ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Microsoft Issues Patches for 79 Flaws, Including 3 Actively Exploited Windows Flaws

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-43461
+2 in the same advisory: …38014 …38217
Windows MSHTML Platform Spoofing Vulnerability Exploited as Zero-Day (CVE-2024-43461)

CVE-2024-43461 is a spoofing vulnerability (CWE-451, user interface misrepresentation) in the Windows MSHTML platform that lets attacker-controlled content misrepresent critical UI information to users. The attack is network-delivered and succeeds when a victim interacts with crafted content — such as opening a malicious file or link rendered by MSHTML — so they believe they are handling something benign (public reporting ties the observed campaign to malicious shortcut files that appeared to be ordinary documents). Successful exploitation deceives the user and, given the high confidentiality, integrity, and availability ratings in the CVSS score, can support follow-on compromise, including delivery of attacker-supplied payloads by the Void Banshee APT. Anyone running the affected Windows releases — Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2 through 24H2), and Windows Server 2008, 2012, and 2016 — is in scope. The flaw was exploited in the wild as a zero-day before it was patched in Microsoft's September 2024 updates, was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-16, and no public PoC is known.

Do: Apply Microsoft's September 2024 cumulative Windows security updates to all Windows 10/11 and Windows Server 2008/2012/2016 systems, prioritizing user workstations since exploitation requires user interaction, per the CISA KEV required action. Hunt for Void Banshee APT lures — files or shortcuts whose displayed type does not match their true format — and verify patched build status across the estate, as an earlier related fix was reportedly lost to a code defect and reissued.

8.8
group max
54% KEV
  • Microsoft Windows 10 1507 1507
  • Microsoft Windows 10 1607 1607
  • Microsoft Windows 10 1809 1809
  • +9 more
masshundreds of millions to 1+ billion Windows client and server installations (MSHTML is a core component of every listed Windows release)
CVE-2024-38112
Windows MSHTML Platform Spoofing Vulnerability Exploited in the Wild (CVE-2024-38112)

CVE-2024-38112 is a spoofing flaw (CWE-451) in the Microsoft Windows MSHTML platform, the Windows component used to render web content, including by applications that embed the legacy Internet Explorer engine. It is triggered when a user interacts with attacker-controlled content rendered through MSHTML: the attack requires no privileges, travels over the network, and needs user interaction (UI:R per its CVSS vector), letting an attacker misrepresent critical UI information to the victim. Despite being classified as spoofing, the CVSS impact scores are high across confidentiality, integrity, and availability, and the CVSS base score is 7.5 (High). Any system running the affected Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), or Windows Server (2008, 2012, 2016, 2019) releases is affected. Exploitation is confirmed in the wild: Microsoft patched it as an actively exploited zero-day in July 2024, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-09, and reporting indicates it had been exploited for over a year before the fix.

Do: Apply Microsoft's July 2024 security updates (Patch Tuesday) across all affected Windows 10, Windows 11, and Windows Server versions, prioritizing internet-facing and user workstations given confirmed in-the-wild exploitation and the 84.2% EPSS score. Until patched, remind users to avoid interacting with untrusted web or document content, since exploitation requires user interaction. Track the fix against CISA's KEV catalog deadlines and verify patch status on all endpoints.

7.584% KEV
  • Microsoft Windows 10 1507
  • Microsoft Windows 10 1607
  • Microsoft Windows 10 1809
  • +9 more
masshundreds of millions of Windows devices (essentially all desktops and servers on the listed Windows 10/11 and Windows Server releases)
CVE-2024-38226
Actively Exploited Security Feature Bypass in Microsoft Publisher

CVE-2024-38226 is a security feature bypass (protection mechanism failure, CWE-693) in Microsoft Publisher, rated 7.3 High with a local attack vector, low privileges required, and user interaction required. An attacker triggers it by convincing a user to open a maliciously crafted Publisher file, which defeats Publisher's built-in protection mechanism, allowing the attacker's content to bypass the expected security checks, with high impact rated for confidentiality, integrity, and availability. Users of Publisher as shipped in Microsoft Office 2019 and Microsoft Office Long Term Servicing Channel (LTSC) are affected. The flaw was patched in Microsoft's September 2024 Patch Tuesday, counted among the four actively exploited Microsoft zero-days that month, and CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-10, confirming exploitation in the wild; ransomware use is listed as unknown.

Do: Apply the September 2024 Microsoft security updates for Office 2019/LTSC (Publisher) across all endpoints, prioritizing systems with Publisher installed, per the vendor's instructions or the CISA KEV required action. Until patched, warn users to exercise caution with .pub files from untrusted sources, since exploitation requires opening a crafted file. Confirm no Publisher clients remain on outdated builds after deployment.

