ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Microsoft fixes critical flaws in Windows Kerberos, Hyper-V (CVE-2024-20674, CVE-2024-20700)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-20674
+2 in the same advisory: …20653 …20683
Windows Kerberos Security Feature Bypass Vulnerability

Windows Kerberos Security Feature Bypass Vulnerability

NVD description · AI analysis pending
8.8
group max
17%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2024-20677
A security vulnerability exists in FBX that could lead to remote code execution.

A security vulnerability exists in FBX that could lead to remote code execution. To mitigate this vulnerability, the ability to insert FBX files has been disabled in Word, Excel, PowerPoint and Outlook for Windows and Mac. Versions of Office that had this feature enabled will no longer have access to it. This includes Office 2019, Office 2021, Office LTSC for Mac 2021, and Microsoft 365. As of February 13, 2024, the ability to insert FBX files has also been disabled in 3D Viewer. 3D models in Office documents that were previously inserted from a FBX file will continue to work as expected unless the Link to File option was chosen at insert time. This change is effective as of the January 9, 2024 security update.

NVD description · AI analysis pending
7.83%
  • microsoft 365 apps
  • microsoft office
  • microsoft office long term servicing channel
CVE-2024-20686
Win32k Elevation of Privilege Vulnerability

Win32k Elevation of Privilege Vulnerability

NVD description · AI analysis pending
7.8<1%
  • microsoft windows server 2022 23h2
CVE-2024-21310
+2 in the same advisory: …20698 …20700
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

NVD description · AI analysis pending
7.8
group max
12%
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • microsoft windows 10 22h2
  • +1 more
CVE-2024-21318
Microsoft SharePoint Server Remote Code Execution Vulnerability

Microsoft SharePoint Server Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.831%
  • microsoft sharepoint server
Full article471 words · extracted from helpnetsecurity.com · click to collapse

For January 2024 Patch Tuesday, Microsoft has released fixes for 49 CVE-numbered vulnerabilities, two of which are critical: CVE-2024-20674 and CVE-2024-20700.

CVE-2024-20674

None of the vulnerabilities fixed this time aroundare under active exploitation or have been previously publicly disclosed.

The critical fixes (CVE-2024-20674, CVE-2024-20700)

CVE-2024-20674 is a security feature bypass vulnerability that may allow attackers to impersonate Windows’ Kerberos server.

“An unauthenticated attacker could exploit this vulnerability by establishing a machine-in-the-middle (MITM) attack or other local network spoofing technique, then sending a malicious Kerberos message to the client victim machine to spoof itself as the Kerberos authentication server,” Microsoft explains.

Though an attacker must first gain access to the restricted network before running an attack, Microsoft thinks that the likelihood of attackers exploiting this flaw is considerable and the complexity of attack is low, and has therefore urged admins to prioritize testing and deploying this patch.

CVE-2024-20700 is a remote code execution flaw in Windows’ Hyper-V native hypervisor. Once again, an attacker first needs to gain access to the restricted network before deploying an exploit for this flaw. But they would also need to win a race condition.

As noted by Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, “we’ve seen plenty of Pwn2Own winners use race conditions in their exploits” – but this requirement makes a successful attack more difficult.

Other fixes to implement sooner rather than later

Satnam Narang, senior staff research engineer at Tenable, singled out CVE-2024-21318, a remote code execution vulnerability in Microsoft SharePoint Server.

“An authenticated attacker with Site Owner privileges could exploit this vulnerability, potentially obtaining access to highly sensitive files stored in this cloud-based server. Despite the authentication requirement, Microsoft says exploitation of this flaw is more likely. Organizations that use SharePoint Server should apply these patches as soon as possible,” he told Help Net Security.

Other vulnerabilities deemed more likely to be exploited are several elevation of privilege vulnerabilities in Windows Clouds Files Mini Filter Driver (CVE-2024-21310), Common Log File System (CVE-2024-20653), Windows Kernel (CVE-2024-20698) and Win32k (CVE-2024-20683, CVE-2024-20686), Narang also pointed out.

Finally, Microsoft has fixed CVE-2024-20677, a vulnerability in Microsoft Office that could lead to remote code execution via FBX files.

“An attacker who successfully exploits this vulnerability could perform a remote attack that could enable access to the victim’s information and the ability to alter information. Successful exploitation could also potentially cause downtime for the targeted environment,” says Microsoft.

The company fixed this flaw by disabling the ability to insert FBX files in Word, Excel, PowerPoint and Outlook for Windows and Mac.

“3D models in Office documents that were previously inserted from a FBX file will continue to work as expected unless the Link to File option was chosen at insert time,” Microsoft added.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/01/09/cve-2024-20674-cve-2024-20700/