Only one critical vulnerability included in May’s Microsoft Patch Tuesday; One other zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-30001 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability Windows Mobile Broadband Driver Remote Code Execution Vulnerability NVD description · AI analysis pending | 6.8 | <1% |
| — | ||
| CVE-2024-30044 | Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability NVD description · AI analysis pending | 7.2 | 84% |
| — | ||
| CVE-2024-30046 | Visual Studio Denial of Service Vulnerability Visual Studio Denial of Service Vulnerability NVD description · AI analysis pending | 5.9 | 2% |
| — | ||
| CVE-2024-30051 | Elevation of Privilege in Microsoft Windows DWM Core Library (Actively Exploited) CVE-2024-30051 is a heap-based buffer overflow / out-of-bounds write (CWE-122, CWE-787) in the Windows Desktop Window Manager (DWM) Core Library that allows a local attacker to escalate privileges. It is triggered by locally executing crafted code that corrupts memory in the DWM component, requiring only low privileges and no user interaction (AV:L/AC:L/PR:L/UI:N). A successful exploit yields high-impact gains on the local system — typically elevation to elevated/SYSTEM rights, giving the attacker full control of confidentiality, integrity and availability on that host. Any organization running the affected Windows 10/11 client releases or Windows Server 2016/2019/2022 with the DWM component is exposed, which in practice means nearly every modern Windows endpoint. The flaw was a zero-day exploited in the wild before remediation: it was added to CISA KEV on 2024-05-14 with known ransomware use, and public reporting ties it to QakBot attack chains and Microsoft's May 2024 Patch Tuesday (which also fixed it alongside other exploited zero-days). Do: Apply Microsoft's May 2024 Patch Tuesday cumulative updates for every affected Windows 10/11 and Windows Server 2016/2019/2022 release immediately; per CISA KEV, apply vendor mitigations or discontinue use of affected systems if updates are unavailable. Prioritize endpoints and servers exposed to user-driven malware (email, web browsing) since the flaw is chained after initial access in QakBot and ransomware operations, and verify patched DWM/dwmcore binaries via the updated OS build. Monitor for local privilege-escalation activity and treat this as a high-priority patch alongside the other May 2024 exploited zero-days. | 7.8 | 6% | KEV ransomware |
| mass≈1 billion+ Windows 10/11 endpoints plus large Windows Server 2016/2019/2022 fleets (DWM is a core component present on effectively every affected Windows… |
Full article452 words · extracted from blog.talosintelligence.com · click to collapse
Tuesday, May 14, 2024 13:57
After a relatively hefty Microsoft Patch Tuesday in April, this month’s security update from the company only included one critical vulnerability across its massive suite of products and services.
In all, May’s slate of vulnerabilities disclosed by Microsoft included 59 total CVEs, most of which are considered to be of “important” severity. There is only one moderate-severity vulnerability.
The lone critical security issue is CVE-2024-30044, a remote code execution vulnerability in SharePoint Server. An authenticated attacker who obtains Site Owner permissions or higher could exploit this vulnerability by uploading a specially crafted file to the targeted SharePoint Server. Then, they must craft specialized API requests to trigger the deserialization of that file’s parameters, potentially leading to remote code execution in the context of the SharePoint Server.
The Windows Mobile Broadband Driver also contains multiple remote code execution vulnerabilities:
- CVE-2024-29997
- CVE-2024-29998
- CVE-2024-29999
- CVE-2024-30000
- CVE-2024-30001
- CVE-2024-30002
- CVE-2024-30003
- CVE-2024-30004
- CVE-2024-30005
However, to successfully exploit this issue, an adversary would need to physically connect a compromised USB device to the victim's machine.
Microsoft also disclosed a zero-day vulnerability in the Windows DWM Core Library, CVE-2024-30051. Desktop Window Manager (DWM) is a Windows operating system service that enables visual effects on the desktop and manages things like transitions between windows.
An adversary could exploit CVE-2024-30051 to gain SYSTEM-level privileges.
This vulnerability is classified as having a “low” level of attack complexity, and exploitation of this vulnerability has already been detected in the wild.
One other issue, CVE-2024-30046, has already been disclosed prior to Patch Tuesday, but has not yet been exploited in the wild. This is a denial-of-service vulnerability in ASP.NET, a web application framework commonly used in Windows.
Microsoft considers this vulnerability “less likely” to be exploited, as successful exploitation would require an adversary to spend a significant amount of time repeating exploitation attempts by sending constant or intermittent data to the targeted machine.
A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its update page.
In response to these vulnerability disclosures, Talos is releasing a new Snort rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Cisco Security Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.
The rules included in this release that protect against the exploitation of many of these vulnerabilities are 63419, 63420, 63422 - 63432, 63444 and 63445. There are also Snort 3 rules 300906 - 300912.
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-may-2024/