Microsoft offers updates on 117 vulnerabilities on Patch Tuesday
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-43573 +1 in the same advisory: …43572 | Spoofing Vulnerability in Microsoft Windows MSHTML Platform Exploited in the Wild CVE-2024-43573 is a spoofing vulnerability in the Microsoft Windows MSHTML platform, classified as an input-neutralization flaw (CWE-79), that can lead to a loss of confidentiality. It is triggered when a user renders attacker-crafted content through the MSHTML engine, the browser-rendering component embedded in Windows that many system surfaces and applications use to display web-like content, causing content or interface elements to appear to come from a trusted source when they are attacker-controlled. An attacker who successfully exploits it can present spoofed content or prompts that deceive users, potentially leading them to reveal sensitive information such as credentials. All Microsoft Windows systems are affected according to CISA's listing, though no specific version breakdown is provided in the source data. The flaw is confirmed to be exploited in the wild (CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-08), EPSS assigns a 44.1% probability of exploitation in the next 30 days (99th percentile), no public PoC is known, and any ransomware association is listed as unknown. Do: Apply Microsoft's October 2024 security updates (or later cumulative updates) to all Windows clients and servers as soon as possible, following vendor instructions; per CISA's required action, apply vendor mitigations or discontinue use of the affected platform if mitigations are unavailable. Until patched, exercise caution with unsolicited documents, links, and content rendered through Windows surfaces, and watch for spoofed prompts or user-interface elements. Federal agencies should complete remediation by the KEV due date for this entry. | 8.1 group max | 44% | KEV |
| mass≈1 billion+ Windows installations worldwide (MSHTML is present on essentially every Windows client and server) |
Full article214 words · extracted from cyberscoop.com · click to collapse
The vulnerabilities are tied to the Microsoft Management Console and Windows MSHTML Platform.
Microsoft on Tuesday shared security updates on 117 common vulnerabilities and exposures, including two that are being actively exploited, according to the company.
The actively exploited vulnerabilities relate to the Microsoft Management Console (CVE-2024-43572) and the Windows MSHTML Platform (CVE-2024-43573), the company said.
The list includes five publicly disclosed zero-days in total, as part of 28 elevation-of-privilege vulnerabilities, seven security feature bypasses, 43 remote code execution vulnerabilities, six information disclosure vulnerabilities, 26 denial-of-service vulnerabilities and seven spoofing vulnerabilities, according to Bleeping Computer.
The MSHTML vulnerability exploits an issue with the Internet Explorer web browser, making it the fourth such MSHTML vulnerability to be exploited in the wild in 2024, Brian Krebs reported Tuesday. Security Week reported that the MSHTML platform has been widely targeted by ransomware and advanced nation-state hacking teams.
The Microsoft Management Console vulnerability allows attackers who leverage malicious Microsoft Saved Console (MSC) files to execute remote code on targeted systems, according to Security Week.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-patch-tuesday-october-2024-117-updates/