Microsoft Patch Tuesday security updates for September 2024 addressed four actively exploited zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-38014 +1 in the same advisory: …38217 | Local Privilege Escalation in Microsoft Windows Installer (Actively Exploited) CVE-2024-38014 is an elevation-of-privilege flaw caused by improper privilege management (CWE-269) in the Microsoft Windows Installer component, rated 7.8 (high) with a local attack vector, low privileges required, and no user interaction. An attacker who already has limited access and can execute code on a targeted machine can trigger the vulnerable Installer behavior to gain elevated privileges, with high impact on the confidentiality, integrity, and availability of the host. The flaw affects the listed Windows 10, Windows 11, and Windows Server versions (CISA describes the affected product simply as 'Microsoft Windows', so other versions may also be impacted). It was fixed as part of Microsoft's September 2024 Patch Tuesday, which addressed 79 flaws including four actively exploited zero-days, and Microsoft's advisories plus CISA's KEV entry (added 2024-09-10) confirm it is being exploited in the wild; no public proof-of-concept is known and ransomware association is unknown. Its EPSS score of 6.3% (93rd percentile) is unusually high for a local privilege escalation, so Windows fleets should treat this as a priority patch. Do: Apply Microsoft's September 2024 security updates (or any later cumulative update) for the affected Windows 10, Windows 11, and Windows Server versions, prioritizing servers and multi-user systems where untrusted local code runs; because this flaw is KEV-listed and actively exploited, remediation should follow CISA's vendor-instruction requirement. Given September 2024 reporting that a servicing defect left some Windows PCs unpatched despite appearing updated, verify via Windows Update history or your patch-management tooling that the cumulative update actually installed. No workaround is specified in the available data, so patching is the primary mitigation. | 7.8 group max | 6% | KEV |
| mass≈1 billion+ Windows devices (Windows Installer is a core component of every affected Windows install) | |
| CVE-2024-38226 | Actively Exploited Security Feature Bypass in Microsoft Publisher CVE-2024-38226 is a security feature bypass (protection mechanism failure, CWE-693) in Microsoft Publisher, rated 7.3 High with a local attack vector, low privileges required, and user interaction required. An attacker triggers it by convincing a user to open a maliciously crafted Publisher file, which defeats Publisher's built-in protection mechanism, allowing the attacker's content to bypass the expected security checks, with high impact rated for confidentiality, integrity, and availability. Users of Publisher as shipped in Microsoft Office 2019 and Microsoft Office Long Term Servicing Channel (LTSC) are affected. The flaw was patched in Microsoft's September 2024 Patch Tuesday, counted among the four actively exploited Microsoft zero-days that month, and CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-10, confirming exploitation in the wild; ransomware use is listed as unknown. Do: Apply the September 2024 Microsoft security updates for Office 2019/LTSC (Publisher) across all endpoints, prioritizing systems with Publisher installed, per the vendor's instructions or the CISA KEV required action. Until patched, warn users to exercise caution with .pub files from untrusted sources, since exploitation requires opening a crafted file. Confirm no Publisher clients remain on outdated builds after deployment. | 7.3 | 3% | KEV |
| massmillions of users (Publisher is bundled with enterprise perpetual-license Office 2019/LTSC suites; no precise public install counts for these channels) | |
| CVE-2024-43491 | Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, ve Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these previously mitigated vulnerabilities on Windows 10, version 1507 (Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB) systems that have installed the Windows security update released on March 12, 2024—KB5035858 (OS Build 10240.20526) or other updates released until August 2024. All later versions of Windows 10 are not impacted by this vulnerability. This servicing stack vulnerability is addressed by installing the September 2024 Servicing stack update (SSU KB5043936) AND the September 2024 Windows security update (KB5043083), in that order. Note: Windows 10, version 1507 reached the end of support (EOS) on May 9, 2017 for devices running the Pro, Home, Enterprise, Education, and Enterprise IoT editions. Only Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB editions are still under support. NVD description · AI analysis pending | 9.8 | 12% |
| — |
Full article425 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 11, 2024

Microsoft Patch Tuesday security updates for September 2024 addressed 79 flaws, including four actively exploited zero-day flaws.
Microsoft Patch Tuesday security updates for September 2024 addressed 79 vulnerabilities in Windows and Windows Components; Office and Office Components; Azure; Dynamics Business Central; SQL Server; Windows Hyper-V; Mark of the Web (MOTW); and the Remote Desktop Licensing Service.
Four of these vulnerabilities were actively exploited as zero-day vulnerabilities, one flaw is publicly known.
Seven vulnerabilities are rated as Critical, 71 as Important, and one as Moderate.
“The size of this release tracks with the volume we saw from Redmond last month, but again, it’s unusual to see such a high number of bugs under active attack.” reported ZDI. “One of these CVEs is listed as publicly known, and four others are listed as under active attack at the time of release. However, we at the ZDI think that number should be five.”
The four actively exploited zero-day vulnerabilities are:
CVE-2024-38014 – Windows Installer Elevation of Privilege Vulnerability. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
CVE-2024-38217 – Windows Mark of the Web Security Feature Bypass Vulnerability. An attacker could exploit this vulnerability by hosting a malicious file on their server and tricking a user into downloading and opening it. This file could bypass Mark of the Web (MOTW) defenses, potentially compromising security features like SmartScreen Application Reputation and Windows Attachment Services security prompts.
CVE-2024-38226 – Microsoft Publisher Security Feature Bypass Vulnerability. An attacker could bypass Office macro policies by tricking an authenticated user into downloading and opening a specially crafted file from a website. This local attack could compromise the victim’s computer through social engineering.
CVE-2024-43491 – Microsoft Windows Update Remote Code Execution Vulnerability. Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these previously mitigated vulnerabilities on Windows 10, version 1507 (Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB) systems that have installed the Windows security update released on March 12, 2024—KB5035858 (OS Build 10240.20526) or other updates released until August 2024. All later versions of Windows 10 are not impacted by this vulnerability.
The complete list of flaws fixed with Microsoft Patch Tuesday security updates for September 2024 is available here.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Microsoft Patch Tuesday)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/168279/security/microsoft-patch-tuesday-sept-2024.html