Threat Advisory

Microsoft Addresses Multiple Active Exploits and Critical Vulnerability in Windows Systems

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Microsoft's security update addresses four actively exploited vulnerabilities, including two zero-days in Microsoft Publisher and Windows Installer. CVE-2024-38226 allows attackers to bypass macro security features in Microsoft Publisher, while CVE-2024-38014 enables privilege escalation to SYSTEM-level in Windows Installer. Additionally, CVE-2024-43491, a high-severity remote code execution vulnerability in Windows Update, and several remote code execution issues in SharePoint Server CVE-2024-38018, CVE-2024-38227, CVE-2024-38228, CVE-2024-43464 are also considered likely to be exploited. Microsoft has also fixed CVE-2024-38217, a public vulnerability in Windows Mark of the Web, and CVE-2024-38257, an information disclosure issue in the AllJoyn API. It should apply the updates to mitigate these risks.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Microsoft's security update addresses four actively exploited vulnerabilities, including two zero-days in Microsoft Publisher and Windows Installer. CVE-2024-38226 allows attackers to bypass macro security features in Microsoft Publisher, while CVE-2024-38014 enables privilege escalation to SYSTEM-level in Windows Installer. Additionally, CVE-2024-43491, a high-severity remote code execution vulnerability in Windows Update, and several remote code execution issues in SharePoint Server CVE-2024-38018, CVE-2024-38227, CVE-2024-38228, CVE-2024-43464 are also considered likely to be exploited. Microsoft has also fixed CVE-2024-38217, a public vulnerability in Windows Mark of the Web, and CVE-2024-38257, an information disclosure issue in the AllJoyn API. It should apply the updates to mitigate these risks.[emaillocker id="1283"]

 

  • CVE-2024-38226: This vulnerability is a security feature bypass in Microsoft Publisher, allowing an attacker to circumvent default macro policies designed to block untrusted files. Exploiting this flaw enables an attacker to trick users into opening malicious files containing harmful macros. These macros can bypass standard protections and potentially launch local attacks on the victim's machine. Default macro blocking in Office software aims to prevent such exploitation.

 

  • CVE-2024-38014: This issue affects Windows Installer and allows an adversary to gain SYSTEM-level privileges. It impacts Windows 11, as well as older versions of Windows 10 and 11. Exploiting this vulnerability could allow an attacker to execute commands with elevated privileges, potentially compromising the entire system.

 

  • CVE-2024-38217: This vulnerability exists in Windows Mark of the Web. It could enable an adversary to bypass usual MOTW detection techniques. The MOTW feature is intended to alert users about files downloaded from the internet and apply additional security controls. This flaw could allow malicious files to evade these protections, potentially leading to security breaches.

 

  • CVE-2024-38257: This disclosure vulnerability in the AllJoyn API can allow to access uninitialized memory. Although considered “less likely” to be exploited, this issue does not require user interaction or privileges. It could potentially expose sensitive information if exploited, but the likelihood of such exploitation is deemed lower.

 

  • CVE-2024-43491: This high-severity vulnerability in Windows Update is classified, It is a remote code execution issue, which means it could allow an attacker to execute arbitrary code on the victim’s system remotely. This vulnerability is considered “more likely” to be exploited, though Microsoft has provided few details on the nature of this vulnerability.

 

  • CVE-2024-38018: This remote code execution vulnerability in SharePoint Server allows an attacker with Site Member permissions to inject and execute arbitrary code. It is considered “more likely” to be exploited. Exploiting this vulnerability requires only Site Member permissions, which are easier to obtain compared to higher-level permissions.

 

  • CVE-2024-38227: This SharePoint Server vulnerability also allows remote code execution but requires an authenticated attacker to have Site Owner permissions to inject and execute code. It is one of the four vulnerabilities in SharePoint Server considered “more likely” to be exploited. Properly managing and monitoring Site Owner permissions is crucial to mitigating the risk of such attacks.

 

  • CVE-2024-38228: This vulnerability in SharePoint Server permits remote code execution but requires Site Owner permissions for exploitation. This, along with others in this category, poses significant risks if exploited due to the elevated permissions required. It highlights the need for stringent access controls to mitigate potential attacks.

 

  • CVE-2024-43464: This is another remote code execution vulnerability in SharePoint Server. It allows an attacker with Site Owner permissions to execute arbitrary code. It is considered “more likely” to be exploited due to the nature of the flaw and the permissions required for successful exploitation. Ensuring that only trusted individuals have Site Owner access can help reduce the risk of exploitation.

RECOMMENDATION:

We strongly recommend applying an update for Microsoft AllJoyn API Information Disclosure Vulnerability

We strongly recommend applying an update for Microsoft SharePoint Server Remote Code Execution Vulnerability

We strongly recommend applying an update for Microsoft SharePoint Server Remote Code Execution Vulnerability

We strongly recommend applying an update for Microsoft SharePoint Server Remote Code Execution Vulnerability

We strongly recommend applying an update for Microsoft SharePoint Server Remote Code Execution Vulnerability

REFERENCES:

The following reports contain further technical details:
https://blog.talosintelligence.com/microsoft-patch-tuesday-september-2024/

[/emaillocker]
crossmenu