Microsoft fixes 6 zero-days under active attack
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-21302 | Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance for blocking rollback of virtualization-based security related updates and the Recommended Actions section of this CVE for guidance on how to protect your systems from this vulnerability. An elevation of privilege vulnerability exists in Windows based systems supporting Virtualization Based Security (VBS), including a subset of Azure Virtual Machine SKUS. This vulnerability enables an attacker with administrator privileges to replace current versions of Windows system files with outdated versions. By exploiting this vulnerability, an attacker could reintroduce previously mitigated vulnerabilities, circumvent some features of VBS, and exfiltrate data protected by VBS. Update: July 10, 2025 Microsoft has addressed this vulnerability for Windows 10 1507, Windows 10, version 1607, Windows 10, version 1809, and Windows Server 2016 and Windows Server 2018. This ensures that mitigations are available to protect all supported versions of Windows 10 and Windows 11 from this vulnerability. See the available mitigations and deployment guidelines described in KB5042562: Guidance for blocking rollback of virtualization-based security related updates. Update: August 13, 2024 Microsoft has released the August 2024 security updates that include an opt-in revocation policy mitigation to address this vulnerability. Customers running affected versions of Windows are encouraged to review KB5042562: Guidance for blocking rollback of virtualization-based security related updates to assess if this opt-in policy meets the needs of their environment before implementing this mitigation. There are risks associated with this mitigation that should be understood prior to applying it to your systems. Detailed information about these risks is also available in KB5042562. Details: A security researcher informed Microsoft of an elevation of privilege vulnerability in Windows 10, Windows 11, Windows Server 2016, and higher based systems including Azure Virtual Machines (VM) that support VBS. For more information on Windows versions and VM SKUs supporting VBS, reference: Virtualization-based Security (VBS) | Microsoft Learn. The vulnerability enables an attacker with administrator privileges on the target system to replace current Windows system files with outdated versions. Successful... See more at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21302 NVD description · AI analysis pending | 6.7 | 2% |
| — | ||
| CVE-2024-38063 +1 in the same advisory: …38199 | Windows TCP/IP Remote Code Execution Vulnerability Windows TCP/IP Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.8 | 71% |
| — | ||
| CVE-2024-38193 | Use-After-Free Privilege Escalation in Microsoft Windows WinSock Driver (afd.sys) The Windows Ancillary Function Driver for WinSock (afd.sys) contains a use-after-free flaw (CWE-416) that allows a local attacker to escalate privileges. An attacker who can already execute code on a Windows host — typically after gaining initial access via phishing, malware, or chaining with another vulnerability — triggers the bug to gain SYSTEM-level privileges, giving them near-full control of the machine. Any Windows host running an affected build is exposed to the flaw, though it requires local code execution and is not remotely exploitable on its own. Exploitation is confirmed in the wild: CISA added the CVE to the KEV catalog on 2024-08-13 and Microsoft shipped fixes in its August 2024 security updates, while the ransomware association is currently listed as unknown. EPSS is elevated at 28.5% (98th percentile), indicating a high likelihood of continued exploitation over the next 30 days. Do: Apply Microsoft's August 2024 Windows cumulative security updates (released 2024-08-13) across all Windows clients and servers, prioritizing multi-user hosts such as RDS/VDI servers and jump boxes where local code execution by low-privileged users is more likely. After patching, verify installed build numbers and hunt for signs of local privilege escalation, per CISA's KEV required action to apply vendor mitigations or discontinue use. Keep the host within your KEV remediation SLA, as listing in the catalog signals active exploitation. | 7.8 group max | 29% | KEV PoC |
| mass>1 billion Windows endpoints worldwide, i.e., effectively every unpatched Windows client or server | |
| CVE-2024-38109 | An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network. An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network. NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2024-38189 | Input-validation RCE in Microsoft Project via crafted project files CVE-2024-38189 is an improper input validation (CWE-20) remote code execution flaw in Microsoft Project. Triggering it requires user interaction: an attacker supplies a maliciously crafted Project file, and when a user opens it, the parsing flaw allows attacker-controlled input to execute code. Successful exploitation yields code execution in the context of the user who opened the file, with high impact to confidentiality, integrity, and availability on that endpoint. Per the CPE data, affected deployments include Project 2016 and the Project client shipped with Office 2019, Office LTSC, and Microsoft 365 Apps. The flaw was one of six zero-days Microsoft patched in its August 2024 Patch Tuesday release and was confirmed to be exploited in the wild, earning a CISA KEV listing on 2024-08-13; EPSS assigns an 8.2% 30-day exploitation probability (95th percentile), and no public PoC is known. Do: Apply Microsoft's August 2024 Patch Tuesday security updates for Microsoft Project/Office (covering Project 2016 and the Project client in Office 2019, Office LTSC, and Microsoft 365 Apps) immediately, per the CISA KEV required action; as an interim measure, caution users against opening Project files from untrusted sources until patched. After updating, verify that the installed Project/Office build reflects the August 2024 security updates. | 8.8 | 8% | KEV |
