Microsoft's March Updates Fix 61 Vulnerabilities, Including Critical Hyper
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-0846 | Unauthenticated, stored cross-site scripting in the display of alarm reduction keys in multiple versions of OpenNMS Horizon and Meridian could allow an attacker Unauthenticated, stored cross-site scripting in the display of alarm reduction keys in multiple versions of OpenNMS Horizon and Meridian could allow an attacker access to confidential session information. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2024-0799 | An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.se An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin. NVD description · AI analysis pending | 9.8 group max | 4% | PoC |
| — | |
| CVE-2024-21334 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability Open Management Infrastructure (OMI) Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.8 | 20% |
| — | ||
| CVE-2024-21390 | Microsoft Authenticator Elevation of Privilege Vulnerability Microsoft Authenticator Elevation of Privilege Vulnerability NVD description · AI analysis pending | 7.1 | 1% |
| — | ||
| CVE-2024-21400 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability NVD description · AI analysis pending | 9.0 | 2% |
| — | ||
| CVE-2024-21407 | Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.1 group max | 16% |
| — | ||
| CVE-2024-26170 | Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability NVD description · AI analysis pending | 7.8 | 7% |
| — | ||
| CVE-2024-26198 | Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.8 | 7% |
| — |
Full article726 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananMar 13, 2024Patch Tuesday / Software Update
Microsoft on Tuesday released its monthly security update, addressing 61 different security flaws spanning its software, including two critical issues impacting Windows Hyper-V that could lead to denial-of-service (DoS) and remote code execution.
Of the 61 vulnerabilities, two are rated Critical, 58 are rated Important, and one is rated Low in severity. None of the flaws are listed as publicly known or under active attack at the time of the release, but six of them have been tagged with an "Exploitation More Likely" assessment.
The fixes are in addition to 17 security flaws that have been patched in the company's Chromium-based Edge browser since the release of the February 2024 Patch Tuesday updates.
Topping the list of critical shortcomings are CVE-2024-21407 and CVE-2024-21408, which affect Hyper-V and could result in remote code execution and a DoS condition, respectively.
Microsoft's update also addresses privilege escalation flaws in the Azure Kubernetes Service Confidential Container (CVE-2024-21400, CVSS score: 9.0), Windows Composite Image File System (CVE-2024-26170, CVSS score: 7.8), and Authenticator (CVE-2024-21390, CVSS score: 7.1).
Successful exploitation of CVE-2024-21390 requires the attacker to have a local presence on the device either via malware or a malicious application already installed via some other means. It also necessitates that the victim closes and re-opens the Authenticator app.
"Exploitation of this vulnerability could allow an attacker to gain access to multi-factor authentication codes for the victim's accounts, as well as modify or delete accounts in the authenticator app but not prevent the app from launching or running," Microsoft said in an advisory.
"While exploitation of this flaw is considered less likely, we know that attackers are keen to find ways to bypass multi-factor authentication," Satnam Narang, senior staff research engineer at Tenable, said in a statement shared with The Hacker News.
"Having access to a target device is bad enough as they can monitor keystrokes, steal data and redirect users to phishing websites, but if the goal is to remain stealth, they could maintain this access and steal multi-factor authentication codes in order to login to sensitive accounts, steal data or hijack the accounts altogether by changing passwords and replacing the multi-factor authentication device, effectively locking the user out of their accounts."
Another vulnerability of note is a privilege escalation bug in the Print Spooler component (CVE-2024-21433, CVSS score: 7.0) that could permit an attacker to obtain SYSTEM privileges but only upon winning a race condition.
The update also plugs a remote code execution flaw in Exchange Server (CVE-2024-26198, CVSS score: 8.8) that an unauthenticated threat actor could abuse by placing a specially crafted file onto an online directory and tricking a victim into opening it, resulting in the execution of malicious DLL files.
The vulnerability with the highest CVSS rating is CVE-2024-21334 (CVSS score: 9.8), which concerns a case of remote code execution affecting the Open Management Infrastructure (OMI).
"A remote unauthenticated attacker could access the OMI instance from the Internet and send specially crafted requests to trigger a use-after-free vulnerability," Redmond said.
"The first quarter of Patch Tuesday in 2024 has been quieter compared to the last four years," Narang said. "On average, there were 237 CVEs patched in the first quarter from 2020 through 2023. In the first quarter of 2024, Microsoft only patched 181 CVEs. The average number of CVEs patched in March over the last four years was 86."
Software Patches from Other Vendors
In addition to Microsoft, security updates have also been released by other vendors over the past few weeks to rectify several vulnerabilities, including —
- Adobe
- AMD
- Android
- Apple
- Arcserve Unified Data Protection (CVE-2024-0799, CVE-2024-0800, and CVE-2024-0801)
- Aruba Networks
- Arm
- Bosch
- Canon
- Cisco
- Citrix
- CODESYS
- Dell
- Drupal
- F5
- Fortinet
- GitLab
- Google Chrome
- Google Cloud
- Google Wear OS
- Hikvision
- Hitachi Energy
- HP
- IBM
- Intel
- Jenkins
- JetBrains TeamCity
- Lenovo
- Linux distributions Debian, Oracle Linux, Red Hat, SUSE, and Ubuntu
- MediaTek
- Mitel
- Mitsubishi Electric
- MongoDB
- Mozilla Firefox, Firefox ESR, and Thunderbird
- NETGEAR
- NVIDIA
- OpenNMS (CVE-2023-0846)
- Palo Alto Networks
- Progress Software OpenEdge
- QNAP
- Qualcomm
- Samsung
- SAP
- Schneider Electric
- Siemens
- SolarWinds
- SonicWall
- Spring Framework
- Synology
- VMware
- Zoom, and
- Zyxel
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/03/microsofts-march-updates-fix-61.html