Microsoft Patch Tuesday – April 2024

Microsoft Patch Tuesday – April 2024


Microsoft patched 149 CVEs in its April 2024 Patch Tuesday release, with three rated critical, 142 rated as important, and two rated as moderate. 2 of the Zeroday vulnerabilities are fixed in this release.

  • 31 Elevation of Privilege Vulnerabilities
  • 28 Security Feature Bypass Vulnerabilities
  • 67 Remote Code Execution Vulnerabilities
  • 13 Information Disclosure Vulnerabilities
  • 7 Denial of Service Vulnerabilities
  • 3 Spoofing Vulnerabilities
Advertisements

SmartScreen Prompt Security Feature Bypass Vulnerability

CVE-2024-29988 with a CVSSv3 score of 8.8, is a security feature bypass vulnerability in Microsoft Defender SmartScreen. An attacker could exploit this vulnerability by convincing a target to open a specially crafted file using social engineering tactics such as an external link or malicious attachment sent over email, instant messages, or social media.

This flaw was reported to Microsoft by some of the same researchers that disclosed CVE-2024-21412, an Internet Shortcut Files security feature bypass that was associated with a DarkGate campaign using fake installer files impersonating Apple iTunes, Notion, NVIDIA, and others.

CVE-2024-29988 is a bypass for the CVE-2024-21412 flaw and was reported by Peter Girnus of Trend Micro’s Zero Day Initiative and Google’s Threat Analysis Group Dmitrij Lenz and Vlad Stolyarov. CVE-2024-21412 was itself a bypass for another Defender SmartScreen vulnerability tracked as CVE-2023-36025, patched during the November 2023 Patch Tuesday and exploited as a zero-day to drop Phemedrone malware.

Proxy Driver Spoofing Vulnerability

CVE-2024-26234 with a CVSSv3 score of 8.8, described as a proxy driver spoofing vulnerability, was issued to track a malicious driver signed using a valid Microsoft Hardware Publisher Certificate that was found by Sophos X-Ops in December 2023 and reported by team lead Christopher Budd.

This malicious file was labeled as “Catalog Authentication Client Service” by “Catalog Thales,” likely an attempt to impersonate Thales Group. However, further investigation revealed that it was previously bundled with a marketing software called LaiXi Android Screen Mirroring.

Advertisements

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

CVE-2024-29990 with a CVSSv3 score of 9.0, is an EoP vulnerability in the Azure Kubernetes Service Confidential Containers (AKSCC). Exploitation of this flaw hinges on the preparation of a target environment by an attacker. Successful exploitation would enable an attacker to “steal credentials and affect resources beyond the security scope managed by AKSCC.” This includes taking over both “confidential guests and containers beyond the network stack it might be bound to.”

Microsoft ODBC Driver, WDAC OLE DB Driver and OLE DB Driver for SQL Server Remote Code Execution Vulnerability

There are  41 CVEs affecting multiple drivers for SQL Server, the Open Database Connectivity (ODBC) driver, WDAC OLE DB Driver and OLE DB driver. All were rated as Exploitation Less Likely according to the Microsoft Exploitability Index, with none being publicly disclosed or exploited in the wild. A full list of the CVEs is included in the table below.

Secure Boot Security Feature Bypass Vulnerability

Microsoft patched 24 CVEs in Windows Secure Boot during this month release. All are rated as Exploitation Less Likely. A full list of the CVEs is included in the table below.

