ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Microsoft patches two zero-days exploited in the wild (CVE-2024-43573, CVE-2024-43572)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-38112
Windows MSHTML Platform Spoofing Vulnerability Exploited in the Wild (CVE-2024-38112)

CVE-2024-38112 is a spoofing flaw (CWE-451) in the Microsoft Windows MSHTML platform, the Windows component used to render web content, including by applications that embed the legacy Internet Explorer engine. It is triggered when a user interacts with attacker-controlled content rendered through MSHTML: the attack requires no privileges, travels over the network, and needs user interaction (UI:R per its CVSS vector), letting an attacker misrepresent critical UI information to the victim. Despite being classified as spoofing, the CVSS impact scores are high across confidentiality, integrity, and availability, and the CVSS base score is 7.5 (High). Any system running the affected Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), or Windows Server (2008, 2012, 2016, 2019) releases is affected. Exploitation is confirmed in the wild: Microsoft patched it as an actively exploited zero-day in July 2024, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-09, and reporting indicates it had been exploited for over a year before the fix.

Do: Apply Microsoft's July 2024 security updates (Patch Tuesday) across all affected Windows 10, Windows 11, and Windows Server versions, prioritizing internet-facing and user workstations given confirmed in-the-wild exploitation and the 84.2% EPSS score. Until patched, remind users to avoid interacting with untrusted web or document content, since exploitation requires user interaction. Track the fix against CISA's KEV catalog deadlines and verify patch status on all endpoints.

7.584% KEV
  • Microsoft Windows 10 1507
  • Microsoft Windows 10 1607
  • Microsoft Windows 10 1809
  • +9 more
masshundreds of millions of Windows devices (essentially all desktops and servers on the listed Windows 10/11 and Windows Server releases)
CVE-2024-43468
Unauthenticated SQL Injection to RCE in Microsoft Configuration Manager

CVE-2024-43468 is a SQL injection flaw (CWE-89) in Microsoft Configuration Manager that Microsoft rates critical (CVSS 3.1: 9.8), with a network attack vector requiring no privileges or user interaction, and it can escalate to remote code execution on affected site infrastructure. An attacker able to reach a vulnerable Configuration Manager component can submit crafted input that injects SQL commands against the underlying database, manipulate it, and gain code execution in the Configuration Manager environment. Affected deployments are the Configuration Manager current branch versions 2403, 2409, and 2503. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog as of 2026-02-12, confirming in-the-wild exploitation; EPSS is very high (82%), and ransomware use is not yet confirmed.

Do: Install the updated Configuration Manager builds for branches 2403, 2409, and 2503 from Microsoft's monthly security update, per the vendor instructions required by the CISA KEV entry; no public PoC or workaround is documented. Prioritize site systems reachable from untrusted networks, since the CVSS vector is network-exploitable without authentication, and federal agencies must apply mitigations under BOD 22-01 within three weeks of the 2026-02-12 KEV addition or discontinue use. While patching, review logs for unexpected SQL activity against Configuration Manager databases to check for signs of exploitation.

9.882% KEV
  • Microsoft Configuration Manager Configuration Manager current branch 2403, 2409, and 2503 (CISA lists Microsoft Configuration Manager broadly)
mass≈100,000+ deployments worldwide (order-of-magnitude estimate)
CVE-2024-43488
Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution thr

Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector.

NVD description · AI analysis pending
9.81%
  • microsoft visual studio code
CVE-2024-43573
+1 in the same advisory: …43572
Spoofing Vulnerability in Microsoft Windows MSHTML Platform Exploited in the Wild

CVE-2024-43573 is a spoofing vulnerability in the Microsoft Windows MSHTML platform, classified as an input-neutralization flaw (CWE-79), that can lead to a loss of confidentiality. It is triggered when a user renders attacker-crafted content through the MSHTML engine, the browser-rendering component embedded in Windows that many system surfaces and applications use to display web-like content, causing content or interface elements to appear to come from a trusted source when they are attacker-controlled. An attacker who successfully exploits it can present spoofed content or prompts that deceive users, potentially leading them to reveal sensitive information such as credentials. All Microsoft Windows systems are affected according to CISA's listing, though no specific version breakdown is provided in the source data. The flaw is confirmed to be exploited in the wild (CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-08), EPSS assigns a 44.1% probability of exploitation in the next 30 days (99th percentile), no public PoC is known, and any ransomware association is listed as unknown.

