Threat Advisory

Critical RCE and Privilege Escalation Vulnerabilities in Microsoft Products

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Several critical and important vulnerabilities have been identified across various Microsoft products, including the TCP/IP stack, Microsoft Project, Windows Kernel, and Office. These vulnerabilities pose significant risks, such as remote code execution, privilege escalation, and security feature bypass, and can be exploited by attackers to compromise system integrity and access sensitive data. Immediate action, including applying available patches and mitigating measures, is strongly advised to safeguard against potential exploitation.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Several critical and important vulnerabilities have been identified across various Microsoft products, including the TCP/IP stack, Microsoft Project, Windows Kernel, and Office. These vulnerabilities pose significant risks, such as remote code execution, privilege escalation, and security feature bypass, and can be exploited by attackers to compromise system integrity and access sensitive data. Immediate action, including applying available patches and mitigating measures, is strongly advised to safeguard against potential exploitation.[emaillocker id="1283"]

 

  • CVE-2024-38063-TCP/IP Remote Code Execution Vulnerability: We strongly recommend disabling IPv6 on systems where it's not needed and applying the August 2024 Patch Tuesday updates immediately to mitigate the risk of remote code execution from unauthenticated attackers exploiting this critical vulnerability.
  • CVE-2024-38189-Microsoft Project Remote Code Execution Vulnerability: Users should ensure that Microsoft Project is updated with the latest security patches to prevent the exploitation of this vulnerability. Avoid opening untrusted project files and consider restricting access to potentially vulnerable systems.
  • CVE-2024-38178-Scripting Engine Memory Corruption Vulnerability: To mitigate the risks associated with this vulnerability, apply the latest security updates provided by Microsoft. Additionally, exercise caution when running scripts from untrusted sources.
  • CVE-2024-38193-Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability: Apply the security updates immediately to prevent attackers from leveraging this vulnerability to gain unauthorized control over systems. Regularly review and manage user privileges to minimize potential damage from privilege escalation.
  • CVE-2024-38106-Windows Kernel Elevation of Privilege Vulnerability: Patch all affected systems promptly to close off this vulnerability. Consider using tools to monitor and restrict kernel-level access to reduce the impact of any potential exploits.
  • CVE-2024-38107-Windows Power Dependency Coordinator Elevation of Privilege Vulnerability: It is essential to apply the recommended patches to protect against privilege escalation attacks. Regularly audit and control administrative privileges across the network.
  • CVE-2024-38213-Windows Mark of the Web Security Feature Bypass Vulnerability: To address this security feature bypass vulnerability, install the latest updates. Additionally, educate users on the dangers of opening files from unknown or untrusted sources, even if security warnings are not triggered.
  • CVE-2024-38202-Windows Update Stack Elevation of Privilege Vulnerability: This vulnerability is rooted in the Windows Backup component and allows an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or bypass certain features of Virtualization Based Security (VBS). The attacker needs to convince an Administrator or a user with delegated permissions to perform a system restore, which inadvertently triggers the flaw, potentially compromising the system's security posture.
  • CVE-2024-21302-Windows Secure Kernel Mode Elevation of Privilege Vulnerability: This vulnerability involves privilege escalation in systems that support VBS, enabling an adversary to replace current versions of Windows system files with outdated versions. The consequences include the potential reintroduction of previously addressed security flaws, bypassing of VBS features, and exposure of sensitive data protected by VBS, leading to significant security risks on the affected systems.
  • CVE-2024-38200: This spoofing vulnerability in Microsoft Office, including Office 2016, Office 2019, Office LTSC 2021, and Microsoft 365 Apps for Enterprise, across both 32-bit and 64-bit systems with a CVSS score of 7.5, could lead to the unauthorized disclosure of sensitive information. In a web-based attack scenario, an attacker could exploit this flaw by convincing a user to visit a malicious website and open a specially crafted file, potentially resulting in sensitive data exposure.

 

The disclosed vulnerabilities, including a critical remote code execution flaw in the TCP/IP stack and multiple privilege escalation issues, highlight the importance of prompt patching and security updates. Failure to address these issues could lead to severe security breaches, allowing attackers to execute arbitrary code, elevate privileges, and bypass critical security features. Organizations and users are urged to implement the recommended patches and security measures to protect their systems from these threats.

RECOMMENDATION:

We strongly recommend you update Microsoft products as addressed in this security update:

REFERENCES:

The following reports contain further technical details:

https://thehackernews.com/2024/08/microsoft-warns-of-unpatched-office.html
https://thehackernews.com/2024/08/windows-downgrade-attack-risks-exposing.html
https://securityaffairs.com/167117/hacking/windows-rce-tcp-ip.html
https://cybersecuritynews.com/microsoft-office-spoofing-vulnerability/
https://www.bleepingcomputer.com/news/security/microsoft-discloses-unpatched-office-flaw-that-exposes-ntlm-hashes/

 

 

[/emaillocker]
crossmenu