Advertisements

Patch Tuesday Summary

CVE TitleCVE IDSeverity
Microsoft Defender for IoT Remote Code Execution VulnerabilityCVE-2024-29053Critical
Microsoft Defender for IoT Remote Code Execution VulnerabilityCVE-2024-21323Critical
Microsoft Defender for IoT Remote Code Execution VulnerabilityCVE-2024-21322Critical
.NET, .NET Framework, and Visual Studio Remote Code Execution VulnerabilityCVE-2024-21409Important
Azure CycleCloud Elevation of Privilege VulnerabilityCVE-2024-29993Important
Azure AI Search Information Disclosure VulnerabilityCVE-2024-29063Important
Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege VulnerabilityCVE-2024-28917Important
Azure Compute Gallery Elevation of Privilege VulnerabilityCVE-2024-21424Important
Azure Migrate Remote Code Execution VulnerabilityCVE-2024-26193Important
Azure Monitor Agent Elevation of Privilege VulnerabilityCVE-2024-29989Important
Intel: CVE-2024-2201 Branch History InjectionCVE-2024-2201Important
SmartScreen Prompt Security Feature Bypass VulnerabilityCVE-2024-29988Important
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege VulnerabilityCVE-2024-29990Important
Microsoft Brokering File System Elevation of Privilege VulnerabilityCVE-2024-28905Important
Microsoft Brokering File System Elevation of Privilege VulnerabilityCVE-2024-28907Important
Microsoft Brokering File System Elevation of Privilege VulnerabilityCVE-2024-26213Important
Microsoft Brokering File System Elevation of Privilege VulnerabilityCVE-2024-28904Important
Microsoft Defender for IoT Elevation of Privilege VulnerabilityCVE-2024-29055Important
Microsoft Defender for IoT Elevation of Privilege VulnerabilityCVE-2024-29054Important
Microsoft Defender for IoT Elevation of Privilege VulnerabilityCVE-2024-21324Important
Microsoft Install Service Elevation of Privilege VulnerabilityCVE-2024-26158Important
Microsoft Excel Remote Code Execution VulnerabilityCVE-2024-26257Important
Outlook for Windows Spoofing VulnerabilityCVE-2024-20670Important
Microsoft SharePoint Server Spoofing VulnerabilityCVE-2024-26251Important
Microsoft WDAC SQL Server ODBC Driver Remote Code Execution VulnerabilityCVE-2024-26214Important
Microsoft WDAC OLE DB Provider for SQL Server Remote Code Execution VulnerabilityCVE-2024-26244Important
Microsoft WDAC OLE DB Provider for SQL Server Remote Code Execution VulnerabilityCVE-2024-26210Important
Windows DNS Server Remote Code Execution VulnerabilityCVE-2024-26233Important
Windows DNS Server Remote Code Execution VulnerabilityCVE-2024-26231Important
Windows DNS Server Remote Code Execution VulnerabilityCVE-2024-26227Important
Windows DNS Server Remote Code Execution VulnerabilityCVE-2024-26223Important
Windows DNS Server Remote Code Execution VulnerabilityCVE-2024-26221Important
Windows DNS Server Remote Code Execution VulnerabilityCVE-2024-26224Important
Windows DNS Server Remote Code Execution VulnerabilityCVE-2024-26222Important
Windows Hyper-V Denial of Service VulnerabilityCVE-2024-29064Important
Microsoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28937Important
Microsoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28938Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-29044Important
Microsoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28935Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28940Important
Microsoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28943Important
Microsoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28941Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28910Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28944Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28908Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28909Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-29985Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28906Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28926Important
Microsoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28933Important
Microsoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28934Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28927Important
Microsoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28930Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-29046Important
Microsoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28932Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-29047Important
Microsoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28931Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-29984Important
Microsoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28929Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28939Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28942Important
Microsoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-29043Important
Microsoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28936Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-29045Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28915Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28913Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28945Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-29048Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28912Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28914Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-29983Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-28911Important
Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityCVE-2024-29982Important
Windows Authentication Elevation of Privilege VulnerabilityCVE-2024-29056Important
Windows Authentication Elevation of Privilege VulnerabilityCVE-2024-21447Important
BitLocker Security Feature Bypass VulnerabilityCVE-2024-20665Important
