ZeroHour
CyberScooppublished ()ingested @chrismvasq

Here’s what Microsoft fixed in September’s Patch Tuesday

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-38014
+1 in the same advisory: …38217
Local Privilege Escalation in Microsoft Windows Installer (Actively Exploited)

CVE-2024-38014 is an elevation-of-privilege flaw caused by improper privilege management (CWE-269) in the Microsoft Windows Installer component, rated 7.8 (high) with a local attack vector, low privileges required, and no user interaction. An attacker who already has limited access and can execute code on a targeted machine can trigger the vulnerable Installer behavior to gain elevated privileges, with high impact on the confidentiality, integrity, and availability of the host. The flaw affects the listed Windows 10, Windows 11, and Windows Server versions (CISA describes the affected product simply as 'Microsoft Windows', so other versions may also be impacted). It was fixed as part of Microsoft's September 2024 Patch Tuesday, which addressed 79 flaws including four actively exploited zero-days, and Microsoft's advisories plus CISA's KEV entry (added 2024-09-10) confirm it is being exploited in the wild; no public proof-of-concept is known and ransomware association is unknown. Its EPSS score of 6.3% (93rd percentile) is unusually high for a local privilege escalation, so Windows fleets should treat this as a priority patch.

Do: Apply Microsoft's September 2024 security updates (or any later cumulative update) for the affected Windows 10, Windows 11, and Windows Server versions, prioritizing servers and multi-user systems where untrusted local code runs; because this flaw is KEV-listed and actively exploited, remediation should follow CISA's vendor-instruction requirement. Given September 2024 reporting that a servicing defect left some Windows PCs unpatched despite appearing updated, verify via Windows Update history or your patch-management tooling that the cumulative update actually installed. No workaround is specified in the available data, so patching is the primary mitigation.

7.8
group max
6% KEV
  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 21H2, 22H2, 23H2, 24H2
  • Microsoft Windows Server 2008, 2012, 2016
mass≈1 billion+ Windows devices (Windows Installer is a core component of every affected Windows install)
CVE-2024-38226
Actively Exploited Security Feature Bypass in Microsoft Publisher

CVE-2024-38226 is a security feature bypass (protection mechanism failure, CWE-693) in Microsoft Publisher, rated 7.3 High with a local attack vector, low privileges required, and user interaction required. An attacker triggers it by convincing a user to open a maliciously crafted Publisher file, which defeats Publisher's built-in protection mechanism, allowing the attacker's content to bypass the expected security checks, with high impact rated for confidentiality, integrity, and availability. Users of Publisher as shipped in Microsoft Office 2019 and Microsoft Office Long Term Servicing Channel (LTSC) are affected. The flaw was patched in Microsoft's September 2024 Patch Tuesday, counted among the four actively exploited Microsoft zero-days that month, and CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-10, confirming exploitation in the wild; ransomware use is listed as unknown.

Do: Apply the September 2024 Microsoft security updates for Office 2019/LTSC (Publisher) across all endpoints, prioritizing systems with Publisher installed, per the vendor's instructions or the CISA KEV required action. Until patched, warn users to exercise caution with .pub files from untrusted sources, since exploitation requires opening a crafted file. Confirm no Publisher clients remain on outdated builds after deployment.

7.33% KEV
  • Microsoft Publisher (shipped with Microsoft Office 2019)
  • Microsoft Publisher (shipped with Microsoft Office Long Term Servicing Channel, LTSC)
massmillions of users (Publisher is bundled with enterprise perpetual-license Office 2019/LTSC suites; no precise public install counts for these channels)
CVE-2024-43491
Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, ve

Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these previously mitigated vulnerabilities on Windows 10, version 1507 (Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB) systems that have installed the Windows security update released on March 12, 2024—KB5035858 (OS Build 10240.20526) or other updates released until August 2024. All later versions of Windows 10 are not impacted by this vulnerability. This servicing stack vulnerability is addressed by installing the September 2024 Servicing stack update (SSU KB5043936) AND the September 2024 Windows security update (KB5043083), in that order. Note: Windows 10, version 1507 reached the end of support (EOS) on May 9, 2017 for devices running the Pro, Home, Enterprise, Education, and Enterprise IoT editions. Only Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB editions are still under support.

NVD description · AI analysis pending
9.812%
  • microsoft windows 10 1507
Full article598 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The tech giant's regular vulnerability list includes new vulnerabilities for Windows Updater and Installer.

Microsoft Romania headquarters in City Gate Towers situated in Free Press Square, in Bucharest, Romania. (Getty Images)

Vulnerabilities released in Microsoft’s Patch Tuesday report include several zero-days impacting versions of several Windows products, including Windows Installer and Windows Updater software.  

The tech giant’s Tuesday announcement includes 79 different vulnerabilities, with at least seven rated critical by Microsoft. Three of those vulnerabilities — CVE-2024-38014, CVE-2024-38217, CVE-2024-38226 — have been exploited in the wild.

The vulnerabilities impacting Windows Update and Installer — CVE-2024-43491 and CVE-2024-38014, respectively — could lead to attackers gaining complete access to systems.

The exploited Windows Update vulnerability allows hackers to remove patches and exploit older, previously mitigated vulnerabilities, however, the bug only impacts versions of Windows 10, which are end-of-life (EOL) products. To fix the bug, admins must install a September 2024 Servicing stack update (SSU KB5043936) and a Windows security update (KB5043083). Microsoft states they are unaware of any active exploitation of CVE-2024-43491, however, because it can undo previous fixes, it could be potentially used in an attack with several other exploits.

CVE-2024-38014, meanwhile, is another publicly exploited vulnerability in Windows Installer that allows a hacker to gain system privileges. Microsoft did not further explain how the bug is exploited, but credited Michael Baer with SEC Consult Vulnerability Lab for the discovery.

The Microsoft Office Publisher bug allows attackers to bypass Office macro policies used to block untrusted or malicious files. If an attacker has local privileges, a user can be tricked into downloading and opening a weaponized file that could lead to an attack. The bug impacts Microsoft Publisher 2016, Microsoft Office LTSC 2021, Office 2019, with both the 64-bit and 32-bit versions affected for all products.

Another actively exploited vulnerability, CVE-2024-38217, affects Microsoft’s “Mark of the Web” security feature, which labels  files downloaded from the internet. If exploited, this vulnerability could compromise other security features linked to the mark, such as SmartScreen and Application Reputation.

The vulnerability has been publicly disclosed and is exploited in the wild, Microsoft noted. Cybersecurity firm Elastic Security Labs’ Joe Desimone discovered the bug.

CISA added four of the vulnerabilities to its Known Exploited Vulnerabilities (KEV) list. 

You can read the full Patch Tuesday notes in Microsoft’s Security Resource Center

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-patch-tuesday-september-2024/