ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz1

Microsoft fixes 4 exploited zero-days and a code defect that nixed earlier security fixes

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-43461
+2 in the same advisory: …38014 …38217
Windows MSHTML Platform Spoofing Vulnerability Exploited as Zero-Day (CVE-2024-43461)

CVE-2024-43461 is a spoofing vulnerability (CWE-451, user interface misrepresentation) in the Windows MSHTML platform that lets attacker-controlled content misrepresent critical UI information to users. The attack is network-delivered and succeeds when a victim interacts with crafted content — such as opening a malicious file or link rendered by MSHTML — so they believe they are handling something benign (public reporting ties the observed campaign to malicious shortcut files that appeared to be ordinary documents). Successful exploitation deceives the user and, given the high confidentiality, integrity, and availability ratings in the CVSS score, can support follow-on compromise, including delivery of attacker-supplied payloads by the Void Banshee APT. Anyone running the affected Windows releases — Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2 through 24H2), and Windows Server 2008, 2012, and 2016 — is in scope. The flaw was exploited in the wild as a zero-day before it was patched in Microsoft's September 2024 updates, was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-16, and no public PoC is known.

Do: Apply Microsoft's September 2024 cumulative Windows security updates to all Windows 10/11 and Windows Server 2008/2012/2016 systems, prioritizing user workstations since exploitation requires user interaction, per the CISA KEV required action. Hunt for Void Banshee APT lures — files or shortcuts whose displayed type does not match their true format — and verify patched build status across the estate, as an earlier related fix was reportedly lost to a code defect and reissued.

8.8
group max
54% KEV
  • Microsoft Windows 10 1507 1507
  • Microsoft Windows 10 1607 1607
  • Microsoft Windows 10 1809 1809
  • +9 more
masshundreds of millions to 1+ billion Windows client and server installations (MSHTML is a core component of every listed Windows release)
CVE-2024-38018
+3 in the same advisory: …43464 …38227 …38228
Authenticated deserialization RCE in Microsoft SharePoint Server

CVE-2024-38018 is a remote code execution vulnerability in on-premises Microsoft SharePoint Server caused by insecure deserialization of untrusted data (CWE-502). Per its CVSS vector (network attack vector, low attack complexity, low privileges required, no user interaction), an attacker who has obtained low-privileged authenticated access to a network-reachable SharePoint server can trigger the flaw by submitting maliciously crafted serialized data. Successful exploitation yields arbitrary code execution with high impact on confidentiality, integrity, and availability (CVSS 8.8, High). Organizations running on-premises SharePoint Server are affected; the advisory is scoped to the on-premises product rather than SharePoint Online/Microsoft 365. No public proof-of-concept is known and it is not yet in CISA's KEV catalog, but its EPSS of ~51.5% (99th percentile) signals a high likelihood of exploitation within 30 days, and related reporting notes a Microsoft servicing code defect caused the earlier (July 2024) fix to be nixed, so some deployments may still be unpatched.

Do: Install the latest SharePoint Server security update (September 2024 or later) on every on-premises SharePoint server, and because related reporting says a servicing defect caused the July 2024 fixes to be lost or removed, verify the patch actually applied and reapply it even if July updates were already installed. Restrict authenticated access to SharePoint (e.g., VPN or network segmentation), monitor these servers for suspicious activity, and treat exploitation risk as elevated given the ~51.5% EPSS score.

8.8
group max
51%
  • Microsoft SharePoint Server (on-premises)
largetens of thousands of internet-exposed SharePoint Server instances, with likely hundreds of thousands of total on-prem deployments
CVE-2024-38226
Actively Exploited Security Feature Bypass in Microsoft Publisher

CVE-2024-38226 is a security feature bypass (protection mechanism failure, CWE-693) in Microsoft Publisher, rated 7.3 High with a local attack vector, low privileges required, and user interaction required. An attacker triggers it by convincing a user to open a maliciously crafted Publisher file, which defeats Publisher's built-in protection mechanism, allowing the attacker's content to bypass the expected security checks, with high impact rated for confidentiality, integrity, and availability. Users of Publisher as shipped in Microsoft Office 2019 and Microsoft Office Long Term Servicing Channel (LTSC) are affected. The flaw was patched in Microsoft's September 2024 Patch Tuesday, counted among the four actively exploited Microsoft zero-days that month, and CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-10, confirming exploitation in the wild; ransomware use is listed as unknown.

Do: Apply the September 2024 Microsoft security updates for Office 2019/LTSC (Publisher) across all endpoints, prioritizing systems with Publisher installed, per the vendor's instructions or the CISA KEV required action. Until patched, warn users to exercise caution with .pub files from untrusted sources, since exploitation requires opening a crafted file. Confirm no Publisher clients remain on outdated builds after deployment.

7.33% KEV
  • Microsoft Publisher (shipped with Microsoft Office 2019)
  • Microsoft Publisher (shipped with Microsoft Office Long Term Servicing Channel, LTSC)
massmillions of users (Publisher is bundled with enterprise perpetual-license Office 2019/LTSC suites; no precise public install counts for these channels)
CVE-2024-43491
Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, ve

Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these previously mitigated vulnerabilities on Windows 10, version 1507 (Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB) systems that have installed the Windows security update released on March 12, 2024—KB5035858 (OS Build 10240.20526) or other updates released until August 2024. All later versions of Windows 10 are not impacted by this vulnerability. This servicing stack vulnerability is addressed by installing the September 2024 Servicing stack update (SSU KB5043936) AND the September 2024 Windows security update (KB5043083), in that order. Note: Windows 10, version 1507 reached the end of support (EOS) on May 9, 2017 for devices running the Pro, Home, Enterprise, Education, and Enterprise IoT editions. Only Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB editions are still under support.

