
Microsoft addresses 138 CVEs in its July 2024 Patch Tuesday release, with five critical vulnerabilities and three zero-day vulnerabilities, two of which were exploited in the wild.
Windows Hyper-V Elevation of Privilege Vulnerability
The vulnerability tracked as CVE-2024-38080 with a CVSSv3 score of 7.8 is an EoP vulnerability in Microsoft Windows Hyper-V virtualization product. A local, authenticated attacker could exploit this vulnerability to elevate to SYSTEM privileges.
This vulnerability was exploited in the wild as a zero-day. No further details have been shared about the in-the-wild exploitation. There have been 44 vulnerabilities in Windows Hyper-V that have been patched since 2022. This is the first Hyper-V vulnerability that has been exploited in the wild as a zero-day.
Windows MSHTML Platform Spoofing Vulnerability
The vulnerability tracked as CVE-2024-38112 with a CVSSv3 score of 7.5 is a spoofing vulnerability in Windows MSHTML. An unauthenticated, remote attacker could exploit this vulnerability by convincing a potential target to open a malicious file. Microsoft notes that to successfully exploit this flaw, an attacker would also need to take “additional actions” to “prepare the target environment.”
This vulnerability was exploited in the wild as a zero-day. No further details about in-the-wild exploitation were available.
.NET and Visual Studio Remote Code Execution Vulnerability
The vulnerability tracked as CVE-2024-35264 with a CVSSv3 score of 8.1, is a RCE vulnerability affecting.NET and Visual Studio. It is the third Microsoft zero-day vulnerability patched this month. While it was not exploited in the wild, details were made public prior to the release of a patch. According to the advisory, exploitation requires an attacker to win a race condition and the exploitability reflects this as it is rated as “Exploitation Less Likely.”
Windows Imaging Component Remote Code Execution Vulnerability
The vulnerability tracked as CVE-2024-38060 with a CVSSv3 score of 8.8 is a RCE vulnerability affecting the Windows Imaging Component, a framework used for processing images. Microsoft rates this vulnerability as “Exploitation More Likely”. Exploitation of this flaw requires an attacker to be authenticated and utilize this access to upload a malicious Tag Image File Format (TIFF) file, an image type used for graphics.
Windows Win32k Elevation of Privilege Vulnerability
The vulnerability tracked as CVE-2024-38059 and CVE-2024-38066 with both assigned CVSSv3 scores of 7.8, are EoP vulnerabilities affecting Windows Win32k, a core kernel-side driver used in Windows. An attacker could exploit these vulnerabilities as part of post-compromise activity to elevate privileges to SYSTEM. Microsoft rates these vulnerabilities as “Exploitation More Likely.”
Microsoft Office Remote Code Execution Vulnerability
The vulnerability tracked as CVE-2024-38021with a CVSSv3 score of 8.8 is a RCE vulnerability affecting Microsoft Office 2016. This vulnerability rated as “Exploitation More Likely.” Successful exploitation would allow an attacker to gain elevated privileges, including write, read, and delete functionality. Microsoft notes that exploitation requires an attacker to create a malicious link that can bypass Protected View Protocol. Based on Microsoft’s description, an attacker would have to entice a user into clicking the link, by sending it to an unsuspecting user in a phishing attack. This would result in the attacker gaining access to local NTLM credential information which could be utilized for elevated access to achieve RCE.
Microsoft OLE DB Driver and SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
This month’s release included 38 CVEs for RCEs affecting SQL Server Native Client OLE DB Provider and the OLE DB Driver for SQL Server. All these CVEs received CVSSv3 scores of 8.8 and were rated as “Exploitation Less Likely.” Successful exploitation of these vulnerabilities can be achieved by convincing an authenticated user into connecting to a malicious SQL server database using an affected driver.
Systematic Identification and Characterization of Proprietary Prefetchers
The vulnerability tracked as CVE-2024-37985 with a CVSSv3 score of 5.9. Microsoft has fixed a previously disclosed “Fetch Bench” side-channel attack that can be used to steal “secret information.”