libarchive Remote Code Execution VulnerabilityCVE-2024-26256Important
Windows Cryptographic Services Security Feature Bypass VulnerabilityCVE-2024-26228Important
Windows Cryptographic Services Remote Code Execution VulnerabilityCVE-2024-29050Important
Windows Defender Credential Guard Elevation of Privilege VulnerabilityCVE-2024-26237Important
DHCP Server Service Denial of Service VulnerabilityCVE-2024-26212Important
DHCP Server Service Denial of Service VulnerabilityCVE-2024-26215Important
DHCP Server Service Remote Code Execution VulnerabilityCVE-2024-26195Important
DHCP Server Service Remote Code Execution VulnerabilityCVE-2024-26202Important
Windows Distributed File System (DFS) Remote Code Execution VulnerabilityCVE-2024-29066Important
Windows Distributed File System (DFS) Information Disclosure VulnerabilityCVE-2024-26226Important
Windows DWM Core Library Information Disclosure VulnerabilityCVE-2024-26172Important
Windows File Server Resource Management Service Elevation of Privilege VulnerabilityCVE-2024-26216Important
HTTP.sys Denial of Service VulnerabilityCVE-2024-26219Important
Windows rndismp6.sys Remote Code Execution VulnerabilityCVE-2024-26253Important
Windows rndismp6.sys Remote Code Execution VulnerabilityCVE-2024-26252Important
Windows Kerberos Denial of Service VulnerabilityCVE-2024-26183Important
Windows Kerberos Elevation of Privilege VulnerabilityCVE-2024-26248Important
Windows Kernel Elevation of Privilege VulnerabilityCVE-2024-20693Important
Windows SMB Elevation of Privilege VulnerabilityCVE-2024-26245Important
Windows CSC Service Elevation of Privilege VulnerabilityCVE-2024-26229Important
Windows Kernel Elevation of Privilege VulnerabilityCVE-2024-26218Important
Microsoft Local Security Authority Subsystem Service Information Disclosure VulnerabilityCVE-2024-26209Important
Microsoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityCVE-2024-26232Important
Microsoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityCVE-2024-26208Important
Windows Mobile Hotspot Information Disclosure VulnerabilityCVE-2024-26220Important
Proxy Driver Spoofing VulnerabilityCVE-2024-26234Important
Windows Remote Access Connection Manager Information Disclosure VulnerabilityCVE-2024-28902Important
Windows Remote Access Connection Manager Information Disclosure VulnerabilityCVE-2024-28900Important
Windows Remote Access Connection Manager Information Disclosure VulnerabilityCVE-2024-28901Important
Windows Remote Access Connection Manager Information Disclosure VulnerabilityCVE-2024-26255Important
Windows Telephony Server Elevation of Privilege VulnerabilityCVE-2024-26230Important
Windows Telephony Server Elevation of Privilege VulnerabilityCVE-2024-26239Important
Windows Remote Access Connection Manager Information Disclosure VulnerabilityCVE-2024-26207Important
Windows Remote Access Connection Manager Information Disclosure VulnerabilityCVE-2024-26217Important
Windows Remote Access Connection Manager Elevation of Privilege VulnerabilityCVE-2024-26211Important
Remote Procedure Call Runtime Remote Code Execution VulnerabilityCVE-2024-20678Important
Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVE-2024-26200Important
Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVE-2024-26179Important
Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVE-2024-26205Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-29061Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-28921Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-20689Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-26250Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-28922Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-29062Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-20669Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-28898Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-20688Important
Lenovo: CVE-2024-23593 Zero Out Boot Manager and drop to UEFI ShellCVE-2024-23593Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-28896Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-28919Important
Lenovo: CVE-2024-23594 Stack Buffer Overflow in LenovoBT.efiCVE-2024-23594Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-28923Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-28903Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-26189Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-26240Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-28924Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-28897Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-28925Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-26175Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-28920Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-26194Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-26180Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-26171Important
Secure Boot Security Feature Bypass VulnerabilityCVE-2024-26168Important
Windows Storage Elevation of Privilege VulnerabilityCVE-2024-29052Important
Windows Telephony Server Elevation of Privilege VulnerabilityCVE-2024-26242Important
Windows Update Stack Elevation of Privilege VulnerabilityCVE-2024-26236Important
Windows Update Stack Elevation of Privilege VulnerabilityCVE-2024-26235Important
Windows USB Print Driver Elevation of Privilege VulnerabilityCVE-2024-26243Important
Microsoft Virtual Machine Bus (VMBus) Denial of Service VulnerabilityCVE-2024-26254Important
Win32k Elevation of Privilege VulnerabilityCVE-2024-26241Important
Azure Private 5G Core Denial of Service VulnerabilityCVE-2024-20685Moderate
Azure Identity Library for .NET Information Disclosure VulnerabilityCVE-2024-29992Moderate

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.