ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity1

January 2025 Patch Tuesday forecast: Changes coming in cybersecurity guidance

criticalVulnerability exploited in the wildimportance 60CVE-2024-49138CVE-2024-49113CVE-2024-49112

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-49112
+1 in the same advisory: …49113
Unauthenticated RCE in Microsoft Windows LDAP (CVE-2024-49112)

CVE-2024-49112 is an integer overflow (CWE-190) in the Windows Lightweight Directory Access Protocol (LDAP) implementation that permits remote code execution. It is triggered by network traffic sent to the LDAP service, with no authentication or user interaction required (CVSS 3.1 network vector, low complexity, no privileges). A successful attacker gains arbitrary code execution in the context of the LDAP service process on the target, and on Active Directory domain controllers this typically means compromising a core infrastructure host with high confidentiality, integrity, and availability impact. All listed Windows 10 and Windows 11 client versions and Windows Server 2008 through 2022 are affected, making virtually every unpatched Windows environment — especially those running domain controllers — exposed. Per related coverage, the flaw was addressed in Microsoft's December 2024 Patch Tuesday (72 flaws fixed, four rated critical); no public proof-of-concept or confirmed in-the-wild exploitation is known for this specific RCE yet, though a related Windows LDAP flaw ('LDAPNightmare') has a public PoC that crashes LSASS and reboots domain controllers, and the ~71% EPSS score signals a high likelihood of exploitation within 30 days.

Do: Apply Microsoft's December 2024 (or later) Windows security updates immediately, prioritizing domain controllers and any server with LDAP reachable from untrusted networks. Until fully patched, restrict inbound LDAP/LDAPS traffic (TCP and UDP 389 and 636) to trusted sources and monitor for LSASS crashes or restarts on domain controllers. Because fixes are version-specific cumulative updates, verify each Windows release against Microsoft's advisory to confirm the correct KB is installed.

9.8
group max
71%
  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2 (builds prior to the December 2024 security updates)
  • Microsoft Windows 11 22H2, 24H2 (builds prior to the December 2024 security updates)
  • Microsoft Windows Server 2008 affected builds prior to the December 2024 security updates
  • +4 more
massorder of millions of systems
CVE-2024-49138
Local Privilege Escalation via Heap Overflow in Microsoft Windows CLFS Driver

Microsoft's Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow (CWE-122) that a local attacker can trigger by submitting crafted input to the CLFS component after gaining the ability to run code on the target machine. Successful exploitation overwrites heap memory in the kernel driver and allows the attacker to escalate privileges, typically from an ordinary user account to SYSTEM-level execution. Any Microsoft Windows system is potentially affected; the CISA listing identifies only "Microsoft Windows" and does not enumerate specific versions or builds, and no CVSS score has been published yet. The flaw was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2024-12-10, confirming it is being exploited in the wild (ransomware use is unknown), and EPSS assigns a 25.4% probability of exploitation activity within 30 days (98th percentile). No public proof-of-concept is known, but the in-the-wild exploitation means defenders should treat this as an actively used privilege-escalation primitive, often chained after initial access by malware or another exploit.

Do: Apply Microsoft's security update for Windows per vendor instructions, as required by the CISA KEV listing (added 2024-12-10), and verify patch compliance across Windows endpoints. Because this is a local privilege escalation, prioritize hosts where untrusted users or malware execute code, and review telemetry for local code execution followed by unexpected escalation to SYSTEM. No public PoC exists, so detection should rely on vendor advisory guidance and EDR telemetry rather than public exploit signatures.

7.825% KEV PoC ×2
  • Microsoft Windows
masshundreds of millions to 1 billion+ Windows installations (Windows runs on 1B+ active devices)
Full article776 words · extracted from helpnetsecurity.com · click to collapse

January 2025 Patch Tuesday is now live:
Microsoft fixes actively exploited Windows Hyper-V zero-day flaws

Welcome to 2025 and a new year of patch excitement! In my December article, I talked about Microsoft’s Secure Future Initiative (SFI) and how it manifested in many of the Microsoft products released in 2024. While this security technology trend will continue in 2025, I believe we will also see some major changes to guidance regarding the security requirements, operations, and other aspects associated with our industry.