| mass≈ millions of enterprise desktop installations (Project desktop is a standard tool across Microsoft's hundreds-of-millions-strong Microsoft 365/Office… | |
| CVE-2024-38200 | Microsoft Office Spoofing Vulnerability Microsoft Office Spoofing Vulnerability NVD description · AI analysis pending | 6.5 | 20% |
| — | ||
| CVE-2024-38202 | Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privilege Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some features of Virtualization Based Security (VBS). However, an attacker attempting to exploit this vulnerability requires additional interaction by a privileged user to be successful. Microsoft has developed a security update to mitigate this threat which was made available October 08, 2024 and is provided in the Security Updates table of this CVE for customers to download. Note: Depending on your version of Windows, additional steps may be required to update Windows Recovery Environment (WinRE) to be protected from this vulnerability. Please refer to the FAQ section for more information. Guidance for customers who cannot immediately implement the update is provided in the Recommended Actions section of this CVE to help reduce the risks associated with this vulnerability and to protect their systems. If there are any further updates regarding mitigations for this vulnerability, this CVE will be updated and customers will be notified. We highly encourage customers to subscribe to Security Update Guide notifications to receive an alert if an update occurs. Details A security researcher informed Microsoft of an elevation of privilege vulnerability in Windows Update potentially enabling an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some features of VBS. For exploitation to succeed, an attacker must trick or convince an Administrator or a user with delegated permissions into performing a system restore which inadvertently triggers the vulnerability. Microsoft has developed a security update to mitigate this threat which was made available October 08, 2024 and is provided in the Security Updates table of this CVE for customers to download. Note: Depending on your version of Windows, additional steps may be required to update Windows Recovery Environment (WinRE) to be protected from this vulnerability. Please refer to the FAQ section for more information. Guidance for customers who cannot immediately implement the update is provided in the Recommended Actions section of this CVE to help reduce the risks associated with this vulnerability and to protect their systems. If there are any further... See more at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38202 NVD description · AI analysis pending | 7.3 | 2% |
| — | ||
| CVE-2024-38206 | An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network. An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network. NVD description · AI analysis pending | 6.5 | 12% |
| — |
Full article1,219 words · extracted from helpnetsecurity.com · click to collapse
August 2024 Patch Tuesday is here, and Microsoft has delivered fixes for 90 vulnerabilities, six of which have been exploited in the wild as zero-days, and four are publicly known.

The zero-days under attack
CVE-2024-38178 is a Scripting Engine Memory Corruption Vulnerability that could lead to remote code execution. Reported by AhnLab and South Korea’s National Cyber Security Center (NCSC), the flaw can be successfully exploited only if the target uses Microsoft Edge in Internet Explorer Mode.
This attack requires an authenticated client (user) to click on a specially crafted URL for an unauthenticated attacker to initiate remote code execution, Microsoft says.
“While [Microsoft Edge in Internet Explorer Mode] is not the default mode for most users, this exploit being actively exploited suggests that there are occasions in which the attacker can set this or has identified an organization (or user) that has this configuration,” says Kevin Breen, Senior Director Cyber Threat Research at Immersive Labs.
CVE-2024-38106 is a bug in the Windows Kernel that could be exploited by attackers to gain SYSTEM privileges. To exploit the vulnerability, the attacker must win a race condition – a non-trivial endeavor – but as Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative noted, some races are easier to run than others.
“It’s times like this where the CVSS can be misleading. Race conditions do lead to complexity high in the CVSS score, but with attacks in the wild, it’s clear this bug is readily exploitable,” he added.
CVE-2024-38107 is another bug that allows privilege escalation, and it’s found in Windows Power Dependency Coordinator, which helps Windows devices to wake from “sleep” instantly. The exploitation vector is “local”, so either an attacker can access the target system locally, or can trick the user into performing the actions required. Unfortunately, Microsoft does not offer more details about the in-the-wild exploitation.
CVE-2024-38193, found in Windows Ancillary Function Driver for WinSock, can also lead to privilege escalation and can also only be exploited “locally”. Again, Microsoft does not offer any specific details, but the identity of the reporters – Luigino Camastra and Martin a Milánek with Gen Digital (i.e., its subsidiary Avast) – may point to the goal of the attack: malware execution with SYSTEM privileges.
