ZeroHour
Security Affairspublished ()ingested @securityaffairs

Microsoft Patch Tuesday for July 2024 fixed 2 actively exploited zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-35264
.NET and Visual Studio Remote Code Execution Vulnerability

.NET and Visual Studio Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.13%
  • microsoft .net
  • microsoft visual studio 2022
CVE-2024-37985
Windows Kernel Information Disclosure Vulnerability

Windows Kernel Information Disclosure Vulnerability

NVD description · AI analysis pending
5.6<1%
  • microsoft windows 11 22h2
  • microsoft windows 11 23h2
CVE-2024-38112
+1 in the same advisory: …38080
Windows MSHTML Platform Spoofing Vulnerability Exploited in the Wild (CVE-2024-38112)

CVE-2024-38112 is a spoofing flaw (CWE-451) in the Microsoft Windows MSHTML platform, the Windows component used to render web content, including by applications that embed the legacy Internet Explorer engine. It is triggered when a user interacts with attacker-controlled content rendered through MSHTML: the attack requires no privileges, travels over the network, and needs user interaction (UI:R per its CVSS vector), letting an attacker misrepresent critical UI information to the victim. Despite being classified as spoofing, the CVSS impact scores are high across confidentiality, integrity, and availability, and the CVSS base score is 7.5 (High). Any system running the affected Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), or Windows Server (2008, 2012, 2016, 2019) releases is affected. Exploitation is confirmed in the wild: Microsoft patched it as an actively exploited zero-day in July 2024, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-09, and reporting indicates it had been exploited for over a year before the fix.

Do: Apply Microsoft's July 2024 security updates (Patch Tuesday) across all affected Windows 10, Windows 11, and Windows Server versions, prioritizing internet-facing and user workstations given confirmed in-the-wild exploitation and the 84.2% EPSS score. Until patched, remind users to avoid interacting with untrusted web or document content, since exploitation requires user interaction. Track the fix against CISA's KEV catalog deadlines and verify patch status on all endpoints.

7.5
group max
84% KEV
  • Microsoft Windows 10 1507
  • Microsoft Windows 10 1607
  • Microsoft Windows 10 1809
  • +9 more
masshundreds of millions of Windows devices (essentially all desktops and servers on the listed Windows 10/11 and Windows Server releases)
Full article287 words · extracted from securityaffairs.com · click to collapse

Microsoft Patch Tuesday security updates for July 2024 addressed 139 flaws, including two actively exploited zero-days.

Microsoft Patch Tuesday security updates for July 2024 addressed 139 vulnerabilities in Windows and Windows Components; Office and Office Components; .NET and Visual Studio; Azure; Defender for IoT; SQL Server; Windows Hyper-V; Bitlocker and Secure(?) Boot; Remote Desktop; and Xbox (yes Xbox!). The updates also addressed additional three issues that reside in the third-party products.

Five vulnerabilities are rated Critical, 133 are rated Important, and three are rated Moderate in severity.

Two of these vulnerabilities are listed as publicly known, and two other bugs are actively exploited in attacks.

The two flaws actively exploited in the wild are:

CVE-2024-38080Windows Hyper-V Elevation of Privilege VulnerabilityImportant7.8NoYesEoP
CVE-2024-38112Windows MSHTML Platform Spoofing VulnerabilityImportant705NoYesSpoofing

CVE-2024-38080 (CVSS score of 7.8) – the flaw is an elevation of privilege vulnerability in Windows Hyper-V. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

CVE-2024-38112 (CVSS score of 7.5) – the flaw is a Windows MSHTML Platform Spoofing Vulnerability. Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment. An attacker can trigger the issue by sending the victim a malicious file that the victim would have to execute.

The two publicly known vulnerabilities are:

CVE-2024-37985 *Arm: CVE-2024-37985 Systematic Identification and Characterization of Proprietary PrefetchersImportant5.9YesNoInfo
CVE-2024-35264.NET and Visual Studio Remote Code Execution VulnerabilityImportant8.1YesNoRCE

The full list of vulnerabilities addressed by Microsoft are available here:

https://www.zerodayinitiative.com/blog/2024/7/9/the-july-2024-security-update-review

Pierluigi Paganini

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

(SecurityAffairs – hacking, Microsoft Patch Tuesday)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/165520/security/microsoft-patch-tuesday-for-july-2024.html