NVD description · AI analysis pending
9.812%
  • microsoft windows 10 1507
Full article886 words · extracted from helpnetsecurity.com · click to collapse

September 2024 Patch Tuesday is here and Microsoft has delivered 79 fixes, including those for a handful of zero-days (CVE-2024-38217, CVE-2024-38226, CVE-2024-38014, CVE-2024-43461) exploited by attackers in the wild, and a Windows 10 code defect (CVE-2024-43491) that rolled back earlier CVE fixes.

CVE-2024-38217 CVE-2024-43491

The actively exploited flaws

Let’s start with the only one that was previously publicly known: CVE-2024-38217, a vulnerability that allows attackers to bypass Mark of the Web (MotW).

Elastic Security researcher Joe Desimone reported the vulnerability being exploited by attackers for years by crafting Windows shortcut files (.LNK) with non-standard target paths or internal structures.

Such a file would force Windows to “rewrite” it and remove the MotW metadata, resulting in – according to Microsoft – a limited loss of integrity and availability of security features such as SmartScreen Application Reputation security check and/or the legacy Windows Attachment Services security prompt.”

Next we have CVE-2024-38226, another vulnerability that allows attackers to bypass a security feature. This vulnerability affects Microsoft Publisher, a standalone application that’s also included in some versions of Microsoft Office.

“The attack itself is carried out locally by a user with authentication to the targeted system. An authenticated attacker could exploit the vulnerability by convincing a victim, through social engineering, to download and open a specially crafted file from a website which could lead to a local attack on the victim computer,” Microsoft explained in the associated advisory.

Obviously, someone managed to do it, and thus bypass Office macro policies to execute malicious code on the targeted machine(s). Unfortunately, Microsoft did not share who reported the flaw, so we can’t even speculate about the nature of the attack this vulnerability has been used in.

Another exploited zero-day Microsoft fixed this time around is CVE-2024-38014, a vulnerability in Windows Installer that may allow authenticated attackers to elevate their privileges to SYSTEM.

“Interestingly, Microsoft states that no user interaction is required for this bug, so the actual mechanics of the exploit may be odd. Still, privilege escalations like this are typically paired with a code execution bug to take over a system. Test and deploy this fix quickly,” advises Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative.

Satnam Narang, senior staff research engineer at Tenable, pointed out that because elevation of privilege vulnerabilities are related to post-compromise activity, they may not receive as much attention as remote code execution bugs.

“But, they are highly valuable to attackers as they are able to inflict more damage or compromise more data, and it is important for organizations to ensure they patch these flaws to cut off attack paths and prevent future compromise,” he added.

CVE-2024-43461, a Windows MSHTML Platform spoofing vulnerability, is not currently described as being exploited in the wild, though Childs says it should.

“This bug is similar to the vulnerability we reported and was patched back in July. The ZDI Threat Hunting team discovered this exploit in the wild and reported it to Microsoft back in June. It appears threat actors quickly bypassed the previous patch,” he noted.

“When we told Microsoft about the bug, we indicated it was being actively used. We’re not sure why they don’t list it as being under active attack, but you should treat it as though it were, especially since it affects all supported versions of Windows.”

Other vulnerabilities of note

CVE-2024-43491 is an interesting vulnerability that has effectively rolled back the fixes for some vulnerabilities affecting Optional Components – e.g., Internet Explorer 11, Windows Media Player, MSMQ server core, etc. – on Windows 10, version 1507.

“This specific vulnerability impacted the Windows update system in a way that security patches for some components were rolled back to a vulnerable state and will have remained in a vulnerable state since March 2024,” Kevin Breen, Senior Director Threat Research at Immersive Labs, told Help Net Security.

“Some of these components were known to be exploited in the wild in the past, meaning attackers could still exploit them despite Windows update saying it is fully patched.”

But, according to Microsoft, no exploitation of CVE-2024-43491 itself has been detected. “In addition, the Windows product team at Microsoft discovered this issue, and we have seen no evidence that it is publicly known.”

The other good news is that only a small share of Windows 10 systems is affected. Users / admins should check the advisory to see whether their machine(s) are affected and install “the September 2024 Servicing stack update (SSU KB5043936) AND the September 2024 Windows security update (KB5043083), in that order.”

Among the patched vulnerabilities Microsoft deems more likely to be exploited are four vulnerabilities in Microsoft Sharepoint (CVE-2024-38018, CVE-2024-38227, CVE-2024-38228, CVE-2024-43464) that could be exploited to achieve remote code execution on the SharePoint Server. All four require the attacker to be authenticated to begin exploitation, but SharePoint admins would do well to implement fixes for those.

UPDATE (September 12, 2024, 10:05 a.m. ET):

SEC Consult has published a blog post explaining how CVE-2024-38014, the Windows Installer EoP vulnerability, can be exploited.

Michael Baer, the researcher who unearthed the vulnerability, has also created an open source tool for scanning Microsoft Windows *.msi Installer files for potential vulnerabilities.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/09/10/cve-2024-38217-cve-2024-43491/