ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-3775
When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bitmap size.

When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bitmap size. As consequence an attacker can craft an input which will lead to a out-of-bounds write into grub2's heap, leading to memory corruption and availability issues. Although complex, arbitrary code execution could not be discarded.

NVD description · AI analysis pending
7.1<1%
  • gnu grub2
  • gnu enterprise linux
CVE-2023-40547
A remote code execution vulnerability was found in Shim.

A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, leading to a completely controlled out-of-bounds write primitive and complete system compromise. This flaw is only exploitable during the early boot phase, an attacker needs to perform a Man-in-the-Middle or compromise the boot server to be able to exploit this vulnerability successfully.

NVD description · AI analysis pending
8.35%
  • redhat shim
  • redhat enterprise linux
CVE-2024-38063
+1 in the same advisory: …38140
Windows TCP/IP Remote Code Execution Vulnerability

Windows TCP/IP Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.871%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2024-38193
+4 in the same advisory: …38178 …38107 …38106 …38213
Use-After-Free Privilege Escalation in Microsoft Windows WinSock Driver (afd.sys)

The Windows Ancillary Function Driver for WinSock (afd.sys) contains a use-after-free flaw (CWE-416) that allows a local attacker to escalate privileges. An attacker who can already execute code on a Windows host — typically after gaining initial access via phishing, malware, or chaining with another vulnerability — triggers the bug to gain SYSTEM-level privileges, giving them near-full control of the machine. Any Windows host running an affected build is exposed to the flaw, though it requires local code execution and is not remotely exploitable on its own. Exploitation is confirmed in the wild: CISA added the CVE to the KEV catalog on 2024-08-13 and Microsoft shipped fixes in its August 2024 security updates, while the ransomware association is currently listed as unknown. EPSS is elevated at 28.5% (98th percentile), indicating a high likelihood of continued exploitation over the next 30 days.

Do: Apply Microsoft's August 2024 Windows cumulative security updates (released 2024-08-13) across all Windows clients and servers, prioritizing multi-user hosts such as RDS/VDI servers and jump boxes where local code execution by low-privileged users is more likely. After patching, verify installed build numbers and hunt for signs of local privilege escalation, per CISA's KEV required action to apply vendor mitigations or discontinue use. Keep the host within your KEV remediation SLA, as listing in the catalog signals active exploitation.

7.8
group max
29% KEV PoC
  • Microsoft Windows Supported Windows client (Windows 10, Windows 11) and Windows Server releases; specific affected builds are enumerated in Microsoft's August 2024 security updat
mass>1 billion Windows endpoints worldwide, i.e., effectively every unpatched Windows client or server
CVE-2024-38109
An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network.

An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network.

NVD description · AI analysis pending
8.82%
  • microsoft azure health bot
CVE-2024-38159
+1 in the same advisory: …38160
Windows Network Virtualization Remote Code Execution Vulnerability

Windows Network Virtualization Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.12%
  • microsoft windows 10 1607
  • microsoft windows server 2016
CVE-2024-38166
An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network by trickin

An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network by tricking a user to click on a link.

NVD description · AI analysis pending
6.1<1%
  • microsoft dynamics crm service portal web resource
CVE-2024-38189
Input-validation RCE in Microsoft Project via crafted project files

CVE-2024-38189 is an improper input validation (CWE-20) remote code execution flaw in Microsoft Project. Triggering it requires user interaction: an attacker supplies a maliciously crafted Project file, and when a user opens it, the parsing flaw allows attacker-controlled input to execute code. Successful exploitation yields code execution in the context of the user who opened the file, with high impact to confidentiality, integrity, and availability on that endpoint. Per the CPE data, affected deployments include Project 2016 and the Project client shipped with Office 2019, Office LTSC, and Microsoft 365 Apps. The flaw was one of six zero-days Microsoft patched in its August 2024 Patch Tuesday release and was confirmed to be exploited in the wild, earning a CISA KEV listing on 2024-08-13; EPSS assigns an 8.2% 30-day exploitation probability (95th percentile), and no public PoC is known.

Do: Apply Microsoft's August 2024 Patch Tuesday security updates for Microsoft Project/Office (covering Project 2016 and the Project client in Office 2019, Office LTSC, and Microsoft 365 Apps) immediately, per the CISA KEV required action; as an interim measure, caution users against opening Project files from untrusted sources until patched. After updating, verify that the installed Project/Office build reflects the August 2024 security updates.

