ZeroHour
Security Affairspublished ()ingested @securityaffairs

Microsoft Patch Tuesday security updates for November 2024 fix two actively exploited zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-49039
+1 in the same advisory: …43451
Windows Task Scheduler Elevation-of-Privilege Flaw Actively Exploited in the Wild

CVE-2024-49039 is an elevation-of-privilege vulnerability (CWE-287, improper authentication) in the Microsoft Windows Task Scheduler, scored 8.8 (High) with a local attack vector, low required privileges, and a changed scope indicating the exploit crosses a security boundary. A local attacker with limited user privileges can trigger the flaw through Task Scheduler to gain elevated rights on the affected system, typically SYSTEM- or administrator-level control, with no user interaction required. Every supported Windows desktop and server release in the vendor's affected list is impacted, since Task Scheduler is a core component of the operating system. The flaw was patched as an actively exploited zero-day in the November 2024 Patch Tuesday release, was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-12, and ransomware operators are known to use it. With an EPSS of 14.2% (96th percentile), defenders should treat this as a high-priority local privilege escalation for privilege-chaining and ransomware campaigns.

Do: Apply the November 2024 Windows security updates across all affected Windows 10, Windows 11, and Windows Server branches, prioritizing servers, jump hosts, and machines used by privileged users given confirmed ransomware use. Confirm no supported Windows host is left unpatched, review local task creation and authentication logs for signs of privilege escalation, and follow CISA's required action to apply vendor mitigations or discontinue use if patches are unavailable.

8.8
group max
14% KEV ransomware
  • Microsoft Windows 10 1507
  • Microsoft Windows 10 1607
  • Microsoft Windows 10 1809
  • +9 more
masshundreds of millions of Windows systems (Task Scheduler ships with every Windows 10, Windows 11, and Windows Server installation)
CVE-2024-43498
.NET and Visual Studio Remote Code Execution Vulnerability

.NET and Visual Studio Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.84%
  • microsoft .net
  • microsoft visual studio 2022
CVE-2024-43602
Azure CycleCloud Remote Code Execution Vulnerability

Azure CycleCloud Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.92%
  • microsoft azure cyclecloud
Full article390 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini November 13, 2024

Microsoft Patch Tuesday security updates for November 2024 addressed 89 vulnerabilities, including two actively exploited zero-day flaws.

Microsoft Patch Tuesday security updates for November 2024 fixed 89 vulnerabilities in Windows and Windows Components; Office and Office Components; Azure; .NET and Visual Studio; LightGBM; Exchange Server; SQL Server; TorchGeo; Hyper-V; and Windows VMSwitch.

Four of these vulnerabilities are rated Critical, 84 are rated Important, and one is rated Moderate in severity. Microsoft has addressed a total of 949 vulnerabilities this year.

“Microsoft lists three of these CVEs as publicly known, but I disagree and put the count at five (more on that later).” reads the post published by the Zero Day Initiative. “They also list two as being exploited in the wild at the time of release. Let’s take a closer look at some of the more interesting updates for this month, starting with the vulnerabilities currently under active attack:”

Two of the vulnerabilities, tracked as CVE-2024-43451 and CVE-2024-49039, are listed as being exploited in the wild at the time of release. Below are the descriptions for these two vulnerabilities:

  • CVE-2024-43451: An NTLM Hash Disclosure Spoofing vulnerability in MSHTML allows attackers to extract a user’s NTLMv2 hash via Internet Explorer components in WebBrowser control. Although user interaction is needed, attackers can still exploit this to impersonate the victim. Immediate patching is recommended.
  • CVE-2024-49039: A Windows Task Scheduler privilege escalation flaw allows AppContainer escape, enabling low-privileged users to run code at Medium integrity. Discovered by multiple researchers, it is actively exploited, especially across different regions, highlighting its potential impact.

The most severe vulnerability addressed by the IT giant is an Azure CycleCloud Remote Code Execution issue tracked as CVE-2024-43602 (CVSS score of 9.9). An attacker with basic user permissions can exploit Azure CycleCloud by sending crafted requests to gain root access, allowing command execution across clusters and potential administrator credential compromise.

Microsoft also addressed a .NET and Visual Studio Remote Code Execution issue tracked as CVE-2024-43498 (CVSS score 9.8). CVE-2024-43498 allows remote code execution via crafted requests to .NET web apps or files loaded by desktop apps.

The full list of vulnerabilities Microsoft addresses with Patch Tuesday security updates for November 2024 is available here.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Patch Tuesday)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/170851/hacking/microsoft-patch-tuesday-november-2024.html