CVE-2024-38213 allows attackers to bypass the Windows SmartScreen, which is triggered by a Windows Mark of the Web “flag” added to files downloaded from untrusted locations (e.g., the internet). “An attacker must send the user a malicious file and convince them to open it,” Microsoft says, and this is obviously happening in the wild.
“This vulnerability is not exploitable on its own and is typically seen as part of an exploit chain, for example, modifying a malicious document or exe file to include this bypass before sending the file via email or distributing on compromised websites,” says Breen.
Peter Girnus, a researcher with Trend Micro who flagged this bug, is expected to reveal more about it and possibly by the attacks exploiting it on Thursday.
Finally, CVE-2024-38189 is a vulnerability in Microsoft Project that can be triggered by tricking targets into opening a specially crafted Project file on a system where the Block macros from running in Office files from the Internet policy is disabled and VBA Macro Notification Settings are not enabled.
The vulnerability could allow attackers to achieve remote code execution on the host, Microsoft warns.
“It’s definitely odd to see a code execution bug in Project, but not only do we have one here, it’s being exploited in the wild. For the most part, this is your typical open-and-own bug, but in this case, the target allows macros to run from the internet,” Childs commented.
“This is not dissimilar to many common phishing attacks where threat actors will name their weaponised documents to play on human social behaviors, socially engineering them into opening the file. Examples include fake invoices, internal salary documents, and even thematic lures for individuals in more targeted attacks,” Breen pointed out.
The publicly known vulnerabilities
CVE-2024-38200, a spoofing vulnerability affecting Microsoft Office unearthed by Jim Rush of PrivSec Consulting and Metin Yunus Kandemir with Synack’s Red Team, may allow attackers to grab and relay the target’s NTLM hash.
An alternative fix has already been put in place by Microsoft, but users are advised to implement the final one released today.
CVE-2024-21302, an EoP flaw in Windows Secure Kernel Mode, and CVE-2024-38202, an EoP in the Windows Update Stack, were revealed by SafeBreach researcher Alon Leviev at Black Hat last week.
They can be leveraged for a covert downgrade attack, making vulnerable Windows machine even more vulnerable by reintroducing previously mitigated vulnerabilities.
CVE-2024-21302 has a fix (sort of), which includes deploying a Microsoft-signed revocation policy. A fix for CVE-2024-38202 is still in the works, but mitigations have been outlined.
CVE-2024-38199 is a use-after-free flaw in the Windows Line Printer Daemon (LPD) Service that can be exploited by an unauthenticated attacker sending a specially crafted print task to a shared vulnerable Windows Line Printer Daemon (LPD) service across a network.
“Successful exploitation could result in remote code execution on the server,” Microsoft says, but the good news is that LDP has been deprecated for over 10 years and – more importantly – it is not installed or enabled on the systems by default. Still, if you are running LPD, definitely treat this as a Critical update, Childs advised.
The Mark of the Web bypass that has been used for years by attackers to avoid Windows SmartScreen and Smart App Control has not been fixed this time around.
To wrap it up, let’s mention that several of the critical vulnerabilities fixed that require no action from customers to resolve.
This group includes two server-side request forgery (SSRF) flaws discovered by Tenable researchers, one (CVE-2024-38206) in Microsoft’s Copilot Studio (an AI-powered chatbot) that could lead to information disclosure, and the other (CVE-2024-38109) affecting Azure Health Bot, which can be abused to escalate privileges and access cross-tenant resources.
UPDATE (August 14, 2024, 05:53 a.m. ET):
The number of exploited and public vulnerabilities has somewhat obscured the importance of a quick implementation of the patch for CVE-2024-38063.
CVE-2024-38063 is a critical flaw in Windows TCP/IP that could allow remote code execution on Windows and Windows Server machines that have IPv6 enabled.
“An unauthenticated attacker could repeatedly send IPv6 packets, that include specially crafted packets, to a Windows machine which could enable remote code execution,” Microsoft says, and assesses that the vulnerability is more likely to be exploited, because “exploit code could be created in such a way that an attacker could consistently exploit this vulnerability,” and because “Microsoft is aware of past instances of this type of vulnerability being exploited.”
IPv6 support is enabled by default on Windows and Windows Server machines and, in general, Microsoft advises against disabling it – especially on the latter.
The reporter of the vulnerability – Xiao Wei at Cyber KunLun’s KunLun Lab – says that “the bug triggers before [local firewall] handling the packet,” which means that blocking IPv6 on it won’t help against exploits. Another reason to patch this bug quickly!

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/08/13/microsoft-zero-days-under-attack/