ZeroHour
Security Affairspublished ()ingested @securityaffairs

Microsoft Patches Tuesday security updates for April 2024 fixed hundreds of issues

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-20678
+1 in the same advisory: …26234
Remote Procedure Call Runtime Remote Code Execution Vulnerability

Remote Procedure Call Runtime Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.8
group max
3%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2024-21323
+2 in the same advisory: …29053 …21322
Microsoft Defender for IoT Remote Code Execution Vulnerability

Microsoft Defender for IoT Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.8
group max
3%
  • microsoft defender for iot
CVE-2024-26221
Windows DNS Server Remote Code Execution Vulnerability

Windows DNS Server Remote Code Execution Vulnerability

NVD description · AI analysis pending
6.62%
  • microsoft windows server 2016
  • microsoft windows server 2019
  • microsoft windows server 2022
  • +1 more
CVE-2024-29988
Mark of the Web Security Feature Bypass in Microsoft SmartScreen Prompt

CVE-2024-29988 is a security feature bypass in Microsoft SmartScreen Prompt that allows an attacker to defeat the Mark of the Web (MotW) mechanism, which normally flags internet-downloaded files so SmartScreen shows a warning before they run. An attacker triggers it by delivering a crafted file that Windows processes without the expected SmartScreen prompt, often as part of an exploit chain with CVE-2023-38831 (WinRAR) or the related SmartScreen bypass CVE-2024-21412. Successful exploitation strips away a key browser/download defense layer, letting a malicious file execute with no user warning. Any Windows system that relies on SmartScreen to vet internet-delivered content is affected; the available data does not specify affected version ranges. The flaw is confirmed to be exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2024-04-30 — and EPSS estimates a 45.2% chance of exploitation in the next 30 days (99th percentile), though no public PoC is known.

Do: Apply Microsoft's update for CVE-2024-29988 as soon as possible via Windows Update, per CISA's KEV required action to apply vendor mitigations; verify patch status across Windows endpoints. Until patched, scrutinize internet-delivered archives and installers, and ensure the chain components are also remediated — update WinRAR for CVE-2023-38831 and patch the related SmartScreen bypass CVE-2024-21412.

8.845% KEV
  • Microsoft SmartScreen Prompt
masshundreds of millions of Windows devices (SmartScreen is built into and enabled by default on Windows 10/11)
Full article341 words · extracted from securityaffairs.com · click to collapse

Microsoft Patches Tuesday security updates for April 2024 addressed three Critical vulnerabilities, none actively exploited in the wild.

Microsoft Patches Tuesday security updates for April 2024 addressed 147 vulnerabilities in multiple products. This is the highest number of fixed issues from Microsoft this year and the largest since at least 2017. The issues impact Microsoft Windows and Windows Components; Office and Office Components; Azure; .NET Framework and Visual Studio; SQL Server; DNS Server; Windows Defender; Bitlocker; and Windows Secure Boot. According to ZDI, three of these vulnerabilities were reported through their ZDI program.

Only three vulnerabilities, tracked as CVE-2024-21322, CVE-2024-21323, and CVE-2024-29053, are rated Critical, the good news is that they are not actively exploited in the wild.

Below are some of the most interesting issues addressed by the IT giant:

CVE-2024-29988 – SmartScreen Prompt Security Feature Bypass Vulnerability. An attacker can exploit this security feature bypass vulnerability by tricking a user into launching malicious files using a launcher application that requests that no UI be shown. An attacker could send the targeted user a specially crafted file that is designed to trigger the remote code execution issue. The flaw is actively exploited in the wild.

CVE-2024-20678 – Remote Procedure Call Runtime Remote Code Execution Vulnerability. Any authenticated user can exploit this vulnerability, according to Microsoft it does not require admin or other elevated privileges.

CVE-2024-26234 – Proxy Driver Spoofing Vulnerability – The flaw reported by Sophos ties a malicious driver signed with a valid Microsoft Hardware Publisher Certificate. The driver was used in attacks in the wild to deploy a backdoor.

CVE-2024-26221 – Windows DNS Server Remote Code Execution Vulnerability. In a network-based attack an attacker would need to have the privileges to query the Domain Name Service (DNS). If the timing of DNS queries is perfect, the attacker could execute code remotely on the target server.

The full list of flaw fixed by Microsoft in April 2024 is available here.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Patches Tuesday)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/161666/breaking-news/microsoft-patches-tuesday-april-2024.html