in the TCP/IP stack

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-38063
Windows TCP/IP Remote Code Execution Vulnerability

Windows TCP/IP Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.871%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2024-38193
+4 in the same advisory: …38178 …38107 …38106 …38213
Use-After-Free Privilege Escalation in Microsoft Windows WinSock Driver (afd.sys)

The Windows Ancillary Function Driver for WinSock (afd.sys) contains a use-after-free flaw (CWE-416) that allows a local attacker to escalate privileges. An attacker who can already execute code on a Windows host — typically after gaining initial access via phishing, malware, or chaining with another vulnerability — triggers the bug to gain SYSTEM-level privileges, giving them near-full control of the machine. Any Windows host running an affected build is exposed to the flaw, though it requires local code execution and is not remotely exploitable on its own. Exploitation is confirmed in the wild: CISA added the CVE to the KEV catalog on 2024-08-13 and Microsoft shipped fixes in its August 2024 security updates, while the ransomware association is currently listed as unknown. EPSS is elevated at 28.5% (98th percentile), indicating a high likelihood of continued exploitation over the next 30 days.

Do: Apply Microsoft's August 2024 Windows cumulative security updates (released 2024-08-13) across all Windows clients and servers, prioritizing multi-user hosts such as RDS/VDI servers and jump boxes where local code execution by low-privileged users is more likely. After patching, verify installed build numbers and hunt for signs of local privilege escalation, per CISA's KEV required action to apply vendor mitigations or discontinue use. Keep the host within your KEV remediation SLA, as listing in the catalog signals active exploitation.

7.8
group max
29% KEV PoC
  • Microsoft Windows Supported Windows client (Windows 10, Windows 11) and Windows Server releases; specific affected builds are enumerated in Microsoft's August 2024 security updat
mass>1 billion Windows endpoints worldwide, i.e., effectively every unpatched Windows client or server
CVE-2024-38189
Input-validation RCE in Microsoft Project via crafted project files

CVE-2024-38189 is an improper input validation (CWE-20) remote code execution flaw in Microsoft Project. Triggering it requires user interaction: an attacker supplies a maliciously crafted Project file, and when a user opens it, the parsing flaw allows attacker-controlled input to execute code. Successful exploitation yields code execution in the context of the user who opened the file, with high impact to confidentiality, integrity, and availability on that endpoint. Per the CPE data, affected deployments include Project 2016 and the Project client shipped with Office 2019, Office LTSC, and Microsoft 365 Apps. The flaw was one of six zero-days Microsoft patched in its August 2024 Patch Tuesday release and was confirmed to be exploited in the wild, earning a CISA KEV listing on 2024-08-13; EPSS assigns an 8.2% 30-day exploitation probability (95th percentile), and no public PoC is known.

Do: Apply Microsoft's August 2024 Patch Tuesday security updates for Microsoft Project/Office (covering Project 2016 and the Project client in Office 2019, Office LTSC, and Microsoft 365 Apps) immediately, per the CISA KEV required action; as an interim measure, caution users against opening Project files from untrusted sources until patched. After updating, verify that the installed Project/Office build reflects the August 2024 security updates.

8.88% KEV
  • Microsoft Project 2016 Versions prior to Microsoft's August 2024 security updates
  • Microsoft Project client shipped with Microsoft 365 Apps Versions prior to Microsoft's August 2024 security updates
  • Microsoft Project client shipped with Office 2019 Versions prior to Microsoft's August 2024 security updates
  • +1 more
mass≈ millions of enterprise desktop installations (Project desktop is a standard tool across Microsoft's hundreds-of-millions-strong Microsoft 365/Office…
Full article395 words · extracted from securityaffairs.com · click to collapse

Microsoft addressed a critical zero-click Windows remote code execution (RCE) in the TCP/IP stack that impacts all systems with IPv6 enabled.

Microsoft urges customers to fix a critical TCP/IP remote code execution (RCE) flaw, tracked as CVE-2024-38063 (CVSS score 9.8), in the TCP/IP stack. The vulnerability impacts all systems with IPv6 enabled (IPv6 is enabled by default).

An unauthenticated attacker can exploit the flaw by repeatedly sending IPv6 packets, including specially crafted packets, to a Windows machine which could lead to remote code execution.

Microsoft confirmed that a threat actor can exploit this flaw in a low-complexity attack and its exploitability assessment labels the issue as “exploitation more likely.” This label suggests that Microsoft is aware of past instances of this type of vulnerability being exploited.

Kunlun Lab’s XiaoWei discovered the flaw several months ago, he urged customers to apply the patches because the “exploitation is more likely.”

MSRC fixed a RCE bug in TCPIP module.
I found the bug several months ago.
Its score is 9.8 and exploitation is more likely. Please apply the patch immediately. pic.twitter.com/bdjBLgoaYv

— wei (@XiaoWei___) August 14, 2024

The flaw is a buffer overflow issue that can be exploited to achieve arbitrary code execution on vulnerable Windows 10, Windows 11, and Windows Server systems.

Considering its harm, I will not disclose more details in the short term.

— wei (@XiaoWei___) August 14, 2024

XiaoWei pointed out that blocking IPv6 on the local Windows firewall cannot prevent the exploitation of the issue because the vulnerability is triggered before it is processed by the firewall.

Microsoft recommends disabling IPv6 as a mitigation measure.

The issue was addressed by Microsoft with the release of Patch Tuesday security updates for August 2024 that also fixed the following actively exploited flaws:

CVETitleSeverityCVSSPublicExploitedType
CVE-2024-38189Microsoft Project Remote Code Execution VulnerabilityImportant8.8NoYesRCE
CVE-2024-38178Scripting Engine Memory Corruption VulnerabilityImportant7.5NoYesRCE
CVE-2024-38193Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant7.8NoYesEoP
CVE-2024-38106Windows Kernel Elevation of Privilege VulnerabilityImportant7NoYesEoP
CVE-2024-38107Windows Power Dependency Coordinator Elevation of Privilege VulnerabilityImportant7.8NoYesEoP
CVE-2024-38213Windows Mark of the Web Security Feature Bypass VulnerabilityModerate6.5NoYesSFB

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, TCP/IP)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/167117/hacking/windows-rce-tcp-ip.html