ZeroHour
The Recordpublished ()ingested

Hackers have sights set on four Microsoft vulnerabilities, CISA warns

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-38014
+1 in the same advisory: …38217
Local Privilege Escalation in Microsoft Windows Installer (Actively Exploited)

CVE-2024-38014 is an elevation-of-privilege flaw caused by improper privilege management (CWE-269) in the Microsoft Windows Installer component, rated 7.8 (high) with a local attack vector, low privileges required, and no user interaction. An attacker who already has limited access and can execute code on a targeted machine can trigger the vulnerable Installer behavior to gain elevated privileges, with high impact on the confidentiality, integrity, and availability of the host. The flaw affects the listed Windows 10, Windows 11, and Windows Server versions (CISA describes the affected product simply as 'Microsoft Windows', so other versions may also be impacted). It was fixed as part of Microsoft's September 2024 Patch Tuesday, which addressed 79 flaws including four actively exploited zero-days, and Microsoft's advisories plus CISA's KEV entry (added 2024-09-10) confirm it is being exploited in the wild; no public proof-of-concept is known and ransomware association is unknown. Its EPSS score of 6.3% (93rd percentile) is unusually high for a local privilege escalation, so Windows fleets should treat this as a priority patch.

Do: Apply Microsoft's September 2024 security updates (or any later cumulative update) for the affected Windows 10, Windows 11, and Windows Server versions, prioritizing servers and multi-user systems where untrusted local code runs; because this flaw is KEV-listed and actively exploited, remediation should follow CISA's vendor-instruction requirement. Given September 2024 reporting that a servicing defect left some Windows PCs unpatched despite appearing updated, verify via Windows Update history or your patch-management tooling that the cumulative update actually installed. No workaround is specified in the available data, so patching is the primary mitigation.

7.8
group max
6% KEV
  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 21H2, 22H2, 23H2, 24H2
  • Microsoft Windows Server 2008, 2012, 2016
mass≈1 billion+ Windows devices (Windows Installer is a core component of every affected Windows install)
CVE-2024-38226
Actively Exploited Security Feature Bypass in Microsoft Publisher

CVE-2024-38226 is a security feature bypass (protection mechanism failure, CWE-693) in Microsoft Publisher, rated 7.3 High with a local attack vector, low privileges required, and user interaction required. An attacker triggers it by convincing a user to open a maliciously crafted Publisher file, which defeats Publisher's built-in protection mechanism, allowing the attacker's content to bypass the expected security checks, with high impact rated for confidentiality, integrity, and availability. Users of Publisher as shipped in Microsoft Office 2019 and Microsoft Office Long Term Servicing Channel (LTSC) are affected. The flaw was patched in Microsoft's September 2024 Patch Tuesday, counted among the four actively exploited Microsoft zero-days that month, and CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-10, confirming exploitation in the wild; ransomware use is listed as unknown.

Do: Apply the September 2024 Microsoft security updates for Office 2019/LTSC (Publisher) across all endpoints, prioritizing systems with Publisher installed, per the vendor's instructions or the CISA KEV required action. Until patched, warn users to exercise caution with .pub files from untrusted sources, since exploitation requires opening a crafted file. Confirm no Publisher clients remain on outdated builds after deployment.

7.33% KEV
  • Microsoft Publisher (shipped with Microsoft Office 2019)
  • Microsoft Publisher (shipped with Microsoft Office Long Term Servicing Channel, LTSC)
massmillions of users (Publisher is bundled with enterprise perpetual-license Office 2019/LTSC suites; no precise public install counts for these channels)
CVE-2024-43491
Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, ve

Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these previously mitigated vulnerabilities on Windows 10, version 1507 (Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB) systems that have installed the Windows security update released on March 12, 2024—KB5035858 (OS Build 10240.20526) or other updates released until August 2024. All later versions of Windows 10 are not impacted by this vulnerability. This servicing stack vulnerability is addressed by installing the September 2024 Servicing stack update (SSU KB5043936) AND the September 2024 Windows security update (KB5043083), in that order. Note: Windows 10, version 1507 reached the end of support (EOS) on May 9, 2017 for devices running the Pro, Home, Enterprise, Education, and Enterprise IoT editions. Only Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB editions are still under support.