8.88% KEV
  • Microsoft Project 2016 Versions prior to Microsoft's August 2024 security updates
  • Microsoft Project client shipped with Microsoft 365 Apps Versions prior to Microsoft's August 2024 security updates
  • Microsoft Project client shipped with Office 2019 Versions prior to Microsoft's August 2024 security updates
  • +1 more
mass≈ millions of enterprise desktop installations (Project desktop is a standard tool across Microsoft's hundreds-of-millions-strong Microsoft 365/Office…
CVE-2024-38206
An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network.

An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network.

NVD description · AI analysis pending
6.512%
  • microsoft copilot studio
Full article596 words · extracted from securityaffairs.com · click to collapse

Microsoft’s August 2024 Patch Tuesday addressed 90 vulnerabilities, including six that are actively exploited.

Patch Tuesday security updates for August 2024 addressed 90 vulnerabilities in Microsoft products including Windows and Windows Components; Office and Office Components; .NET and Visual Studio; Azure; Co-Pilot; Microsoft Dynamics; Teams; and Secure Boot and others, bringing the total to 102 when including third-party bugs. Seven vulnerabilities are rated Critical, 79 Important, and one Moderate. Four of these flaws are publicly known, and six are under active attack. The company confirmed that several vulnerabilities are currently being exploited in the wild.

Below are the actively exploited flaws addressed by Patch Tuesday security updates for August 2024:

CVETitleSeverityCVSSPublicExploitedType
CVE-2024-38189Microsoft Project Remote Code Execution VulnerabilityImportant8.8NoYesRCE
CVE-2024-38178Scripting Engine Memory Corruption VulnerabilityImportant7.5NoYesRCE
CVE-2024-38193Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant7.8NoYesEoP
CVE-2024-38106Windows Kernel Elevation of Privilege VulnerabilityImportant7NoYesEoP
CVE-2024-38107Windows Power Dependency Coordinator Elevation of Privilege VulnerabilityImportant7.8NoYesEoP
CVE-2024-38213Windows Mark of the Web Security Feature Bypass VulnerabilityModerate6.5NoYesSFB

Below is the list of critical flaws addressed by the IT giant:

CVETitleSeverityCVSSPublic Exploitedtype
CVE-2024-38109Azure Health Bot Elevation of Privilege VulnerabilityCritical9.1NoNoEoP
CVE-2024-38206Microsoft Copilot Studio Information Disclosure VulnerabilityCritical8.5NoNoInfo
CVE-2024-38166Microsoft Dynamics 365 Cross-site Scripting VulnerabilityCritical8.2NoNoXSS
CVE-2022-3775 *Redhat: CVE-2022-3775 grub2 – Heap based out-of-bounds write when rendering certain Unicode sequencesCritical7.1NoNoRCE
CVE-2023-40547 *Redhat: CVE-2023-40547 Shim – RCE in HTTP boot support may lead to secure boot bypassCritical8.3NoNoSFB
CVE-2024-38159Windows Network Virtualization Remote Code Execution VulnerabilityCritical9.1NoNoRCE
CVE-2024-38160Windows Network Virtualization Remote Code Execution VulnerabilityCritical9.1NoNoRCE
CVE-2024-38140Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution VulnerabilityCritical9.8NoNoRCE
CVE-2024-38063Windows TCP/IP Remote Code Execution VulnerabilityCritical9.8NoNoRCE

The most severe flaws are:

CVE-2024-38140 is Remote Code Execution Vulnerability in Windows Reliable Multicast Transport Driver (RMCAST). An unauthenticated attacker could exploit the flaw by sending specially crafted packets to a Windows Pragmatic General Multicast (PGM) open socket on the server, without any interaction from the user. However, this vulnerability is only exploitable if there is a program listening on a Pragmatic General Multicast (PGM) port. Microsoft states that if PGM is installed or enabled but no programs are actively listening as a receiver, then this vulnerability is not exploitable.

CVE-2024-38063 is a Remote Code Execution vulnerability in Windows TCP/IP. An unauthenticated attacker could exploit this flaw by sending specially crafted IPv6 packets to a Windows machine, potentially enabling remote code execution.

“Moving on to the other code execution bugs, we’re greeted with three different CVSS 9.8 bugs right off the top. The worst is likely the bug in TCP/IP that would allow a remote, unauthenticated attacker to get elevated code execution just by sending specially crafted IPv6 packets to an affected target. That means it’s wormable.” reported ZDI. “You can disable IPv6 to prevent this exploit, but IPv6 is enabled by default on just about everything. It’s a similar attack scenario for the Reliable Multicast Transport Driver (RMCAST), but in this case, you need a service listening as a receiver on PGM to be vulnerable”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Microsoft Patch Tuesday)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/167000/security/microsoft-patch-tuesday-august-2024.html