Microsoft fixes two zero-days exploited by attackers (CVE-2024-38080, CVE-2024-38112)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-35264 | .NET and Visual Studio Remote Code Execution Vulnerability .NET and Visual Studio Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.1 | 3% |
| — | ||
| CVE-2024-37985 | Windows Kernel Information Disclosure Vulnerability Windows Kernel Information Disclosure Vulnerability NVD description · AI analysis pending | 5.6 | <1% |
| — | ||
| CVE-2024-38060 | Windows Imaging Component Remote Code Execution Vulnerability Windows Imaging Component Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.8 | 16% |
| — | ||
| CVE-2024-38077 +1 in the same advisory: …38074 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.8 | 84% |
| — | ||
| CVE-2024-38076 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2024-38112 +1 in the same advisory: …38080 | Windows MSHTML Platform Spoofing Vulnerability Exploited in the Wild (CVE-2024-38112) CVE-2024-38112 is a spoofing flaw (CWE-451) in the Microsoft Windows MSHTML platform, the Windows component used to render web content, including by applications that embed the legacy Internet Explorer engine. It is triggered when a user interacts with attacker-controlled content rendered through MSHTML: the attack requires no privileges, travels over the network, and needs user interaction (UI:R per its CVSS vector), letting an attacker misrepresent critical UI information to the victim. Despite being classified as spoofing, the CVSS impact scores are high across confidentiality, integrity, and availability, and the CVSS base score is 7.5 (High). Any system running the affected Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), or Windows Server (2008, 2012, 2016, 2019) releases is affected. Exploitation is confirmed in the wild: Microsoft patched it as an actively exploited zero-day in July 2024, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-09, and reporting indicates it had been exploited for over a year before the fix. Do: Apply Microsoft's July 2024 security updates (Patch Tuesday) across all affected Windows 10, Windows 11, and Windows Server versions, prioritizing internet-facing and user workstations given confirmed in-the-wild exploitation and the 84.2% EPSS score. Until patched, remind users to avoid interacting with untrusted web or document content, since exploitation requires user interaction. Track the fix against CISA's KEV catalog deadlines and verify patch status on all endpoints. | 7.5 group max | 84% | KEV |
| masshundreds of millions of Windows devices (essentially all desktops and servers on the listed Windows 10/11 and Windows Server releases) |
Full article605 words · extracted from helpnetsecurity.com · click to collapse
For July 2024 Patch Tuesday, Microsoft has released security updates and patches that fix 142 CVEs, including two exploited zero-days (CVE-2024-38080, CVE-2024-38112) in Windows Hyper-V and Windows MSHTML Platform (respectively).

Zero-days exploited in the wild (CVE-2024-38080, CVE-2024-38112)
CVE-2024-38080 is a integer overflow or wraparound bug affecting Hyper-V, Windows’ native hypervisor for creating virtual machines on systems running Windows and Windows Server. Successful exploitation may allow attackers to gain SYSTEM privileges on the host machine, but initial local access is required to exploit the flaw, according to Microsoft.
Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, advises testing and deploying this update quickly on systems running Hyper-V. “While not specifically stated by Microsoft, let’s assume the worst-case scenario and say that an authorized user could be on a guest OS. Microsoft also does not state how widespread the exploitation is, but this exploit would prove quite useful for ransomware.”
CVE-2024-38112 is a spoofing vulnerability in Windows MSHTML Platform that can be triggered with a specially crafted HTML file.
“This vulnerability resides in the MSHTML (Trident) rendering engine, which is pivotal for rendering web content in Internet Explorer and other applications via embedded web browser controls,” Mike Walters, VP of Vulnerability and Threat Research at Action1, explained.
“The primary flaw stems from inadequate handling and exposure of resources, which could deceive users into believing that malicious content originates from a trusted source. This is due to insufficient validation and enforcement of resource access restrictions, leading to unauthorized exposure within the MSHTML library. Attackers could employ phishing tactics, sending emails with malicious attachments or links leading to spoofed websites. Upon interaction, malicious content could be rendered in a trusted context, misleading users to divulge sensitive information like login credentials or to install malware.”
Other vulnerabilities of note
Two CVEs fixed this month have been publicly disclosed prior to the release of the patches: CVE-2024-35264, a remote code execution flaw in .NET and Visual Studio, and CVE-2024-37985, an information disclosure flaw affecting Windows 11 on ARM64-based systems.
Among the critical vulnerabilities fixed are three (CVE-2024-38074, CVE-2024-38076, CVE-2024-38077) affecting the Windows Remote Desktop Licensing Service. “An attacker could send a specially crafted packet to a server set up as a Remote Desktop Licensing server, which will cause remote code execution,” Microsoft says.
Patches are available, but risk of exploitation can also be temporarily lowered by disabling the service if is not required.
“Exploitation of this should be straightforward, as any unauthenticated user could execute their code simply by sending a malicious message to an affected server,” Childs noted.
“If a bunch of these servers are Internet-connected, I would expect exploitation soon. Now is also a good time to audit your servers to ensure they aren’t running any unnecessary services.”
Tom Bowyer, Director IT Security at Automox says that school districts, government infrastructure, and SLED-type Windows environments are particularly vulnerable due to their widespread use of Remote Desktop services. “Ensuring these systems are patched promptly will help protect against potential attacks that could disrupt critical operations.”
Microsoft has also patched many vulnerabilities that could be used for lateral movement (once initial access is secured):
- 38 CVEs in SQL Server Native Client OLE DB allowing RCE if an authenticated user is tricked into connecting to a malicious SQL server database via a connection driver
- CVE-2024-38060, a bug in the Microsoft Windows Codecs Library which may allow an authenticated attacker to achieve RCE by upload a specially crafted TIFF image to an affected system.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/07/09/microsoft-fixes-two-zero-days-exploited-by-attackers-cve-2024-38080-cve-2024-38112/