ZeroHour
CyberScooppublished ()ingested @gregotto

Microsoft closes 2024 with extensive security update

criticalVulnerability exploited in the wildimportance 60CVE-2024-49138CVE-2024-49112

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-49112
Unauthenticated RCE in Microsoft Windows LDAP (CVE-2024-49112)

CVE-2024-49112 is an integer overflow (CWE-190) in the Windows Lightweight Directory Access Protocol (LDAP) implementation that permits remote code execution. It is triggered by network traffic sent to the LDAP service, with no authentication or user interaction required (CVSS 3.1 network vector, low complexity, no privileges). A successful attacker gains arbitrary code execution in the context of the LDAP service process on the target, and on Active Directory domain controllers this typically means compromising a core infrastructure host with high confidentiality, integrity, and availability impact. All listed Windows 10 and Windows 11 client versions and Windows Server 2008 through 2022 are affected, making virtually every unpatched Windows environment — especially those running domain controllers — exposed. Per related coverage, the flaw was addressed in Microsoft's December 2024 Patch Tuesday (72 flaws fixed, four rated critical); no public proof-of-concept or confirmed in-the-wild exploitation is known for this specific RCE yet, though a related Windows LDAP flaw ('LDAPNightmare') has a public PoC that crashes LSASS and reboots domain controllers, and the ~71% EPSS score signals a high likelihood of exploitation within 30 days.

Do: Apply Microsoft's December 2024 (or later) Windows security updates immediately, prioritizing domain controllers and any server with LDAP reachable from untrusted networks. Until fully patched, restrict inbound LDAP/LDAPS traffic (TCP and UDP 389 and 636) to trusted sources and monitor for LSASS crashes or restarts on domain controllers. Because fixes are version-specific cumulative updates, verify each Windows release against Microsoft's advisory to confirm the correct KB is installed.

9.871%
  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2 (builds prior to the December 2024 security updates)
  • Microsoft Windows 11 22H2, 24H2 (builds prior to the December 2024 security updates)
  • Microsoft Windows Server 2008 affected builds prior to the December 2024 security updates
  • +4 more
massorder of millions of systems
CVE-2024-49138
Local Privilege Escalation via Heap Overflow in Microsoft Windows CLFS Driver

Microsoft's Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow (CWE-122) that a local attacker can trigger by submitting crafted input to the CLFS component after gaining the ability to run code on the target machine. Successful exploitation overwrites heap memory in the kernel driver and allows the attacker to escalate privileges, typically from an ordinary user account to SYSTEM-level execution. Any Microsoft Windows system is potentially affected; the CISA listing identifies only "Microsoft Windows" and does not enumerate specific versions or builds, and no CVSS score has been published yet. The flaw was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2024-12-10, confirming it is being exploited in the wild (ransomware use is unknown), and EPSS assigns a 25.4% probability of exploitation activity within 30 days (98th percentile). No public proof-of-concept is known, but the in-the-wild exploitation means defenders should treat this as an actively used privilege-escalation primitive, often chained after initial access by malware or another exploit.

Do: Apply Microsoft's security update for Windows per vendor instructions, as required by the CISA KEV listing (added 2024-12-10), and verify patch compliance across Windows endpoints. Because this is a local privilege escalation, prioritize hosts where untrusted users or malware execute code, and review telemetry for local code execution followed by unexpected escalation to SYSTEM. No public PoC exists, so detection should rely on vendor advisory guidance and EDR telemetry rather than public exploit signatures.

7.825% KEV PoC ×2
  • Microsoft Windows
masshundreds of millions to 1 billion+ Windows installations (Windows runs on 1B+ active devices)
Full article532 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Adobe, too.

Listen to this article

0:00

Learn more.

The Microsoft logo is illuminated on a wall during a Microsoft launch event on May 2, 2017 in New York City. (Photo by Drew Angerer/Getty Images)

In its final Patch Tuesday update of 2024, Microsoft has addressed 71 new security vulnerabilities, including a zero-day flaw that is currently being actively exploited. 

The zero-day vulnerability, documented as CVE-2024-49138, is a bug in the company’s Windows Common Log File System (CLFS). It poses a significant threat as it enables attackers to achieve system-level privileges via a heap-based buffer overflow, potentially allowing for ransomware attacks and other escalated cyber threats. 

Detailed information about the specific extent or location of its exploitation has not been disclosed. CISA on Tuesday added the vulnerability to its Known Exploited Vulnerabilities list.

In tandem, Microsoft has urged immediate attention to another severe vulnerability, CVE-2024-49112, in the Windows Lightweight Directory Access Protocol (LDAP). The vulnerability carries a CVSS severity score of 9.8. This flaw can allow an attacker to execute remote code without authentication, posing a high risk to domain controllers central to network security structures. Microsoft’s advisory recommends urgent patching and isolation of LDAP services from untrusted networks to prevent potential exploits.

This month’s fixes highlight pressing threats within the Windows ecosystem, particularly the vulnerabilities enabling unauthorized access or remote code execution across critical services like Remote Desktop and Hyper-V. These patches underscore vulnerabilities that can readily be weaponized by cybercriminals aiming to exploit widely used enterprise components.

Also on Tuesday, Adobe issued patches addressing 167 vulnerabilities across its software suite, with significant updates in products like Adobe Experience Manager and Adobe Connect. None of Adobe’s patched vulnerabilities were known to be under active exploitation at the time of release. 

Organizations are strongly encouraged to expedite these patches, given the severity scores and the additions to the KEV list. 

You can view the full Microsoft list in the company’s Security Response Center

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-patch-tuesday-december-2024/