ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Microsoft Patches One Critical and One Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-50868
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU

The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.

NVD description · AI analysis pending
7.582% PoC
  • netapp hci baseboard management controller
  • netapp active iq unified manager
  • netapp bootstrap os
  • +1 more
CVE-2024-30080
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.843%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2024-30104
+1 in the same advisory: …30101
Microsoft Office Remote Code Execution Vulnerability

Microsoft Office Remote Code Execution Vulnerability

NVD description · AI analysis pending
7.8
group max
2%
  • microsoft 365 apps
  • microsoft office
  • microsoft office long term servicing channel
Full article343 words · extracted from infosecurity-magazine.com · click to collapse

System administrators have had a relatively quiet June Patch Tuesday after Microsoft revealed updates for just 51 vulnerabilities, only one of which was rated “critical.”

That bug (CVE-2024-30080) is a remote code execution (RCE) flaw in Microsoft Message Queuing (MSMQ) and has been assigned a CVSS score of 9.8, with exploitation rated as “more likely” by Microsoft.

“Microsoft has recommended disabling the service until a time at which you can install the update,” said Fortra associate director of security R&D, Tyler Reguly.

“A couple of quick Shodan searches reveal over a million hosts running with port 1801 open and over 3500 results for ‘msmq.’ Given this is a remote code execution, I would expect to see this vulnerability included in exploit frameworks in the near future.”

Read more on Patch Tuesday: Microsoft Fixes Three Zero-Days in May Patch Tuesday

The zero-day vulnerability, which was made public in February, is a protocol-level bug impacting DNSSEC validation.

“The vulnerability exists in DNSSEC validation that may allow an attacker to exploit standard DNSSEC protocols intended for DNS integrity by using excessive resources on a resolver, causing a denial of service for legitimate users,” explained Qualys technical content developer Diksha Ojha.

It has already been patched in various DNS implementations including BIND, PowerDNS and Unbound.

“The CVE-2023-50868 advisory published today does not provide further insight as to why this vulnerability wasn’t patched sooner,” said Rapid7 lead software engineer, Adam Barnett.

“It’s possible that Microsoft does not wish to be the only major server OS vendor without a patch.”

Barnett also pointed to two “RCE-via-malicious-file” vulnerabilities which are worthy of note.

CVE-2024-30101 is a vulnerability in Outlook. Although the Preview Pane is a vector, the user must subsequently perform unspecified specific actions to trigger the vulnerability and the attacker must win a race condition,” he explained.

“On the other hand, CVE-2024-30104 does not have the Preview Pane as a vector, but nevertheless ends up with a slightly higher CVSS base score of 7.8, since exploitation relies solely on the user opening a malicious file.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-patches-critica-zeroday/