ZeroHour
Cisco Talospublished ()ingested

November Patch Tuesday release contains three critical remote code execution vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-49039
+1 in the same advisory: …43451
Windows Task Scheduler Elevation-of-Privilege Flaw Actively Exploited in the Wild

CVE-2024-49039 is an elevation-of-privilege vulnerability (CWE-287, improper authentication) in the Microsoft Windows Task Scheduler, scored 8.8 (High) with a local attack vector, low required privileges, and a changed scope indicating the exploit crosses a security boundary. A local attacker with limited user privileges can trigger the flaw through Task Scheduler to gain elevated rights on the affected system, typically SYSTEM- or administrator-level control, with no user interaction required. Every supported Windows desktop and server release in the vendor's affected list is impacted, since Task Scheduler is a core component of the operating system. The flaw was patched as an actively exploited zero-day in the November 2024 Patch Tuesday release, was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-12, and ransomware operators are known to use it. With an EPSS of 14.2% (96th percentile), defenders should treat this as a high-priority local privilege escalation for privilege-chaining and ransomware campaigns.

Do: Apply the November 2024 Windows security updates across all affected Windows 10, Windows 11, and Windows Server branches, prioritizing servers, jump hosts, and machines used by privileged users given confirmed ransomware use. Confirm no supported Windows host is left unpatched, review local task creation and authentication logs for signs of privilege escalation, and follow CISA's required action to apply vendor mitigations or discontinue use if patches are unavailable.

8.8
group max
14% KEV ransomware
  • Microsoft Windows 10 1507
  • Microsoft Windows 10 1607
  • Microsoft Windows 10 1809
  • +9 more
masshundreds of millions of Windows systems (Task Scheduler ships with every Windows 10, Windows 11, and Windows Server installation)
CVE-2024-43498
.NET and Visual Studio Remote Code Execution Vulnerability

.NET and Visual Studio Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.84%
  • microsoft .net
  • microsoft visual studio 2022
CVE-2024-43602
Azure CycleCloud Remote Code Execution Vulnerability

Azure CycleCloud Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.92%
  • microsoft azure cyclecloud
CVE-2024-43623
+1 in the same advisory: …43636
Windows NT OS Kernel Elevation of Privilege Vulnerability

Windows NT OS Kernel Elevation of Privilege Vulnerability

NVD description · AI analysis pending
7.84%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2024-43642
+1 in the same advisory: …43625
Unauthenticated use-after-free DoS in Windows SMB (Windows 11 / Windows Server)

CVE-2024-43642 is a use-after-free flaw (CWE-416) in the SMB implementation of Windows that allows an unauthenticated remote attacker to send specially crafted SMB network traffic and crash the affected service. Because the CVSS vector is network-exploitable with low complexity, no privileges and no user interaction, any host running the SMB service on an affected edition can be targeted directly. The attacker gains only availability impact (a high-severity denial of service); confidentiality and integrity are not affected. Systems running Windows 11 22H2, 23H2 or 24H2 and Windows Server 2022, 2022 23H2 or 2025 are affected until they receive the November 2024 cumulative security updates. As of the current data there is no public proof-of-concept and the flaw is not in CISA's KEV catalog, but its EPSS of 62.7% (99th percentile) indicates an elevated likelihood of exploitation attempts within 30 days.

Do: Install the November 2024 cumulative security update for Windows 11 22H2/23H2/24H2 and Windows Server 2022/2022 23H2/2025 as soon as practical, prioritizing internet-facing and multi-user servers. Until patched, restrict inbound SMB (TCP/UDP 445) to trusted networks only via firewall rules or VPN, and monitor for crash/restart events of the SMB service on exposed hosts.

