ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

September 2024 Patch Tuesday forecast: Downgrade is the new exploit

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-21302
Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability.

Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance for blocking rollback of virtualization-based security related updates and the Recommended Actions section of this CVE for guidance on how to protect your systems from this vulnerability. An elevation of privilege vulnerability exists in Windows based systems supporting Virtualization Based Security (VBS), including a subset of Azure Virtual Machine SKUS. This vulnerability enables an attacker with administrator privileges to replace current versions of Windows system files with outdated versions. By exploiting this vulnerability, an attacker could reintroduce previously mitigated vulnerabilities, circumvent some features of VBS, and exfiltrate data protected by VBS. Update: July 10, 2025 Microsoft has addressed this vulnerability for Windows 10 1507, Windows 10, version 1607, Windows 10, version 1809, and Windows Server 2016 and Windows Server 2018. This ensures that mitigations are available to protect all supported versions of Windows 10 and Windows 11 from this vulnerability. See the available mitigations and deployment guidelines described in KB5042562: Guidance for blocking rollback of virtualization-based security related updates. Update: August 13, 2024 Microsoft has released the August 2024 security updates that include an opt-in revocation policy mitigation to address this vulnerability. Customers running affected versions of Windows are encouraged to review KB5042562: Guidance for blocking rollback of virtualization-based security related updates to assess if this opt-in policy meets the needs of their environment before implementing this mitigation. There are risks associated with this mitigation that should be understood prior to applying it to your systems. Detailed information about these risks is also available in KB5042562. Details: A security researcher informed Microsoft of an elevation of privilege vulnerability in Windows 10, Windows 11, Windows Server 2016, and higher based systems including Azure Virtual Machines (VM) that support VBS. For more information on Windows versions and VM SKUs supporting VBS, reference: Virtualization-based Security (VBS) | Microsoft Learn. The vulnerability enables an attacker with administrator privileges on the target system to replace current Windows system files with outdated versions. Successful... See more at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21302

NVD description · AI analysis pending
6.72%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2024-38202
Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privilege

Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some features of Virtualization Based Security (VBS). However, an attacker attempting to exploit this vulnerability requires additional interaction by a privileged user to be successful. Microsoft has developed a security update to mitigate this threat which was made available October 08, 2024 and is provided in the Security Updates table of this CVE for customers to download. Note: Depending on your version of Windows, additional steps may be required to update Windows Recovery Environment (WinRE) to be protected from this vulnerability. Please refer to the FAQ section for more information. Guidance for customers who cannot immediately implement the update is provided in the Recommended Actions section of this CVE to help reduce the risks associated with this vulnerability and to protect their systems. If there are any further updates regarding mitigations for this vulnerability, this CVE will be updated and customers will be notified. We highly encourage customers to subscribe to Security Update Guide notifications to receive an alert if an update occurs. Details A security researcher informed Microsoft of an elevation of privilege vulnerability in Windows Update potentially enabling an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some features of VBS. For exploitation to succeed, an attacker must trick or convince an Administrator or a user with delegated permissions into performing a system restore which inadvertently triggers the vulnerability. Microsoft has developed a security update to mitigate this threat which was made available October 08, 2024 and is provided in the Security Updates table of this CVE for customers to download. Note: Depending on your version of Windows, additional steps may be required to update Windows Recovery Environment (WinRE) to be protected from this vulnerability. Please refer to the FAQ section for more information. Guidance for customers who cannot immediately implement the update is provided in the Recommended Actions section of this CVE to help reduce the risks associated with this vulnerability and to protect their systems. If there are any further... See more at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38202

NVD description · AI analysis pending
7.32%
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • +1 more
Full article711 words · extracted from helpnetsecurity.com · click to collapse

September 2024 Patch Tuesday is now live:
Microsoft fixes 4 exploited zero-days and a code defect that nixed earlier security fixes

I asked for a calm August 2024 Patch Tuesday in last month’s forecast article and that came to pass.

September 2024 Patch Tuesday forecast

The updates released were limited to the regular operating systems and all forms of Office applications. Six zero-day vulnerabilities were announced, with five in the operating systems and one in the Office applications. There were 63 CVEs addressed in the Windows 10 operating systems and associated servers and 55 CVEs addressed in Windows 11. Overall, it was a straightforward set of updates to deploy, but several issues were identified over the past month, which Microsoft has acknowledged and is working on. They should be addressed in the upcoming September releases.

Windows Downdate downgrade attack

The Windows Downdate downgrade attack deserves some attention this month. At Black Hat USA 2024, Alon Leviev revealed an exploit using CVE-2024-38202 and CVE-2024-21302 which takes over Windows Update and then downgrades the operating system to a previous version. This exposes all the vulnerabilities that had been reported and fixed in newer versions.

This could expose a system to hundreds of now ‘zero-day’ vulnerabilities, yet the system appears to be fully patched. Microsoft addressed CVE-2024-21302 with the August 2024 Patch Tuesday updates, but they could only provide mitigation guidance for CVE-2024-38202 in a security advisory. We’ll see if there is a KB that can give a patch solution for this CVE this month.

Microsoft confirmed several reported issues throughout the month about the August updates. They added a comment to KB5041578 for Server 2019 noting that after installing the August update you can experience slowdowns, unresponsiveness, and high CPU usage.

The temporary workaround for this issue is to use the Known Issue Rollback (KIR) policy and that they are working on a fix. Microsoft also acknowledges that following the August updates you may “face issues with booting Linux if you have enabled the dual-boot setup for Windows and Linux in your device.” This comment was added to KBs for Microsoft Servers 2016, 2019, and 2022. Again, there is a workaround, and they are working on a resolution. These issues may be resolved with the September updates.

Final Windows updates

There are a few items of general interest to note. Keep in mind, the final updates for Windows 11, 21H2 Enterprise and Education versions, and Windows 11 22H2 Home and Professional are coming in October. You should be planning to upgrade to a newer version to ensure you have security updates available after October. For those of you still dealing with the Windows Recovery Environment (WinRE) partition error with not enough space, Microsoft has updated the January patches to not install if the partition is too small thus avoiding the cryptic error message.

Now per Microsoft, ‘The WinRE partition requires 250 megabytes of free space. Devices which do not have sufficient free space will need to increase the size of the partition via manual action.’ So you will need to manually update the partition size or use the recommended script prior to installing these ‘new’ updates.

September 2024 Patch Tuesday forecast

  • Microsoft will release the standard operating system, Office, Sharepoint, and perhaps a .NET framework or SQL update this month.
  • Adobe released a major security update for Acrobat and Reader last patch Tuesday, so I don’t expect any updates this month.
  • Apple released OS updates the first week of August but did not include any CVE information. While Apple doesn’t generally release on Patch Tuesday, the last security update was in July so we are due for another update soon.
  • Google Chrome provided a fix for their 10th zero-day exploit last week. While we may not see another zero-day exploit, expect Google to have an update next week as usual.
  • Mozilla released security updates for Firefox 130, Firefox ESR 115 and 128 earlier this week. If you are a Thunderbird user, I’d expect another update any day now.

Summer doesn’t officially end until later this month, but for many of us we associate the end of summer with the new school year. The lazy days of summer may be over (we did have an easy August Patch Tuesday), but let’s hope they last one more month!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/09/06/september-2024-patch-tuesday-forecast/