May 2024 Patch Tuesday: Microsoft fixes exploited zero-days (CVE-2024-30051, CVE-2024-30040)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-36033 | Local Privilege Escalation in Microsoft Windows DWM Core Library A flaw in the Windows Desktop Window Manager (DWM) Core Library — classified as an untrusted pointer dereference/memory-bounds issue (CWE-822, CWE-119) — allows a local, low-privileged attacker to elevate privileges on affected Windows systems. Per the CVSS vector, exploitation requires only the ability to execute code on the target (local vector, low privileges) and no user interaction. A successful attacker runs code with elevated privileges, gaining high-impact control of confidentiality, integrity, and availability on the host, typically as a post-compromise escalation step after initial access. All systems running Windows 10 1809/21H2/22H2, Windows 11 21H2/22H2/23H2, Windows Server 2019, or Windows Server 2022 (including the 23H2 edition) are affected. The vulnerability is confirmed to be exploited in the wild: CISA added it to the KEV on 2023-11-14, Microsoft's November 2023 Patch Tuesday fixed it among three actively exploited zero-days, public coverage notes active exploitation including reported QakBot malware campaigns, and it carries an elevated EPSS of roughly 12% within 30 days (96th percentile). Do: Apply the November 2023 (November 14, 2023) cumulative Windows updates to all Windows 10 1809/21H2/22H2, Windows 11 21H2/22H2/23H2, Windows Server 2019, and Windows Server 2022 (including 23H2) systems, prioritizing servers, RDS hosts, and shared-use machines. Because the flaw is used as a post-compromise escalation step in the wild (KEV-listed, with public reporting tied to QakBot campaigns), assume possible compromise on unpatched endpoints and hunt for follow-on malware, credential theft, and persistence activity; verify patch levels across the fleet rather than relying on mitigations, as CISA lists patching per vendor instructions as the required action. | 7.8 | 12% | KEV |
| masshundreds of millions of Windows client and server endpoints (the Windows 10 1809+ through Windows 11 23H2 and Server 2019/2022 population; exact unpatched… | |
| CVE-2024-30040 | Actively Exploited Security Feature Bypass in Microsoft Windows MSHTML Platform CVE-2024-30040 is a high-severity (CVSS 8.8) security feature bypass in the Windows MSHTML platform, the HTML-rendering engine component embedded in Internet Explorer and many Windows applications. A remote attacker can trigger it by persuading a user to open or render specially crafted content, since the attack requires user interaction but no privileges or special conditions (AV:N/AC:L/PR:N/UI:R). Successful exploitation defeats an intended Windows security feature, and the high confidentiality, integrity, and availability impact ratings indicate it can enable significant compromise when chained with other techniques. All supported Windows 10 and Windows 11 client releases (1507 through 22H2, and 21H2 through 23H2, respectively) plus Windows Server 2016, 2019, 2022, and 2022 23H2 are affected. The flaw is being actively exploited in the wild — it was added to CISA's KEV catalog on 2024-05-14 and was one of two zero-days fixed in Microsoft's May 2024 Patch Tuesday — though no public proof-of-concept is known and EPSS estimates a 3.9% chance of exploitation in the next 30 days (90th percentile). Do: Apply the May 2024 Patch Tuesday cumulative updates (released 2024-05-14) for Windows 10, Windows 11, and Windows Server as soon as possible; the flaw is under active exploitation and listed in CISA KEV, so prioritize endpoints and servers that render untrusted documents or HTML content. Confirm via patch reporting that the May 2024 cumulative update is installed on all assets, and in the interim caution users against opening unsolicited files and links, since exploitation requires user interaction. | 8.8 | 4% | KEV |
| mass≈1 billion+ Windows installations (MSHTML is a core component of every supported Windows 10/11 and Windows Server release) | |
| CVE-2024-30043 | Microsoft SharePoint Server Information Disclosure Vulnerability Microsoft SharePoint Server Information Disclosure Vulnerability NVD description · AI analysis pending | 7.5 | 55% |
| — | ||
| CVE-2024-30050 | Windows Mark of the Web Security Feature Bypass Vulnerability Windows Mark of the Web Security Feature Bypass Vulnerability NVD description · AI analysis pending | 5.4 | 11% |
| — | ||
| CVE-2024-30051 | Elevation of Privilege in Microsoft Windows DWM Core Library (Actively Exploited) CVE-2024-30051 is a heap-based buffer overflow / out-of-bounds write (CWE-122, CWE-787) in the Windows Desktop Window Manager (DWM) Core Library that allows a local attacker to escalate privileges. It is triggered by locally executing crafted code that corrupts memory in the DWM component, requiring only low privileges and no user interaction (AV:L/AC:L/PR:L/UI:N). A successful exploit yields high-impact gains on the local system — typically elevation to elevated/SYSTEM rights, giving the attacker full control of confidentiality, integrity and availability on that host. Any organization running the affected Windows 10/11 client releases or Windows Server 2016/2019/2022 with the DWM component is exposed, which in practice