Largest Patch Tuesday in 3 months includes 5 critical vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-38021 | Microsoft Outlook Remote Code Execution Vulnerability Microsoft Outlook Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.8 | 3% |
| — | ||
| CVE-2024-38023 +1 in the same advisory: …38024 | Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability NVD description · AI analysis pending | 7.2 | 53% |
| — | ||
| CVE-2024-38060 | Windows Imaging Component Remote Code Execution Vulnerability Windows Imaging Component Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.8 | 16% |
| — | ||
| CVE-2024-38062 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability Windows Kernel-Mode Driver Elevation of Privilege Vulnerability NVD description · AI analysis pending | 7.8 | 2% |
| — | ||
| CVE-2024-38077 +1 in the same advisory: …38074 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.8 | 84% |
| — | ||
| CVE-2024-38076 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2024-38080 | Actively Exploited Local Privilege Escalation in Microsoft Windows Hyper-V CVE-2024-38080 is an integer-overflow (CWE-190) elevation-of-privilege vulnerability in the Windows Hyper-V component, rated 7.8 (High). It is triggered locally: an attacker who can already run low-privileged code on an affected Windows 11 or Windows Server 2022 host can exploit it without user interaction. Successful exploitation allows the attacker to elevate privileges, with high impact on confidentiality, integrity, and availability of the affected system. Affected systems include Windows 11 21H2, 22H2, and 23H2 and Windows Server 2022 (including the 2022 23H2 update) running the vulnerable Hyper-V code. Microsoft patched the flaw in its July 2024 Patch Tuesday release, and it is being actively exploited in the wild; it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-07-09 alongside the other actively exploited July zero-day, CVE-2024-38112. Do: Apply Microsoft's July 2024 (July 9, 2024 Patch Tuesday) cumulative security updates for Windows 11 21H2/22H2/23H2 and Windows Server 2022 immediately, prioritizing hosts and endpoints where the Hyper-V platform or role is enabled; per CISA KEV requirements, federal agencies must apply the vendor fixes within the mandated deadline. Inventory systems running the affected versions, confirm the update is installed after reboot, and restrict untrusted local code execution on Hyper-V hosts until patching is complete. | 7.8 | 7% | KEV |
| massplausibly >1,000,000 systems | |
| CVE-2024-38094 | Authenticated deserialization RCE in Microsoft SharePoint Server CVE-2024-38094 is a deserialization of untrusted data flaw (CWE-502) in on-premises Microsoft SharePoint Server, rated 7.2 (high) on CVSS 3.1 and classified by Microsoft as a remote code execution vulnerability. The CVSS vector (AV:N/AC:L/PR:H/UI:N) indicates the attack is network-reachable but requires an attacker who already holds high-privileged access, such as site collection or farm administrator credentials, to submit maliciously crafted serialized data to the server. Successful exploitation yields remote code execution on the SharePoint server with high impact to confidentiality, integrity, and availability, giving attackers a foothold for follow-on activity such as ransomware deployment. Any organization running on-premises SharePoint Server is potentially affected, while SharePoint Online in Microsoft 365 is a separate cloud service. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-10-22 with known ransomware use, and the EPSS of 50.9% (99th percentile) signals a high probability of continued exploitation, although no public proof-of-concept is known. Do: Apply Microsoft's vendor-supplied mitigations and security updates for SharePoint Server as soon as possible; CISA's required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Limit internet exposure of SharePoint front-ends, review high-privileged site and farm administrator accounts for compromise or unusual activity, and prioritize patching given the confirmed ransomware use. No public PoC is known, but the 50.9% EPSS and KEV listing indicate attackers are actively working this flaw. | 7.2 | 51% | KEV ransomware |
| largeon the order of tens of thousands of internet-exposed SharePoint Server deployments (roughly 10k-100k servers) |
Full article561 words · extracted from blog.talosintelligence.com · click to collapse
Tuesday, July 9, 2024 14:01
Microsoft released its monthly security update on Tuesday, disclosing 142 vulnerabilities across its suite of products and software. Of those, there are five critical vulnerabilities, and every other security issue disclosed this month is considered "important."
This is the largest Patch Tuesday since April when Microsoft patched 150 vulnerabilities.
Of the critical vulnerabilities, two are considered more likely to be exploited:
CVE-2024-38023, a remote code execution vulnerability in Microsoft SharePoint server, where an authenticated attacker with Site Owner permissions can use the vulnerability to execute arbitrary code in the context of SharePoint server.
CVE-2024-38060, a remote code execution vulnerability in Microsoft Windows Codecs Library that can be exploited by an authenticated attacker who uploads a specially crafted malicious TIFF file.
There are three other critical vulnerabilities listed in this advisory. All three (CVE-2024-38074, CVE-2024-38076 and CVE-2024-38077) are remote code execution vulnerabilities in Windows Remote Desktop Licensing Service. In all of them, an attacker could send a specially crafted network packet which could cause remote code execution. In the case of CVE-2024-38077, the adversary does not need to be authenticated.
All the remaining vulnerabilities are considered important. Of these, CVE-2024-38080 is particularly relevant because Microsoft has acknowledged that it’s already being exploited in the wild. An adversary could exploit this elevation of privilege vulnerability in Windows Hyper-V to gain System privileges.
Cisco Talos' Vulnerability Research team discovered another elevation of privilege vulnerability, CVE-2024-38062, in the kernel-mode driver. An adversary could also exploit this vulnerability to gain System privileges. Microsoft considers the complexity of this attack to be "low," though it's "less likely" to be exploited.
Several other “important” vulnerabilities could lead to remote code execution and are identified by Microsoft as being “more likely” to be exploited.
CVE-2024-38021 is a remote code execution vulnerability in Microsoft Office. An attacker could craft a malicious link that bypasses the Protected View Protocol, leading to the leaking of local NTLM credentials and remote code execution.
CVE-2024-38024 is a remote code execution vulnerability in Microsoft SharePoint Server. An adversary could exploit this issue by uploading a specially crafted file to the targeted SharePoint Server and crafting specialized API requests to trigger the deserialization of a file's parameters, leading to arbitrary code execution in the context of the SharePoint server. However, this attacker would need to have Site Owner permissions or higher.
CVE-2024-38094 is another vulnerability in SharePoint servers. Adversaries with Site Owner permissions can use this vulnerability to inject arbitrary code and execute code in the context of a SharePoint server.
A complete list of all the vulnerabilities Microsoft disclosed this month is available on its update page.
In response to these vulnerability disclosures, Talos is releasing a new Snort rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date, and current rules are subject to change pending additional information. Cisco Secure Firewall customers should use the latest update to their rule set by updating their SRU. Open-source Snort Subscriber Rule Set customers can stay up-to-date by downloading the latest rule pack available for purchase on Snort.org.
The rules included in this release that protect against the exploitation of many of these vulnerabilities are 63687 - 63690, 63693, 63694 and 63697 - 63700. There are also Snort 3 rules 300958 - 300961.
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-july-2024/