January 2025 Patch Tuesday forecast

Before we get into some of those details, let’s quickly recap December 2024 Patch Tuesday.

Microsoft set of updates

Microsoft released a small set of updates that only applied to Windows 10, Windows 11, Office, and Sharepoint. There were no standalone SSU updates and only a single development tool update for the relatively obscure Microsoft/Muzic. The Microsoft Windows updates addressed 58 CVEs in the workstation and associated server operating systems.

Only CVE-2024-49138 was both publicly disclosed and known to have been exploited. You have probably noticed that Microsoft often limits the amount of information it includes with its CVE disclosures, such as in the case of this CVE: “An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.”

While this may be the only CVE that has been actively exploited, there are concerns about several others, including CVE-2024-49113 and CVE-2024-49112, which can be chained and used in domain controllers also quickly to crash other Windows servers. The article contains a high-level explanation and a link to the detailed SafeBreach investigation into these vulnerabilities. The good news is they proved the effectiveness of Microsoft’s December update, so ensure you are up-to-date on applying these patches.

.NET Installers

Microsoft sent out a critical announcement to developers with a call to action to check the source of your .NET Installers. Per Microsoft, Edg,io will soon cease operations due to bankruptcy. “It is possible that azureedge.net domains will have downtime soon. We expect these domains to be permanently retired in the first few months of 2025.” Microsoft provides the changes they’ve made and recommended response activities as the call to action.

Important events

Two events of note foreshadow the start of upcoming changes in cybersecurity guidance I previously mentioned. The first event is a set of proposed amendments to the Health Insurance Portability and Accountability Act (HIPAA). HIPAA was introduced when personal medical records were being ‘digitized’ and focused on ensuring patient privacy and not the security of the systems managing the documents.

The proposed changes will significantly impact the healthcare industry and bring security requirements more in line with traditional security frameworks. The second event is the incoming Trump 2.0 administration and its impact on CISA and other federal organizations. President Trump signed the legislation that created CISA in 2018. The new organization’s purpose was to provide guidance on defending the US infrastructure against cyberattacks and to work with the commercial industry to improve cyber defense.

With the incoming administration’s stated desire to remove regulations so private industry can move faster, we may see some changes in the type of guidance CISA will provide. Also, with a stated desire for the US to be a leader in AI technology, we may see CISA become more involved in that aspect of AI-based security. Time will tell how this evolves. These are just two recent events that will result in new guidance and likely impact the way we conduct security operations, but there are sure more changes to come in 2025.

January 2025 Patch Tuesday forecast

  • Microsoft will be fully up-to-speed after the holidays so expect updates across the board for OS, developer tools and applications.
  • Adobe provided security updates for almost every product in their portfolio last Patch Tuesday. We may see some minor releases next week, but don’t expect many.
  • Apple also released security updates for all their operating systems and the Safari browser last month. Don’t expect many updates here either.
  • We saw some early channel, limited updates for Google Chrome and ChromeOS this week, so expect widespread distribution announcements next week.
  • The Mozilla Foundation released security updates for all their products on January 7th. They were a mix of High and Moderate rated updates with a maximum of 11 vulnerabilities reported in Firefox. These releases were Thunderbird ESR 128.6 and Thunderbird 134, Firefox ESR 115.1, Firefox ESR 128.6, and finally Firefox 134. Be sure to include these in your Patch Tuesday mix if you haven’t deployed them already.

2025 could be a very transformative year for our industry with new Windows operating systems, AI technologies, and changes to security guidance and operations. Hang on for a fun ride ahead!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/01/10/january-2025-patch-tuesday-forecast/