NVD description · AI analysis pending
9.812%
  • microsoft windows 10 1507
Full article691 words · extracted from therecord.media · click to collapse

Federal civilian agencies across the U.S. government have until the end of the month to fix four key issues in Microsoft products after they were made public on Tuesday. 

The Cybersecurity and Infrastructure Security Agency (CISA) said the four vulnerabilities affect widely used Microsoft tools and are already being exploited by hackers.

The four bugs — CVE-2024-38226, CVE-2024-43491, CVE-2024-38014 and CVE-2024-38217 — were part of the 79 vulnerabilities included in the monthly security release from Microsoft. 

Randy Watkins, CTO at cybersecurity firm Critical Start, warned that the vulnerabilities demand urgent attention, especially for organizations in industries like healthcare, finance and government. 

“Organizations must prioritize these updates,” he said. “With attackers constantly evolving their tactics, failure to patch could leave organizations exposed to not just data theft, but also significant operational downtime.”

‘Part of an attack chain’

The vulnerabilities affect key tools like Windows Update, Windows Publisher, Windows Installer and a tool that, ironically, warns users of potential security issues. 

Several experts said CVE-2024-43491 appeared to be the most concerning of the bunch because Microsoft gave it a severity score of 9.8 out of 10. 

But on a closer look, researchers explained that Microsoft's description of the issue showed it affected a very specific version of Windows 10 released in July 2015. All later versions of Windows 10 are not impacted by this vulnerability, according to Microsoft. 

Action1 founder Mike Walters said the vulnerability emerged due to a rollback of fixes for certain previously-mitigated bugs following the installation of security updates from March to August 2024. 

“All in all, while there are certainly more than a few organizations out there still running [the affected] Windows 10 1507, most admins can breathe a sigh of relief on this one, and then go back to worrying about everything else,” said Rapid7’s Adam Barnett.

Experts said CVE-2024-38226 — the vulnerability affecting Microsoft Publisher, a program for page layout and graphic design — would likely be used as part of a chain of attacks because it allows hackers to bypass security features. 

An attacker would likely exploit the bug by sending Microsoft Publisher phishing documents. 

CVE-2024-38014 — affecting Windows Installer — would also likely be used as part of a larger attack chain because it allows someone with low privileges in a system to escalate their access. Walters said it would allow an attacker to gain “full control over the host system, including system modifications, arbitrary software installations, and potentially disabling security measures.”

“When combined with other attack vectors, this… vulnerability can enable sophisticated and damaging intrusion campaigns, allowing attackers to potentially navigate through defenses and achieve administrative control,” Walters said. 

“It can act as a secondary stage in multi-vector attacks, where an initial breach through another vulnerability is escalated using CVE-2024-38014. Given the Windows Installer’s critical role across various Windows versions, both enterprise environments and individual user devices are at risk, accounting for potentially thousands of vulnerable organizations and millions of devices.”

The last of the four — CVE-2024-38217 — is another vulnerability affecting Windows Mark of the Web, a security tool designed to flag files that have been downloaded from the internet.

Hackers have targeted the feature for months, and Qualys Threat Research Unit manager Saeed Abbasi explained that the vulnerability allows attackers to manipulate security warnings that typically inform users about the risks of opening files from unknown or untrusted sources. 

“Similar [Mark of the Web] bypasses have historically been linked to ransomware attacks, where the stakes are high,” he said. “Given the exploit's public disclosure and confirmed exploitation, it is a prime vector for cybercriminals to infiltrate corporate networks.”

Rapid7’s Barnett noted that exploit code for the vulnerability is also available on GitHub.

Several other companies released Patch Tuesday security updates, highlighting severe bugs in products from Ivanti, Cisco, Adobe, Fortinet and more.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/hackers-four-microsoft-vulnerabilities-cisa