Microsoft Patch Tuesday – May 2024

Microsoft Patch Tuesday – May 2024


Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2024-30051 with a CVSSv3 score of 7.8, is an EoP vulnerability in the DWM Core Library in Microsoft Windows. It was exploited in the wild as a zero-day and was publicly disclosed prior to a patch being available. A local attacker with a presence on a vulnerable system could exploit this vulnerability to gain SYSTEM privileges. This vulnerability was discovered by researchers from Google Threat Analysis Group, Google Mandiant and Kaspersky.

Microsoft also patched two other EoP vulnerabilities in the DWM Core Library (CVE-2024-30032, CVE-2024-30035) and an information disclosure vulnerability (CVE-2024-30008).

Windows MSHTML Platform Security Feature Bypass Vulnerability

CVE-2024-30040 with a CVSSv3 score of 8.8 is a security feature bypass vulnerability in the MSHTML (Trident) engine in Microsoft Windows that was exploited in the wild as a zero-day. An attacker could exploit this vulnerability by using social engineering tactics via email, social media, or instant messaging to convince a target user to open a specially crafted document. Once exploited, an attacker could execute code on the target system.

Advertisements

Visual Studio Denial of Service Vulnerability

CVE-2024-30046  with a CVSSv3 score of 5.9, is a denial of service (DoS) vulnerability affecting multiple versions of Microsoft Visual Studio 2022. It is rated as “Exploitation Less Likely” according to Microsoft’s Exploitability Index and its Attack Complexity rating is listed as High. This is because an attacker would need to “invest time in repeated exploitation attempts” through the sending of “constant or intermittent data” to a targeted system. DoS attacks often require a steady stream of requests to overwhelm a target system, so these ratings are expected.

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVE-2024-30044 with a CVSSv3 score of 8.8 is a RCE vulnerability in Microsoft SharePoint Server. This vulnerability is rated as Exploitation More Likely. The exploitation of this flaw requires an attacker authenticated to a vulnerable SharePoint Server with Site Owner permissions to perform two steps:

The attacker must upload a specially crafted file to the vulnerable SharePoint Server

  • The attacker then send specially crafted API requests to the SharePoint Server to “trigger deserialization of file’s parameters.” Successful exploitation would result in remote code execution “in the context of the SharePoint Server.”
Advertisements

Other Notable Vulnerabilities

CVE-2024-29996 and CVE-2024-30025 are elevation of privilege vulnerabilities in the Windows Common Log File System Driver. On successful exploitation, an attacker could gain SYSTEM privileges.

CVE-2024-30050 is a security feature bypass vulnerability in Windows Mark of the Web. An attacker might host a file on a server and convince a targeted user to download and open the file to exploit this vulnerability. An attacker may alter the functionality of the Mark of the Web on successful exploitation.

CVE-2024-30038 is an elevation of privilege vulnerability in Win32k. Successful exploitation of the vulnerability may allow a local, authenticated attacker to gain elevated local system or administrator privileges.

CVE-2024-30049 is an elevation of privilege vulnerability in the Windows Win32 Kernel Subsystem. On successful exploitation, an attacker could gain SYSTEM privileges.

