ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Microsoft fixes RCE vulnerabilities in MSMQ, Outlook (CVE-2024-30080, CVE-2024-30103)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-36802
Use-After-Free Privilege Escalation in Microsoft Streaming Service Proxy

CVE-2023-36802 is a use-after-free vulnerability (CWE-416) in the Microsoft Streaming Service Proxy, a component that ships with Windows, that allows an attacker to escalate privileges. It is triggered by a local attacker who can already execute code on a target machine and interacts with the streaming service proxy component in a way that mishandles freed memory. Successful exploitation typically yields elevated (SYSTEM/kernel-level) privileges, giving an attacker full control of the host and making it a common link in chained attack sequences alongside other exploits. Any Windows system carrying the affected component is potentially affected, which in practice means a very broad installed base of Windows client and server machines. The flaw is being actively exploited — CISA added it to the Known Exploited Vulnerabilities catalog on 2023-09-12 — though no public proof-of-concept is known and Microsoft's severity scoring was not yet available in the source data; EPSS estimates a high 27.5% chance of exploitation within 30 days (98th percentile).

Do: Apply Microsoft's security updates for this vulnerability via the vendor's mitigation instructions (Windows Update/patch channel), as required by the CISA KEV listing, prioritizing internet-reachable and multi-user Windows hosts. Since exploitation requires local access, limit who can run code on Windows systems and review endpoints for signs of local privilege escalation activity; confirm the patch landed by checking installed updates against Microsoft's advisory.

7.828% KEV
  • Microsoft Streaming Service Proxy
mass≈hundreds of millions of Windows devices (the Streaming Service Proxy component ships with Windows, so exposure broadly mirrors the Windows install base)
CVE-2024-2137
The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple pricing widgets (e.g.

The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple pricing widgets (e.g. Pricing Single, Pricing Icon, Pricing Tab) in all versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

NVD description · AI analysis pending
5.4<1%
  • themesgrove all-in-one addons for elementor
CVE-2024-30072
Microsoft Event Trace Log File Parsing Remote Code Execution Vulnerability

Microsoft Event Trace Log File Parsing Remote Code Execution Vulnerability

NVD description · AI analysis pending
7.8<1%
  • microsoft windows 11 22h2
  • microsoft windows 11 23h2
  • microsoft windows server 2022 23h2
CVE-2024-30080
+1 in the same advisory: …30078
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.8
group max
43%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2024-30089
Microsoft Streaming Service Elevation of Privilege Vulnerability

Microsoft Streaming Service Elevation of Privilege Vulnerability

NVD description · AI analysis pending
7.88%
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • microsoft windows 10 22h2
  • +1 more
CVE-2024-30103
Microsoft Outlook Remote Code Execution Vulnerability

Microsoft Outlook Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.83%
  • microsoft 365 apps
  • microsoft office
  • microsoft office long term servicing channel
  • +1 more
Full article637 words · extracted from helpnetsecurity.com · click to collapse

June 2024 Patch Tuesday is here and Microsoft has delivered fixes for a critical MSMQ flaw (CVE-2024-30080) and a RCE vulnerability in Microsoft Outlook (CVE-2024-30103).

CVE-2024-30080 CVE-2024-30103

49 CVE-numbered vulnerabilities have been fixed in total, none of which have been exploited in the wild as zero-days.

About CVE-2024-30080 and CVE-2024-30103

CVE-2024-30080 is a use after free flaw affecting Microsoft Message Queuing (MSMQ) and can be exploited by unauthenticated attackers by sending a specially crafted malicious MSMQ packet to a MSMQ server. Successful exploitation will allow remote code execution (RCE).

While the vulnerability can be exploited only on Windows and Windows Server installations with the Windows message queuing service enabled, the lack of other exploitation requirements (e.g., previous authentication, user interaction) is partly what makes Microsoft say that exploitation of this flaw by attackers is “more likely”. So patch this one quickly, or disable the vulnerable service (if not needed).

CVE-2024-30103, a Microsoft Outlook vulnerability that can also lead to RCE, should also be fixed sooner rather than later.

“An attacker who successfully exploited this vulnerability could bypass Outlook registry block lists and enable the creation of malicious DLL files,” Microsoft says.

“While not explicitly stated, attackers would likely then use the malicious DLL files to perform some form of DLL hijacking for further compromise,” Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, noted.

“The good news here is that the attacker would need valid Exchange credentials to perform this attack. The bad news is that the exploit can occur in the Preview Pane. Considering how often credentials end up being sold in underground forums, I would not ignore this fix.”

The vulnerability was discovered by Morphisec researchers Michael Gorelik and Shmuel Uzan, who pointed out that the vulnerability is particularly dangerous for accounts using Microsoft Outlook’s auto-open email feature, as execution initiates when an affected email is opened.

They plan to release the technical details and a PoC exploit in early August, at the DEFCON 32 conference.

Other vulnerabilities of note

CVE-2024-30078 is a RCE bug affecting the Windows Wi-Fi driver.

“This vulnerability allows an unauthenticated attacker to execute code on an affected system by sending the target a specially crafted network packet. Obviously, the target would need to be in Wi-Fi range of the attacker and using a Wi-Fi adapter, but that’s the only restriction,” Childs explained, and said that the bug “will likely draw a lot of attention from attackers and red teams alike.”

Jason Kikta, CISO and SVP of Product at Automox, told Help Net Security that this vulnerability is particularly concerning because it enables attackers to gain control over targets’ system without physical access.

“Given its nature, this vulnerability poses a significant risk in endpoint-dense environments including hotels, trade shows, or anywhere else numerous devices connect to WiFi networks,” he opined.

CVE-2024-30072 is another interesting RCE vulnerability that can be triggered by opening a malicious Microsoft Event Trace Log file.

“With the commonality of IT teams using Event Trace Log files to debug user systems and given the high privileges often associated with IT support roles, exploiting this vulnerability could provide attackers with substantial access to sensitive systems,” noted Henry Smith, senior AppSec engineer at Automox.

Satnam Narang, senior staff research engineer at Tenable, singled out CVE-2024-30089, an elevation of privilege flaw in the Microsoft Streaming Service, as worthy of a quick fix.

Microsoft labeled this vulnerability as ‘Exploitation More Likely’, he pointed out, and it was disclosed to Microsoft by the same security researcher that disclosed CVE-2023-36802, another Microsoft Streaming Service elevation of privilege flaw that was patched in the September 2023 Patch Tuesday (and had been exploited by attackers in the wild).

UPDATE (August 13, 2024, 06:20 a.m. ET):

Morphisec has released more details about CVE-2024-30103, which is a bypass for the previously patched CVE-2024-2137.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/06/11/cve-2024-30080-cve-2024-30103/