ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Microsoft fixes two zero-days exploited by attackers (CVE-2024-38080, CVE-2024-38112)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-35264
.NET and Visual Studio Remote Code Execution Vulnerability

.NET and Visual Studio Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.13%
  • microsoft .net
  • microsoft visual studio 2022
CVE-2024-37985
Windows Kernel Information Disclosure Vulnerability

Windows Kernel Information Disclosure Vulnerability

NVD description · AI analysis pending
5.6<1%
  • microsoft windows 11 22h2
  • microsoft windows 11 23h2
CVE-2024-38060
Windows Imaging Component Remote Code Execution Vulnerability

Windows Imaging Component Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.816%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2024-38077
+1 in the same advisory: …38074
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.884%
  • microsoft windows server 2008
  • microsoft windows server 2012
  • microsoft windows server 2016
  • +1 more
CVE-2024-38076
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.82%
  • microsoft windows server 2016
  • microsoft windows server 2019
  • microsoft windows server 2022
  • +1 more
CVE-2024-38112
+1 in the same advisory: …38080
Windows MSHTML Platform Spoofing Vulnerability Exploited in the Wild (CVE-2024-38112)

CVE-2024-38112 is a spoofing flaw (CWE-451) in the Microsoft Windows MSHTML platform, the Windows component used to render web content, including by applications that embed the legacy Internet Explorer engine. It is triggered when a user interacts with attacker-controlled content rendered through MSHTML: the attack requires no privileges, travels over the network, and needs user interaction (UI:R per its CVSS vector), letting an attacker misrepresent critical UI information to the victim. Despite being classified as spoofing, the CVSS impact scores are high across confidentiality, integrity, and availability, and the CVSS base score is 7.5 (High). Any system running the affected Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), or Windows Server (2008, 2012, 2016, 2019) releases is affected. Exploitation is confirmed in the wild: Microsoft patched it as an actively exploited zero-day in July 2024, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-09, and reporting indicates it had been exploited for over a year before the fix.

Do: Apply Microsoft's July 2024 security updates (Patch Tuesday) across all affected Windows 10, Windows 11, and Windows Server versions, prioritizing internet-facing and user workstations given confirmed in-the-wild exploitation and the 84.2% EPSS score. Until patched, remind users to avoid interacting with untrusted web or document content, since exploitation requires user interaction. Track the fix against CISA's KEV catalog deadlines and verify patch status on all endpoints.

7.5
group max
84% KEV
  • Microsoft Windows 10 1507
  • Microsoft Windows 10 1607
  • Microsoft Windows 10 1809
  • +9 more
masshundreds of millions of Windows devices (essentially all desktops and servers on the listed Windows 10/11 and Windows Server releases)
Full article605 words · extracted from helpnetsecurity.com · click to collapse

For July 2024 Patch Tuesday, Microsoft has released security updates and patches that fix 142 CVEs, including two exploited zero-days (CVE-2024-38080, CVE-2024-38112) in Windows Hyper-V and Windows MSHTML Platform (respectively).

CVE-2024-38080 CVE-2024-38112

Zero-days exploited in the wild (CVE-2024-38080, CVE-2024-38112)

CVE-2024-38080 is a integer overflow or wraparound bug affecting Hyper-V, Windows’ native hypervisor for creating virtual machines on systems running Windows and Windows Server. Successful exploitation may allow attackers to gain SYSTEM privileges on the host machine, but initial local access is required to exploit the flaw, according to Microsoft.

Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, advises testing and deploying this update quickly on systems running Hyper-V. “While not specifically stated by Microsoft, let’s assume the worst-case scenario and say that an authorized user could be on a guest OS. Microsoft also does not state how widespread the exploitation is, but this exploit would prove quite useful for ransomware.”

CVE-2024-38112 is a spoofing vulnerability in Windows MSHTML Platform that can be triggered with a specially crafted HTML file.

“This vulnerability resides in the MSHTML (Trident) rendering engine, which is pivotal for rendering web content in Internet Explorer and other applications via embedded web browser controls,” Mike Walters, VP of Vulnerability and Threat Research at Action1, explained.

“The primary flaw stems from inadequate handling and exposure of resources, which could deceive users into believing that malicious content originates from a trusted source. This is due to insufficient validation and enforcement of resource access restrictions, leading to unauthorized exposure within the MSHTML library. Attackers could employ phishing tactics, sending emails with malicious attachments or links leading to spoofed websites. Upon interaction, malicious content could be rendered in a trusted context, misleading users to divulge sensitive information like login credentials or to install malware.”

Other vulnerabilities of note

Two CVEs fixed this month have been publicly disclosed prior to the release of the patches: CVE-2024-35264, a remote code execution flaw in .NET and Visual Studio, and CVE-2024-37985, an information disclosure flaw affecting Windows 11 on ARM64-based systems.

Among the critical vulnerabilities fixed are three (CVE-2024-38074, CVE-2024-38076, CVE-2024-38077) affecting the Windows Remote Desktop Licensing Service. “An attacker could send a specially crafted packet to a server set up as a Remote Desktop Licensing server, which will cause remote code execution,” Microsoft says.

Patches are available, but risk of exploitation can also be temporarily lowered by disabling the service if is not required.

“Exploitation of this should be straightforward, as any unauthenticated user could execute their code simply by sending a malicious message to an affected server,” Childs noted.

“If a bunch of these servers are Internet-connected, I would expect exploitation soon. Now is also a good time to audit your servers to ensure they aren’t running any unnecessary services.”

Tom Bowyer, Director IT Security at Automox says that school districts, government infrastructure, and SLED-type Windows environments are particularly vulnerable due to their widespread use of Remote Desktop services. “Ensuring these systems are patched promptly will help protect against potential attacks that could disrupt critical operations.”

Microsoft has also patched many vulnerabilities that could be used for lateral movement (once initial access is secured):

  • 38 CVEs in SQL Server Native Client OLE DB allowing RCE if an authenticated user is tricked into connecting to a malicious SQL server database via a connection driver
  • CVE-2024-38060, a bug in the Microsoft Windows Codecs Library which may allow an authenticated attacker to achieve RCE by upload a specially crafted TIFF image to an affected system.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/07/09/microsoft-fixes-two-zero-days-exploited-by-attackers-cve-2024-38080-cve-2024-38112/