7.33% KEV
  • Microsoft Publisher (shipped with Microsoft Office 2019)
  • Microsoft Publisher (shipped with Microsoft Office Long Term Servicing Channel, LTSC)
massmillions of users (Publisher is bundled with enterprise perpetual-license Office 2019/LTSC suites; no precise public install counts for these channels)
CVE-2024-43491
Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, ve

Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these previously mitigated vulnerabilities on Windows 10, version 1507 (Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB) systems that have installed the Windows security update released on March 12, 2024—KB5035858 (OS Build 10240.20526) or other updates released until August 2024. All later versions of Windows 10 are not impacted by this vulnerability. This servicing stack vulnerability is addressed by installing the September 2024 Servicing stack update (SSU KB5043936) AND the September 2024 Windows security update (KB5043083), in that order. Note: Windows 10, version 1507 reached the end of support (EOS) on May 9, 2017 for devices running the Pro, Home, Enterprise, Education, and Enterprise IoT editions. Only Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB editions are still under support.

NVD description · AI analysis pending
9.812%
  • microsoft windows 10 1507
Full article919 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananSep 11, 2024Windows Security / Vulnerability

Microsoft on Tuesday disclosed that three new security flaws impacting the Windows platform have come under active exploitation as part of its Patch Tuesday update for September 2024.

The monthly security release addresses a total of 79 vulnerabilities, of which seven are rated Critical, 71 are rated Important, and one is rated Moderate in severity. This is aside from 26 flaws that the tech giant resolved in its Chromium-based Edge browser since last month's Patch Tuesday release.

The three vulnerabilities that have been weaponized in a malicious context are listed below, alongside a bug that Microsoft is treating as exploited -

  • CVE-2024-38014 (CVSS score: 7.8) - Windows Installer Elevation of Privilege Vulnerability
  • CVE-2024-38217 (CVSS score: 5.4) - Windows Mark-of-the-Web (MotW) Security Feature Bypass Vulnerability
  • CVE-2024-38226 (CVSS score: 7.3) - Microsoft Publisher Security Feature Bypass Vulnerability
  • CVE-2024-43491 (CVSS score: 9.8) - Microsoft Windows Update Remote Code Execution Vulnerability

"Exploitation of both CVE-2024-38226 and CVE-2024-38217 can lead to the bypass of important security features that block Microsoft Office macros from running," Satnam Narang, senior staff research engineer at Tenable, said in a statement.

"In both cases, the target needs to be convinced to open a specially crafted file from an attacker-controlled server. Where they differ is that an attacker would need to be authenticated to the system and have local access to it to exploit CVE-2024-38226."

As disclosed by Elastic Security Labs last month, CVE-2024-38217 – also referred to as LNK Stomping – is said to have been abused in the wild as far back as February 2018.

CVE-2024-43491, on the other hand, is notable for the fact that it's similar to the downgrade attack that cybersecurity company SafeBreach detailed early last month.

"Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015)," Redmond noted.

"This means that an attacker could exploit these previously mitigated vulnerabilities on Windows 10, version 1507 (Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB) systems that have installed the Windows security update released on March 12, 2024 — KB5035858 (OS Build 10240.20526) or other updates released until August 2024."

The Windows maker further said it can be resolved by installing the September 2024 Servicing stack update (SSU KB5043936) and the September 2024 Windows security update (KB5043083), in that order.

It's also worth pointing out that Microsoft's "Exploitation Detected" assessment for CVE-2024-43491 stems from the rollback of fixes that addressed vulnerabilities impacting certain Optional Components for Windows 10 (version 1507), some of which have been previously exploited.

"No exploitation of CVE-2024-43491 itself has been detected," the company said. "In addition, the Windows product team at Microsoft discovered this issue, and we have seen no evidence that it is publicly known."

Software Patches from Other Vendors

In addition to Microsoft, security updates have also been released by other vendors over the past few weeks to rectify several vulnerabilities, including —

Update

Microsoft on Friday updated the advisory for CVE-2024-43461 to reveal that the vulnerability has been actively exploited in the wild by a threat actor known as Void Banshee, bringing the tally to four zero-day bugs that were patched by the company this month.

The vulnerability, tracked as CVE-2024-43461 (CVSS score: 8.8), has been characterized as an MSHTML platform spoofing vulnerability similar to CVE-2024-38112, which was exploited by the threat actor to deliver Atlantida stealer malware.

"CVE-2024-43461 was exploited as a part of an attack chain relating to CVE-2024-38112, prior to July 2024," Microsoft noted in the bulletin. "We released a fix for CVE-2024-38112 in our July 2024 security updates which broke this attack chain."

The disclosure comes as SEC Consult revealed details of CVE-2024-38014, a privilege escalation flaw in the Windows Installer component that could enable a malicious actor to gain SYSTEM privileges.

"The MSI file format allows to create standardized installers that can install, remove, and repair software," security researcher Michael Baer said. "While the installation and removal of software usually requires elevated permissions, the repair function for already installed software can be performed by a low-privileged user.

"The issued repair functions can, however, be executed under the context of NT AUTHORITY\SYSTEM, a very high access right in Windows. If an attacker is able to maliciously interfere with those functions, a privilege escalation attack is possible."

However, there are a few caveats: The exploit requires GUI access and a supported browser, such as Google Chrome or Mozilla Firefox. It does not work on recent versions of Microsoft's Edge browser.

(The story was updated after publication on September 16, 2024, to reflect the active exploitation of CVE-2024-43461.)

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/09/microsoft-issues-patches-for-79-flaws.html