ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity1

July 2024 Patch Tuesday forecast: The end of an AV giant in the US

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-30080
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.843%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2024-38112
+1 in the same advisory: …38080
Windows MSHTML Platform Spoofing Vulnerability Exploited in the Wild (CVE-2024-38112)

CVE-2024-38112 is a spoofing flaw (CWE-451) in the Microsoft Windows MSHTML platform, the Windows component used to render web content, including by applications that embed the legacy Internet Explorer engine. It is triggered when a user interacts with attacker-controlled content rendered through MSHTML: the attack requires no privileges, travels over the network, and needs user interaction (UI:R per its CVSS vector), letting an attacker misrepresent critical UI information to the victim. Despite being classified as spoofing, the CVSS impact scores are high across confidentiality, integrity, and availability, and the CVSS base score is 7.5 (High). Any system running the affected Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), or Windows Server (2008, 2012, 2016, 2019) releases is affected. Exploitation is confirmed in the wild: Microsoft patched it as an actively exploited zero-day in July 2024, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-09, and reporting indicates it had been exploited for over a year before the fix.

Do: Apply Microsoft's July 2024 security updates (Patch Tuesday) across all affected Windows 10, Windows 11, and Windows Server versions, prioritizing internet-facing and user workstations given confirmed in-the-wild exploitation and the 84.2% EPSS score. Until patched, remind users to avoid interacting with untrusted web or document content, since exploitation requires user interaction. Track the fix against CISA's KEV catalog deadlines and verify patch status on all endpoints.

7.5
group max
84% KEV
  • Microsoft Windows 10 1507
  • Microsoft Windows 10 1607
  • Microsoft Windows 10 1809
  • +9 more
masshundreds of millions of Windows devices (essentially all desktops and servers on the listed Windows 10/11 and Windows Server releases)
Full article579 words · extracted from helpnetsecurity.com · click to collapse

July 2024 Patch Tuesday is now live:
Microsoft fixes two zero-days exploited by attackers (CVE-2024-38080, CVE-2024-38112)

The US celebrated Independence Day last week, providing many with a long weekend leading into patch week. With summer vacations underway, many developers must be out of the office because June was fairly quiet regarding software updates. This included June 2024 Patch Tuesday, which saw Windows 10 and associated servers with 33 vulnerabilities addressed, while Windows 11 had 28 fixed.

The operating system updates were rated Critical due to CVE-2024-30080 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability. There were also important updates for Microsoft Sharepoint Server and the usual Office and Office 365 product suites. But the main news around Microsoft in June was focused on previews.

July 2024 Patch Tuesday forecast

Microsoft Recall

I mentioned last month the preview for Windows 11 24H2 hit the Release Preview Channel in late May. It was subsequently pulled on June 7 and then re-released on June 15.

The hot topic of discussion is the AI-powered Recall feature, which was introduced with it and Copilot+. Due to security and privacy concerns, this has been delayed and moved to the Windows Insider Program for further review and comment.

Microsoft temporarily pulled and then re-released the Windows 11 preview update KB5039302, originally released on June 25th. The original preview was causing reboots on systems using virtualization, such as Azure Virtual Desktop and VMware. The latest update will be blocked from being installed on those devices until Microsoft can resolve the issue. This is a prime example showing the value of the preview program in action.

Kaspersky ban

This month’s article title refers to the big news from June 20th when the US Department of Commerce officially banned the sale of all Kaspersky Lab products in the US. This is the first time the Trump Administration 2019 Executive Order on Securing the Information and Communications Technology and Services Supply Chain was used. This action is the culmination of activity that started back in 2017 when the Department of Homeland Security placed the first ban on the use of Kaspersky software by the federal government.

This latest ban prohibits the sale of products to private companies and individuals in the US. The justification under the executive order is that as a Russian company, Kaspersky may be obligated to turn customer information over to their government which could put US security at risk. Per the announcement, all Kaspersky products must be removed by September 29th.

Just as a reminder, last month Microsoft released the final updates for Windows 10 21H2 Education and Enterprise editions. With no additional security updates, all users are encouraged to update to the latest version of Windows 10 (or Windows 11 if your system requirements support it).

July 2024 Patch Tuesday forecast

  • Anticipate a large set of updates this week. Even though it has been a slow month, we’re due for some .NET framework updates, and maybe a SQL Server update too.
  • Adobe released security updates for most of their major products last Patch Tuesday, but we didn’t see one for Acrobat and Reader. There’s a slight chance for one this week.
  • Be on the lookout for an Apple OS update soon. The last major release was May 13th.
  • Google Chrome is now a Patch Tuesday staple. Expect the latest version on Tuesday afternoon.
  • Mozilla has also been gravitating towards a regular monthly release around Patch Tuesday. Let’s plan for Firefox and Thunderbird security updates this week.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/07/08/july-2024-patch-tuesday-forecast/