7.5
group max
63%
  • microsoft windows 11 22h2
  • microsoft windows 11 23h2
  • microsoft windows 11 24h2
  • +3 more
masshundreds of millions of endpoints and servers potentially in scope (Windows 11 22H2-24H2 desktop base plus Windows Server 2022/2025 fleets)
CVE-2024-43629
Windows DWM Core Library Elevation of Privilege Vulnerability

Windows DWM Core Library Elevation of Privilege Vulnerability

NVD description · AI analysis pending
7.84%
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • microsoft windows 10 22h2
  • +1 more
CVE-2024-43630
Windows Kernel Elevation of Privilege Vulnerability

Windows Kernel Elevation of Privilege Vulnerability

NVD description · AI analysis pending
7.84%
  • microsoft windows 10 21h2
  • microsoft windows 10 22h2
  • microsoft windows 11 24h2
  • +1 more
CVE-2024-43639
Windows KDC Proxy Remote Code Execution Vulnerability

Windows KDC Proxy Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.89%
  • microsoft windows server 2012
  • microsoft windows server 2016
  • microsoft windows server 2019
  • +1 more
CVE-2024-49019
Active Directory Certificate Services Elevation of Privilege Vulnerability

Active Directory Certificate Services Elevation of Privilege Vulnerability

NVD description · AI analysis pending
7.82%
  • microsoft windows server 2008
  • microsoft windows server 2012
  • microsoft windows server 2016
  • +1 more
CVE-2024-49033
Microsoft Word Security Feature Bypass Vulnerability

Microsoft Word Security Feature Bypass Vulnerability

NVD description · AI analysis pending
7.52%
  • microsoft 365 apps
  • microsoft office
  • microsoft office long term servicing channel
  • +1 more
Full article546 words · extracted from blog.talosintelligence.com · click to collapse

Tuesday, November 12, 2024 18:11

The Patch Tuesday for November of 2024 includes 89 vulnerabilities, including four that Microsoft marked as “critical.” The remaining vulnerabilities listed are classified as “important.”

Microsoft assessed that exploitation of the four “critical” vulnerabilities is “less likely.”

CVE-2024-43639 is a remote code execution vulnerability in Windows Kerberos that could be exploited by an attacker by creating a specially crafted application to leverage a vulnerable cryptographic protocol. While considered “critical” it was determined that exploitation is “less likely” and not been detected in the wild.

CVE-2024-43625 is a privilege escalation vulnerability in a VMSwitch driver, which is a networking component of Hyper-V. An attacker could exploit this by sending a specific series of network packets to the driver to trigger a “use after free” vulnerability in the Hyper-V host, allowing the attacker to execute arbitrary code with elevated privileges.Although classified as “critical,” exploitation was deemed “less likely” and the attack complexity considered “high.” Microsoft has not detected active exploitation of this vulnerability in the wild.

CVE-2024-43602 is a remote code execution vulnerability in Azure CycleCloud. Although marked as "critical," Microsoft has determined that exploitation is "less likely." If an attacker has gained basic user privileges they may be able to exploit this by sending specially crafted packets to the Azure CycleCloud cluster to gain root privileges. Microsoft has not detected active exploitation of this vulnerability in the wild.

CVE-2024-43498 is a "critical" remote code execution vulnerability in .NET and Visual Studio. Microsoft has assessed exploitation of this vulnerability as "less likely." A remote attacker could exploit a vulnerable .NET web app by sending specially crafted packets, or loading a specially crafted file into a vulnerable application. In the wild exploitation of this vulnerability has not been detected by Microsoft.

Of the vulnerabilities included in the release, several “important” updates were listed as “exploitation more likely”. These updates are listed below:

  • CVE-2024-49033 - Microsoft Word Security Feature Bypass Vulnerability
  • CVE-2024-43623 - Windows NT OS Kernel Elevation of Privilege Vulnerability
  • CVE-2024-43629 - Windows DWM Core Library Elevation of Privilege Vulnerability
  • CVE-2024-43630 - Windows Kernel Elevation of Privilege Vulnerability
  • CVE-2024-43636 - Win32k Elevation of Privilege Vulnerability
  • CVE-2024-49019 - Active Directory Certificate Services Elevation of Privilege VulnerabilityCisco Confidential
  • CVE-2024-43642 - Windows SMB Denial of Service Vulnerability

Additionally, Talos would like to highlight the following “important” vulnerabilities as exploitation has been detected by Microsoft:

A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its update page. In response to these vulnerability disclosures, Talos is releasing a new Snort rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Cisco Security Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.

The rules included in this release that protect against the exploitation of many of these vulnerabilities are 62022, 62023, 64218-64224, 64229, 64232 and 64233. There are also Snort 3 rules 301064, 300612, 301065, 301066 and 301073.

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/november-patch-tuesday-release/