ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Microsoft's January 2024 Windows Update Patches 48 New Vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-7024
Actively Exploited Heap Buffer Overflow in Google Chrome WebRTC (CVE-2023-7024)

CVE-2023-7024 is a high-severity heap buffer overflow (CWE-787) in the WebRTC component of Google Chrome/Chromium. A remote attacker can trigger it by convincing a user to open a crafted HTML page (user interaction is required per the CVSS score), causing memory corruption in the browser. Successful exploitation can crash the browser or potentially allow arbitrary code execution, with high impact on confidentiality, integrity, and availability. Anyone running Google Chrome prior to 120.0.6099.129 is affected, as are users of Chromium builds packaged by Debian and Fedora. The flaw is being exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-02, and Google addressed it as an actively exploited zero-day — with an EPSS probability of ~7.4% of exploitation within 30 days (94th percentile).

Do: Update Google Chrome to 120.0.6099.129 or later immediately (verify via chrome://settings/help, since many installs auto-update but require a relaunch); organizations on Debian or Fedora should apply their distribution's patched chromium security update. Per CISA KEV requirements, federal agencies must apply vendor mitigations or discontinue use of affected builds by the required deadline. Until patched, avoid opening untrusted web pages, as exploitation requires user interaction with crafted HTML content.

8.87% KEV PoC
  • google Chrome (Chromium browser) All versions prior to 120.0.6099.129
  • Debian Linux (chromium package) Chromium builds prior to 120.0.6099.129; fixed via Debian security updates
  • fedoraproject Fedora (chromium package) Chromium builds prior to 120.0.6099.129; fixed via Fedora security updates
mass≈3 billion+ users/installs (Chrome's global install base)
CVE-2024-0056
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability

Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability

NVD description · AI analysis pending
8.71%
  • microsoft microsoft.data.sqlclient
  • microsoft sql server
  • microsoft system.data.sqlclient
  • +1 more
CVE-2024-20674
+1 in the same advisory: …20653
Windows Kerberos Security Feature Bypass Vulnerability

Windows Kerberos Security Feature Bypass Vulnerability

NVD description · AI analysis pending
8.8
group max
17%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2024-20677
A security vulnerability exists in FBX that could lead to remote code execution.

A security vulnerability exists in FBX that could lead to remote code execution. To mitigate this vulnerability, the ability to insert FBX files has been disabled in Word, Excel, PowerPoint and Outlook for Windows and Mac. Versions of Office that had this feature enabled will no longer have access to it. This includes Office 2019, Office 2021, Office LTSC for Mac 2021, and Microsoft 365. As of February 13, 2024, the ability to insert FBX files has also been disabled in 3D Viewer. 3D models in Office documents that were previously inserted from a FBX file will continue to work as expected unless the Link to File option was chosen at insert time. This change is effective as of the January 9, 2024 security update.

NVD description · AI analysis pending
7.83%
  • microsoft 365 apps
  • microsoft office
  • microsoft office long term servicing channel
CVE-2024-20700
Windows Hyper-V Remote Code Execution Vulnerability

Windows Hyper-V Remote Code Execution Vulnerability

NVD description · AI analysis pending
7.54%
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • microsoft windows 10 22h2
  • +1 more
Full article615 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJan 10, 2024Vulnerability / Windows Security

Microsoft has addressed a total of 48 security flaws spanning its software as part of its Patch Tuesday updates for January 2024.

Of the 48 bugs, two are rated Critical and 46 are rated Important in severity. There is no evidence that any of the issues are publicly known or under active attack at the time of release, making it the second consecutive Patch Tuesday with no zero-days.

The fixes are in addition to nine security vulnerabilities that have been resolved in the Chromium-based Edge browser since the release of December 2023 Patch Tuesday updates. This also includes a fix for a zero-day (CVE-2023-7024, CVSS score: 8.8) that Google said has been actively exploited in the wild.

The most critical among the flaws patched this month are as follows -

  • CVE-2024-20674 (CVSS score: 9.0) - Windows Kerberos Security Feature Bypass Vulnerability
  • CVE-2024-20700 (CVSS score: 7.5) - Windows Hyper-V Remote Code Execution Vulnerability

“The authentication feature could be bypassed as this vulnerability allows impersonation,” Microsoft said in an advisory for CVE-2024-20674.

“An authenticated attacker could exploit this vulnerability by establishing a machine-in-the-middle (MitM) attack or other local network spoofing technique, then sending a malicious Kerberos message to the client victim machine to spoof itself as the Kerberos authentication server.”

However, the company noted that successful exploitation requires an attacker to gain access to the restricted network first. Security researcher ldwilmore34 has been credited with discovering and reporting the flaw.

CVE-2024-20700, on the other hand, neither requires authentication nor user interaction to achieve remote code execution, although winning a race condition is a prerequisite to staging an attack.

“It isn’t clear exactly where the attacker must be located — the LAN on which the hypervisor resides, or a virtual network created and managed by the hypervisor — or in what context the remote code execution would occur,” Adam Barnett, lead software engineer at Rapid7, told The Hacker News.

Other notable flaws include CVE-2024-20653 (CVSS score: 7.8), a privilege escalation flaw impacting the Common Log File System (CLFS) driver, and CVE-2024-0056 (CVSS score: 8.7), a security bypass affecting System.Data.SqlClient and Microsoft.Data.SqlClient.

“An attacker who successfully exploited this vulnerability could carry out a machine-in-the-middle (MitM) attack and could decrypt and read or modify TLS traffic between the client and server," Redmond said about CVE-2024-0056.

Microsoft further noted that it’s disabling the ability to insert FBX files in Word, Excel, PowerPoint, and Outlook in Windows by default due to a security flaw (CVE-2024-20677, CVSS score: 7.8) that could lead to remote code execution.

“3D models in Office documents that were previously inserted from an FBX file will continue to work as expected unless the ‘Link to File’ option was chosen at the insert time,” Microsoft said in a separate alert. “GLB (Binary GL Transmission Format) is the recommended substitute 3D file format for use in Office.”

It’s worth noting that Microsoft took a similar step of disabling the SketchUp (SKP) file format in Office last year following Zscaler's discovery of 117 security flaws in Microsoft 365 applications.

Software Patches from Other Vendors

In addition to Microsoft, security updates have also been released by other vendors over the past few weeks to rectify several vulnerabilities, including -

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/01/microsofts-january-2024-windows-update.html