Summary

CVE IDVulnerability TitleSeverity
CVE-2024-30044Microsoft SharePoint Server Remote Code Execution VulnerabilityCritical
CVE-2024-30045.NET and Visual Studio Remote Code Execution VulnerabilityImportant
CVE-2024-30053Azure Migrate Cross-Site Scripting VulnerabilityImportant
CVE-2024-30041Microsoft Bing Search Spoofing VulnerabilityImportant
CVE-2024-30007Microsoft Brokering File System Elevation of Privilege VulnerabilityImportant
CVE-2024-30048Dynamics 365 Customer Insights Spoofing VulnerabilityImportant
CVE-2024-30047Dynamics 365 Customer Insights Spoofing VulnerabilityImportant
CVE-2024-30059Microsoft Intune for Android Mobile Application Management Tampering VulnerabilityImportant
CVE-2024-30042Microsoft Excel Remote Code Execution VulnerabilityImportant
CVE-2024-30043Microsoft SharePoint Server Information Disclosure VulnerabilityImportant
CVE-2024-30006Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution VulnerabilityImportant
CVE-2024-29994Microsoft Windows SCSI Class System File Elevation of Privilege VulnerabilityImportant
CVE-2024-30033Windows Search Service Elevation of Privilege VulnerabilityImportant
CVE-2024-30054Microsoft Power BI Client JavaScript SDK Information Disclosure VulnerabilityImportant
CVE-2024-30046Visual Studio Denial of Service VulnerabilityImportant
CVE-2024-32004GitHub: CVE-2024-32004 Remote Code Execution while cloning special-crafted local repositoriesImportant
CVE-2024-32002CVE-2024-32002 Recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code ExecutionImportant
CVE-2024-30034Windows Cloud Files Mini Filter Driver Information Disclosure VulnerabilityImportant
CVE-2024-30031Windows CNG Key Isolation Service Elevation of Privilege VulnerabilityImportant
CVE-2024-29996Windows Common Log File System Driver Elevation of Privilege VulnerabilityImportant
CVE-2024-30037Windows Common Log File System Driver Elevation of Privilege VulnerabilityImportant
CVE-2024-30025Windows Common Log File System Driver Elevation of Privilege VulnerabilityImportant
CVE-2024-30020Windows Cryptographic Services Remote Code Execution VulnerabilityImportant
CVE-2024-30016Windows Cryptographic Services Information Disclosure VulnerabilityImportant
CVE-2024-30036Windows Deployment Services Information Disclosure VulnerabilityImportant
CVE-2024-30019DHCP Server Service Denial of Service VulnerabilityImportant
CVE-2024-30008Windows DWM Core Library Information Disclosure VulnerabilityImportant
CVE-2024-30051Windows DWM Core Library Elevation of Privilege VulnerabilityImportant
CVE-2024-30035Windows DWM Core Library Elevation of Privilege VulnerabilityImportant
CVE-2024-30032Windows DWM Core Library Elevation of Privilege VulnerabilityImportant
CVE-2024-30011Windows Hyper-V Denial of Service VulnerabilityImportant
CVE-2024-30017Windows Hyper-V Remote Code Execution VulnerabilityImportant
CVE-2024-30010Windows Hyper-V Remote Code Execution VulnerabilityImportant
CVE-2024-30018Windows Kernel Elevation of Privilege VulnerabilityImportant
CVE-2024-30002Windows Mobile Broadband Driver Remote Code Execution VulnerabilityImportant
CVE-2024-29997Windows Mobile Broadband Driver Remote Code Execution VulnerabilityImportant
CVE-2024-30003Windows Mobile Broadband Driver Remote Code Execution VulnerabilityImportant
CVE-2024-30012Windows Mobile Broadband Driver Remote Code Execution VulnerabilityImportant
CVE-2024-29999Windows Mobile Broadband Driver Remote Code Execution VulnerabilityImportant
CVE-2024-29998Windows Mobile Broadband Driver Remote Code Execution VulnerabilityImportant
CVE-2024-30000Windows Mobile Broadband Driver Remote Code Execution VulnerabilityImportant
CVE-2024-30005Windows Mobile Broadband Driver Remote Code Execution VulnerabilityImportant
CVE-2024-30004Windows Mobile Broadband Driver Remote Code Execution VulnerabilityImportant
CVE-2024-30021Windows Mobile Broadband Driver Remote Code Execution VulnerabilityImportant
CVE-2024-30001Windows Mobile Broadband Driver Remote Code Execution VulnerabilityImportant
CVE-2024-30040Windows MSHTML Platform Security Feature Bypass VulnerabilityImportant
CVE-2024-30027NTFS Elevation of Privilege VulnerabilityImportant
CVE-2024-30039Windows Remote Access Connection Manager Information Disclosure VulnerabilityImportant
CVE-2024-30009Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportant
CVE-2024-30024Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportant
CVE-2024-30015Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportant
CVE-2024-30029Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportant
CVE-2024-30023Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportant
CVE-2024-30014Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportant
CVE-2024-30022Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportant
CVE-2024-26238Microsoft PLUGScheduler Scheduled Task Elevation of Privilege VulnerabilityImportant
CVE-2024-30030Win32k Elevation of Privilege VulnerabilityImportant
CVE-2024-30038Win32k Elevation of Privilege VulnerabilityImportant
CVE-2024-30049Windows Win32 Kernel Subsystem Elevation of Privilege VulnerabilityImportant
CVE-2024-30028Win32k Elevation of Privilege VulnerabilityImportant

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.