means nearly every modern Windows endpoint. The flaw was a zero-day exploited in the wild before remediation: it was added to CISA KEV on 2024-05-14 with known ransomware use, and public reporting ties it to QakBot attack chains and Microsoft's May 2024 Patch Tuesday (which also fixed it alongside other exploited zero-days). Do: Apply Microsoft's May 2024 Patch Tuesday cumulative updates for every affected Windows 10/11 and Windows Server 2016/2019/2022 release immediately; per CISA KEV, apply vendor mitigations or discontinue use of affected systems if updates are unavailable. Prioritize endpoints and servers exposed to user-driven malware (email, web browsing) since the flaw is chained after initial access in QakBot and ransomware operations, and verify patched DWM/dwmcore binaries via the updated OS build. Monitor for local privilege-escalation activity and treat this as a high-priority patch alongside the other May 2024 exploited zero-days. | 7.8 | 6% | KEV ransomware |
| mass≈1 billion+ Windows 10/11 endpoints plus large Windows Server 2016/2019/2022 fleets (DWM is a core component present on effectively every affected Windows… |
Full article626 words · extracted from helpnetsecurity.com · click to collapse
For May 2024 Patch Tuesday, Microsoft has released fixes for 59 CVE-numbered vulnerabilities, including two zero-days (CVE-2024-30051, CVE-2024-30040) actively exploited by attackers.

CVE-2024-30051 and CVE-2024-30040
CVE-2024-30051 is a heap-based buffer overflow vulnerability affecting the Windows DWM Core Library that can be exploited to elevate attackers’ privileges on a target system. “An attacker who successfully exploited this vulnerability could gain SYSTEM privileges,” Microsoft says.
Researchers from Kaspersky, DBAPPSecurity WeBin Lab, Google Threat Analysis Group and Google Mandiant have been credited with reporting it so it has been speculated that the attacks leveraging it are widespread.
Kaspersky researchers Boris Larin and Mert Degirmenci have shared more details: CVE-2024-30051 is being leveraged in conjuction with Qakbot and other malware. “[We] believe that multiple threat actors have access to it,” they said, and promised to publish technical details once users have had time to update their Windows systems.
The interesting thing here is how they “discovered” the vulnerability: it was described in a file uploaded to VirusTotal.
“The exploitation process described in this document was identical to that used in the previously mentioned zero-day exploit for CVE-2023-36033, but the vulnerability was different,” they said.
CVE-2024-30040 is a vulnerability that allows attackers to bypasses OLE [Object Linking and Embedding] mitigations in Microsoft 365 and Microsoft Office (i.e., security features that protect users from malicious files).
To exploit it, attackers need to “convince the user to load a malicious file onto a vulnerable system, typically by way of an enticement in an email or instant messenger message, and then convince the user to manipulate the specially crafted file, but not necessarily click or open the malicious file,” Microsoft says.
“An unauthenticated attacker who successfully exploited this vulnerability could gain code execution through convincing a user to open a malicious document at which point the attacker could execute arbitrary code in the context of the user.”
Microsoft does not say who reported the vulnerability or explains the nature of the attacks for which it is being leveraged.
Other vulnerabilities of note
Satnam Narang, senior staff research engineer at Tenable, says that exploitation of CVE-2024-30043, the only critical vulnerability fixed this month, requires an attacker to be authenticated to a vulnerable SharePoint Server with Site Owner permissions (or higher) first and then take additional steps, “which makes this flaw less likely to be widely exploited as most attackers follow the path of least resistance.”
The discoverer – Piotr Bazydło – says it’s the most interesting XML external entity (XXE) injection flaw that he’s ever found.
“An authenticated attacker could use this bug to read local files with SharePoint Farm service account user privileges. They could also perform an HTTP-based server-side request forgery (SSRF), and – most importantly – perform NLTM relaying as the SharePoint Farm service account,” Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, commented.
He also singled out CVE-2024-30050, a moderately severe vulnerability that may allow attackers to bypass the protections provided by Windows Mark of the Web (MotW) controls, because this type of security feature bypass is quite in vogue with ransomware gangs at the moment.
“They zip their payload to bypass network and host-based defenses, they use a Mark of the Web (MotW) bypass to evade SmartScreen or Protected View in Microsoft Office,” he explained.
“While we have no indication this bug is being actively used, we see the technique used often enough to call it out. Bugs like this one show why Moderate-rated bugs shouldn’t be ignored or deprioritized.”
UPDATE (May 31, 2024, 04:25 a.m. ET):
Bazydło has published a write-up on CVE-2024-30043, along with a demonstration of exploitation.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/05/14/patch-tuesday-cve-2024-30051-cve-2024-30040/