ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Microsoft Fixes Three Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-30040
Actively Exploited Security Feature Bypass in Microsoft Windows MSHTML Platform

CVE-2024-30040 is a high-severity (CVSS 8.8) security feature bypass in the Windows MSHTML platform, the HTML-rendering engine component embedded in Internet Explorer and many Windows applications. A remote attacker can trigger it by persuading a user to open or render specially crafted content, since the attack requires user interaction but no privileges or special conditions (AV:N/AC:L/PR:N/UI:R). Successful exploitation defeats an intended Windows security feature, and the high confidentiality, integrity, and availability impact ratings indicate it can enable significant compromise when chained with other techniques. All supported Windows 10 and Windows 11 client releases (1507 through 22H2, and 21H2 through 23H2, respectively) plus Windows Server 2016, 2019, 2022, and 2022 23H2 are affected. The flaw is being actively exploited in the wild — it was added to CISA's KEV catalog on 2024-05-14 and was one of two zero-days fixed in Microsoft's May 2024 Patch Tuesday — though no public proof-of-concept is known and EPSS estimates a 3.9% chance of exploitation in the next 30 days (90th percentile).

Do: Apply the May 2024 Patch Tuesday cumulative updates (released 2024-05-14) for Windows 10, Windows 11, and Windows Server as soon as possible; the flaw is under active exploitation and listed in CISA KEV, so prioritize endpoints and servers that render untrusted documents or HTML content. Confirm via patch reporting that the May 2024 cumulative update is installed on all assets, and in the interim caution users against opening unsolicited files and links, since exploitation requires user interaction.

8.84% KEV
  • microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • microsoft Windows 11 21H2, 22H2, 23H2
  • microsoft Windows Server 2016, 2019, 2022, 2022 23H2
mass≈1 billion+ Windows installations (MSHTML is a core component of every supported Windows 10/11 and Windows Server release)
CVE-2024-30044
Microsoft SharePoint Server Remote Code Execution Vulnerability

Microsoft SharePoint Server Remote Code Execution Vulnerability

NVD description · AI analysis pending
7.284%
  • microsoft sharepoint server
CVE-2024-30046
Visual Studio Denial of Service Vulnerability

Visual Studio Denial of Service Vulnerability

NVD description · AI analysis pending
5.92%
  • microsoft .net
  • microsoft visual studio 2022
CVE-2024-30051
Elevation of Privilege in Microsoft Windows DWM Core Library (Actively Exploited)

CVE-2024-30051 is a heap-based buffer overflow / out-of-bounds write (CWE-122, CWE-787) in the Windows Desktop Window Manager (DWM) Core Library that allows a local attacker to escalate privileges. It is triggered by locally executing crafted code that corrupts memory in the DWM component, requiring only low privileges and no user interaction (AV:L/AC:L/PR:L/UI:N). A successful exploit yields high-impact gains on the local system — typically elevation to elevated/SYSTEM rights, giving the attacker full control of confidentiality, integrity and availability on that host. Any organization running the affected Windows 10/11 client releases or Windows Server 2016/2019/2022 with the DWM component is exposed, which in practice means nearly every modern Windows endpoint. The flaw was a zero-day exploited in the wild before remediation: it was added to CISA KEV on 2024-05-14 with known ransomware use, and public reporting ties it to QakBot attack chains and Microsoft's May 2024 Patch Tuesday (which also fixed it alongside other exploited zero-days).

Do: Apply Microsoft's May 2024 Patch Tuesday cumulative updates for every affected Windows 10/11 and Windows Server 2016/2019/2022 release immediately; per CISA KEV, apply vendor mitigations or discontinue use of affected systems if updates are unavailable. Prioritize endpoints and servers exposed to user-driven malware (email, web browsing) since the flaw is chained after initial access in QakBot and ransomware operations, and verify patched DWM/dwmcore binaries via the updated OS build. Monitor for local privilege-escalation activity and treat this as a high-priority patch alongside the other May 2024 exploited zero-days.

7.86% KEV ransomware
  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 21H2, 22H2, 23H2
  • Microsoft Windows Server 2016 all supported releases (as listed by CISA)
  • +2 more
mass≈1 billion+ Windows 10/11 endpoints plus large Windows Server 2016/2019/2022 fleets (DWM is a core component present on effectively every affected Windows…

Indicators of compromiseAll →

TypeIndicatorContext
domainshutterstock.comn Microsoft SharePoint Server. Image credit: Framalicious / Shutterstock.com
Full article384 words · extracted from infosecurity-magazine.com · click to collapse

System administrators have over 60 CVEs to address in the latest Microsoft Patch Tuesday, including three zero-day vulnerabilities.

Of these three zero-day bugs, two have been actively exploited in the wild, the most prominent of which (CVE-2024-30051) has been used to deliver QuakBot and other malware.

It is an elevation of privilege vulnerability which stems from a heap-based buffer overflow in the Windows Desktop Window Manager (DWM) Core Library.

Action1 president, Mike Walters, warned that it could pose a significant risk to environments with “numerous and diverse local users,” like corporate networks and academic institutions.

“This vulnerability can be exploited by a low-privileged local user on a shared system to gain system-level access, which could allow them to install software, alter or delete data, and modify system settings destructively. Alternatively, malware utilizing a multi-stage payload might leverage this exploit to increase its privileges and further compromise the system,” he explained.

“Furthermore, an attacker might use a less severe vulnerability as an entry point to gain initial low-level access to a machine and then exploit CVE-2024-30051 to escalate their privileges from a low-privileged account to system, thereby gaining extensive control over the machine.”

These privileges could be used to disable security features, steal sensitive data or conduct lateral movement across a victim network, Walters added.

Read more on Patch Tuesday: Microsoft Fixes Two Zero-Days in February Patch Tuesday

The second actively exploited zero-day is CVE-2024-30040, a Windows MSHTML platform security feature bypass flaw.

“Windows MSHTML is a browser engine that renders web pages frequently connected to Internet Explorer. Even though the Internet Explorer 11 desktop application has reached the end of support, MSHTML vulnerabilities are still relevant today and are being patched by Microsoft,” explained Qualys technical content developer Diksha Ojha.

“The vulnerability can bypass OLE mitigations in Microsoft 365 and Microsoft Office, which protect users from vulnerable COM/OLE controls. An unauthenticated attacker may exploit this vulnerability to execute code by convincing a user to open a malicious document.”

Finally, Microsoft also patched a denial-of-service flaw in Microsoft Visual Studio (CVE-2024-30046) which it claimed was publicly disclosed but not currently exploited.

The only critical CVE of the 61 fixed this month was CVE-2024-30044, a remote code execution (RCE) bug in Microsoft SharePoint Server.

Image credit: Framalicious / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-three-zerodays-may24/