ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster1

Microsoft Fixes Four Actively Exploited Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-38014
+1 in the same advisory: …38217
Local Privilege Escalation in Microsoft Windows Installer (Actively Exploited)

CVE-2024-38014 is an elevation-of-privilege flaw caused by improper privilege management (CWE-269) in the Microsoft Windows Installer component, rated 7.8 (high) with a local attack vector, low privileges required, and no user interaction. An attacker who already has limited access and can execute code on a targeted machine can trigger the vulnerable Installer behavior to gain elevated privileges, with high impact on the confidentiality, integrity, and availability of the host. The flaw affects the listed Windows 10, Windows 11, and Windows Server versions (CISA describes the affected product simply as 'Microsoft Windows', so other versions may also be impacted). It was fixed as part of Microsoft's September 2024 Patch Tuesday, which addressed 79 flaws including four actively exploited zero-days, and Microsoft's advisories plus CISA's KEV entry (added 2024-09-10) confirm it is being exploited in the wild; no public proof-of-concept is known and ransomware association is unknown. Its EPSS score of 6.3% (93rd percentile) is unusually high for a local privilege escalation, so Windows fleets should treat this as a priority patch.

Do: Apply Microsoft's September 2024 security updates (or any later cumulative update) for the affected Windows 10, Windows 11, and Windows Server versions, prioritizing servers and multi-user systems where untrusted local code runs; because this flaw is KEV-listed and actively exploited, remediation should follow CISA's vendor-instruction requirement. Given September 2024 reporting that a servicing defect left some Windows PCs unpatched despite appearing updated, verify via Windows Update history or your patch-management tooling that the cumulative update actually installed. No workaround is specified in the available data, so patching is the primary mitigation.

7.8
group max
6% KEV
  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 21H2, 22H2, 23H2, 24H2
  • Microsoft Windows Server 2008, 2012, 2016
mass≈1 billion+ Windows devices (Windows Installer is a core component of every affected Windows install)
CVE-2024-38226
Actively Exploited Security Feature Bypass in Microsoft Publisher

CVE-2024-38226 is a security feature bypass (protection mechanism failure, CWE-693) in Microsoft Publisher, rated 7.3 High with a local attack vector, low privileges required, and user interaction required. An attacker triggers it by convincing a user to open a maliciously crafted Publisher file, which defeats Publisher's built-in protection mechanism, allowing the attacker's content to bypass the expected security checks, with high impact rated for confidentiality, integrity, and availability. Users of Publisher as shipped in Microsoft Office 2019 and Microsoft Office Long Term Servicing Channel (LTSC) are affected. The flaw was patched in Microsoft's September 2024 Patch Tuesday, counted among the four actively exploited Microsoft zero-days that month, and CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-10, confirming exploitation in the wild; ransomware use is listed as unknown.

Do: Apply the September 2024 Microsoft security updates for Office 2019/LTSC (Publisher) across all endpoints, prioritizing systems with Publisher installed, per the vendor's instructions or the CISA KEV required action. Until patched, warn users to exercise caution with .pub files from untrusted sources, since exploitation requires opening a crafted file. Confirm no Publisher clients remain on outdated builds after deployment.

7.33% KEV
  • Microsoft Publisher (shipped with Microsoft Office 2019)
  • Microsoft Publisher (shipped with Microsoft Office Long Term Servicing Channel, LTSC)
massmillions of users (Publisher is bundled with enterprise perpetual-license Office 2019/LTSC suites; no precise public install counts for these channels)
CVE-2024-43491
Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, ve

Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these previously mitigated vulnerabilities on Windows 10, version 1507 (Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB) systems that have installed the Windows security update released on March 12, 2024—KB5035858 (OS Build 10240.20526) or other updates released until August 2024. All later versions of Windows 10 are not impacted by this vulnerability. This servicing stack vulnerability is addressed by installing the September 2024 Servicing stack update (SSU KB5043936) AND the September 2024 Windows security update (KB5043083), in that order. Note: Windows 10, version 1507 reached the end of support (EOS) on May 9, 2017 for devices running the Pro, Home, Enterprise, Education, and Enterprise IoT editions. Only Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB editions are still under support.

NVD description · AI analysis pending
9.812%
  • microsoft windows 10 1507
Full article384 words · extracted from infosecurity-magazine.com · click to collapse

Microsoft heaped more work onto sysadmins this week after fixing four zero-day vulnerabilities being actively exploited in the wild.

First on the list is CVE-2024-43491 – a CVSS 9.8 remote code execution (RCE) bug in Microsoft Windows Update which requires no privileges or user interaction, and of low attack complexity.

“This vulnerability emerged due to a rollback of fixes for certain previously mitigated vulnerabilities following the installation of security updates from March to August 2024,” explained Action1 president, Mike Walters. “This rollback inadvertently occurred due to a code defect in the servicing stack triggered by build version numbers.”

Next is CVE-2024-38014, an “important”-rated elevation of privilege (EoP) vulnerability that stems from improper privilege management in Windows Installer.

Given the importance of Windows Installer, this could impact thousands of enterprises and millions of devices, said Walters.

“Successful exploitation grants system privileges, allowing full control over the host system, including system modifications, arbitrary software installations and potentially disabling security measures,” he added.

“When combined with other attack vectors, this EoP vulnerability can enable sophisticated and damaging intrusion campaigns, allowing attackers to potentially navigate through defenses and achieve administrative control.”

Read more on Microsoft zero-days: Microsoft Fixes Four Zero-Days in July Patch Tuesday

Third on the zero-day list is CVE-2024-38217, the only one this month to have been publicly disclosed. Although disclosed last month, this Windows Mark of the Web (MoTW) security feature bypass vulnerability may have been exploited since 2018.

Saeed Abbasi, manager of vulnerability research at Qualys Threat Research Unit, explained that similar MoTW bypasses have been linked to ransomware attacks in the past.

“This vulnerability allows an attacker to manipulate the security warnings that typically inform users about the risks of opening files from unknown or untrusted sources,” he added.

“Given the exploit’s public disclosure and confirmed exploitation, it is a prime vector for cybercriminals to infiltrate corporate networks. Enterprises must prioritize patch management and educate users on the risks of downloading files from untrusted sources to mitigate the exploitation of such vulnerabilities.”

The final zero-day addressed in this month’s Patch Tuesday is CVE-2024-38226 – a Microsoft Publisher security feature bypass bug, which allows threat actors to circumvent security protections against embedded macros in downloaded documents.

Unusually, Microsoft didn’t explain how the flaw is being exploited in the wild.

Image credit: bluestork / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-fixes-four-actively/