Do: Apply Microsoft's October 2024 security updates (or later cumulative updates) to all Windows clients and servers as soon as possible, following vendor instructions; per CISA's required action, apply vendor mitigations or discontinue use of the affected platform if mitigations are unavailable. Until patched, exercise caution with unsolicited documents, links, and content rendered through Windows surfaces, and watch for spoofed prompts or user-interface elements. Federal agencies should complete remediation by the KEV due date for this entry.

8.1
group max
44% KEV
  • Microsoft Windows
mass≈1 billion+ Windows installations worldwide (MSHTML is present on essentially every Windows client and server)
CVE-2024-43582
Remote Desktop Protocol Server Remote Code Execution Vulnerability

Remote Desktop Protocol Server Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.13%
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • microsoft windows 10 22h2
  • +1 more
Full article521 words · extracted from helpnetsecurity.com · click to collapse

For October 2024 Patch Tuesday, Microsoft has released fixes for 117 security vulnerabilities, including two under active exploitation: CVE-2024-43573, a spoofing bug affecting the Windows MSHTML Platform, and CVE-2024-43572, a remote code execution flaw in the Microsoft Management Console (MMC).

CVE-2024-43573 CVE-2024-43572

About CVE-2024-43573 and CVE-2024-43572

As far as it can be deduced from the accompanying advisory, CVE-2024-43573 is similar to CVE-2024-38112, a vulnerability in MSHTML, a browser engine for the now deprecated Internet Explorer, which has been expoited as a zero-day by the Void Banshee APT and patched by Microsoft in July 2024.

It was later revealed that Void Banshee used a second Windows MSHTML flaw in those same attacks.

“There’s no word from Microsoft on whether it’s the same group, but considering there is no acknowledgment here, it makes me think the original patch was insufficient,” says Dustin Childs, head of threat awareness at Trend Micro Inc.’s Zero Day Initiative, who advises testing and deploy the update for CVE-2024-43573 quickly.

According to Satnam Narang, senior staff research engineer at Tenable, CVE-2024-43573 highlights a valuable attack path being currently leveraged by threat actors. “User interaction is required to exploit all of these MSHTML flaws, which typically utilizes some type of social engineering.”

CVE-2024-43572 – the RCE flaw in the Microsoft Management Console – can be triggered by a user loading a malicious MMC snap-in file.

“Microsoft doesn’t say how widespread these attacks are, but considering the amount of social engineering required to exploit this bug, I would think attacks would be limited at this point,” Childs pointed out. Implementing the security update provided by Microsoft will prevent untrusted Microsoft Saved Console (MSC) files from being opened.

“While we don’t have any specific details about the in-the-wild exploitation of CVE-2024-43572, this patch arrived a few months after researchers disclosed an attack technique called GrimResource that leveraged an old cross-site scripting (XSS) vulnerability combined with a specially crafted MSC file to gain code execution privileges,” Narang told Help Net Security.

Other vulnerabilities of note

Microsoft has also released patches for three publicly known (but not actively exploited) vulnerabilities in curl, Windows Hyper-V, and WinLogon, of which the last one is more likely to be exploited (for gaining SYSTEM privileges on compromised systems).

Childs has also singled out two vulnerabilities that can be triggered remotely by sending a specially crafted request or a malformed packet: the former is CVE-2024-43468, a flaw in Microsoft Configuration Manager, and the latter CVE-2024-43582, in Remote Desktop Protocol (RDP) Server. Both could allow remote code execution.

CVE-2024-43488, a critical RCE in the Visual Studio Code extension for Arduino, will not be fixed as the extension has been deprecated.

“Microsoft recommends that customers use Arduino IDE software,” the company says. But Will Bradle, a security consultant at NetSPI, told Help Net Security that although the vulnerable extension is no longer available on the VS Code Marketplace, it can still be installed via GitHub, and existing installations remain vulnerable to unauthenticated RCE.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/10/08/cve-2024-43573-cve-2024-43572/