ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-35264
.NET and Visual Studio Remote Code Execution Vulnerability

.NET and Visual Studio Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.13%
  • microsoft .net
  • microsoft visual studio 2022
CVE-2024-37985
Windows Kernel Information Disclosure Vulnerability

Windows Kernel Information Disclosure Vulnerability

NVD description · AI analysis pending
5.6<1%
  • microsoft windows 11 22h2
  • microsoft windows 11 23h2
CVE-2024-38023
Microsoft SharePoint Server Remote Code Execution Vulnerability

Microsoft SharePoint Server Remote Code Execution Vulnerability

NVD description · AI analysis pending
7.253%
  • microsoft sharepoint server
CVE-2024-38060
Windows Imaging Component Remote Code Execution Vulnerability

Windows Imaging Component Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.816%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2024-38077
+1 in the same advisory: …38074
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.884%
  • microsoft windows server 2008
  • microsoft windows server 2012
  • microsoft windows server 2016
  • +1 more
CVE-2024-38076
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.82%
  • microsoft windows server 2016
  • microsoft windows server 2019
  • microsoft windows server 2022
  • +1 more
CVE-2024-38112
+1 in the same advisory: …38080
Windows MSHTML Platform Spoofing Vulnerability Exploited in the Wild (CVE-2024-38112)

CVE-2024-38112 is a spoofing flaw (CWE-451) in the Microsoft Windows MSHTML platform, the Windows component used to render web content, including by applications that embed the legacy Internet Explorer engine. It is triggered when a user interacts with attacker-controlled content rendered through MSHTML: the attack requires no privileges, travels over the network, and needs user interaction (UI:R per its CVSS vector), letting an attacker misrepresent critical UI information to the victim. Despite being classified as spoofing, the CVSS impact scores are high across confidentiality, integrity, and availability, and the CVSS base score is 7.5 (High). Any system running the affected Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), or Windows Server (2008, 2012, 2016, 2019) releases is affected. Exploitation is confirmed in the wild: Microsoft patched it as an actively exploited zero-day in July 2024, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-09, and reporting indicates it had been exploited for over a year before the fix.

Do: Apply Microsoft's July 2024 security updates (Patch Tuesday) across all affected Windows 10, Windows 11, and Windows Server versions, prioritizing internet-facing and user workstations given confirmed in-the-wild exploitation and the 84.2% EPSS score. Until patched, remind users to avoid interacting with untrusted web or document content, since exploitation requires user interaction. Track the fix against CISA's KEV catalog deadlines and verify patch status on all endpoints.

7.5
group max
84% KEV
  • Microsoft Windows 10 1507
  • Microsoft Windows 10 1607
  • Microsoft Windows 10 1809
  • +9 more
masshundreds of millions of Windows devices (essentially all desktops and servers on the listed Windows 10/11 and Windows Server releases)
Full article342 words · extracted from infosecurity-magazine.com · click to collapse

Sysadmins have a busy time ahead this month after Microsoft issued updates for over 140 CVEs, including four zero-day vulnerabilities.

The zero-days are as follows:

  • CVE-2024-38080 is an elevation of privilege (EoP) vulnerability affecting Microsoft Hyper-V virtualization. It has been actively exploited in the wild to give attackers system-level privileges
  • CVE-2024-38112 is a spoofing vulnerability affecting Microsoft’s MSHTML browser engine impacting all versions of Windows. User interaction is required for exploitation, which has been observed in the wild
  • CVE-2024-35264 is a publicly disclosed remote code execution (RCE) vulnerability in .NET and Visual Studio. An attacker could exploit the bug by “closing an http/3 stream while the request body is being processed leading to a race condition” – leading to RCE, Microsoft explained
  • CVE-2024-37985 is described as "Systematic Identification and Characterization of Proprietary Prefetchers." An attacker who successfully exploits the bug could view heap memory from a privileged process running on the server, although this requires “additional actions prior to exploitation to prepare the target environment"

RCE Vulnerabilities 

Microsoft patched five critical RCE vulnerabilities in this July's Patch Tuesday.

First, a SharePoint vulnerability CVE-2024-38023 has been identified. "[It] could allow an authenticated attacker with site owner permissions or higher to upload a specially crafted file to a SharePoint Server, then craft malicious API requests to trigger deserialisation of the file's parameters, thus enabling them to achieve remote code execution in the context of the SharePoint server,” explained Rapid7 product manager, Greg Wiseman.

Next, CVE-2024-38060 is a bug in the Windows Imaging Component related to TIFF (Tagged Image File Format) image processing, which could enable execution of arbitrary code on a targeted system.

The final three RCE vulnerabilities – CVE-2024-38074, CVE-2024-38076 and CVE-2024-38077 – relate to the Windows Remote Desktop Licensing Service, and have CVSS base score of 9.8.

“If you rely on the Remote Desktop licensing service, best get patching immediately,” urged Wiseman. “As a mitigation, consider disabling the service entirely until there is an opportunity to apply the update.” 

Read more on Patch Tuesday: Microsoft Fixes Three Zero-Days in May Patch Tuesday.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-four-zerodays-july-patch/