An attacker who successfully exploited this vulnerability could view heap memory from a privileged process running on the server. Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.
Patch Tuesday Summary
| CVE ID | CVE Title | Severity |
| CVE-2024-38023 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Critical |
| CVE-2024-38060 | Windows Imaging Component Remote Code Execution Vulnerability | Critical |
| CVE-2024-38076 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | Critical |
| CVE-2024-38074 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | Critical |
| CVE-2024-38077 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | Critical |
| CVE-2024-30105 | .NET Core and Visual Studio Denial of Service Vulnerability | Important |
| CVE-2024-38081 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | Important |
| CVE-2024-35264 | .NET and Visual Studio Remote Code Execution Vulnerability | Important |
| CVE-2024-38095 | .NET and Visual Studio Denial of Service Vulnerability | Important |
| CVE-2024-38092 | Azure CycleCloud Elevation of Privilege Vulnerability | Important |
| CVE-2024-35266 | Azure DevOps Server Spoofing Vulnerability | Important |
| CVE-2024-35267 | Azure DevOps Server Spoofing Vulnerability | Important |
| CVE-2024-38086 | Azure Kinect SDK Remote Code Execution Vulnerability | Important |
| CVE-2024-35261 | Azure Network Watcher VM Extension Elevation of Privilege Vulnerability | Important |
| CVE-2024-37985 | Arm: CVE-2024-37985 Systematic Identification and Characterization of Proprietary Prefetchers | Important |
| CVE-2024-38027 | Windows Line Printer Daemon Service Denial of Service Vulnerability | Important |
| CVE-2024-38089 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | Important |
| CVE-2024-30061 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | Important |
| CVE-2024-38079 | Windows Graphics Component Elevation of Privilege Vulnerability | Important |
| CVE-2024-38051 | Windows Graphics Component Remote Code Execution Vulnerability | Important |
| CVE-2024-38021 | Microsoft Office Remote Code Execution Vulnerability | Important |
| CVE-2024-38024 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important |
| CVE-2024-32987 | Microsoft SharePoint Server Information Disclosure Vulnerability | Important |
| CVE-2024-38094 | Microsoft SharePoint Remote Code Execution Vulnerability | Important |
| CVE-2024-38057 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | Important |
| CVE-2024-38054 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | Important |
| CVE-2024-38052 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | Important |
| CVE-2024-38055 | Microsoft Windows Codecs Library Information Disclosure Vulnerability | Important |
| CVE-2024-38056 | Microsoft Windows Codecs Library Information Disclosure Vulnerability | Important |
| CVE-2024-38091 | Microsoft WS-Discovery Denial of Service Vulnerability | Important |
| CVE-2024-38048 | Windows Network Driver Interface Specification (NDIS) Denial of Service Vulnerability | Important |
| CVE-2024-3596 | CERT/CC: CVE-2024-3596 RADIUS Protocol Spoofing Vulnerability | Important |
| CVE-2024-38061 | DCOM Remote Cross-Session Activation Elevation of Privilege Vulnerability | Important |
| CVE-2024-38080 | Windows Hyper-V Elevation of Privilege Vulnerability | Important |
| CVE-2024-28928 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-38088 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-20701 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-21317 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-21331 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-21308 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-21333 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-35256 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-21303 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-21335 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-35271 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-35272 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-21332 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-38087 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-21425 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-21449 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-37324 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-37330 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-37326 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-37329 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-37328 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-37327 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-37334 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | Important |
| CVE-2024-37321 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-37320 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-37319 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-37322 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-37333 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-37336 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-37323 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-37331 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-21398 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-21373 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-37318 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-21428 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-21415 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-37332 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-21414 | SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | Important |
| CVE-2024-38058 | BitLocker Security Feature Bypass Vulnerability | Important |
| CVE-2024-38100 | Windows File Explorer Elevation of Privilege Vulnerability | Important |
| CVE-2024-21417 | Windows Text Services Framework Elevation of Privilege Vulnerability | Important |
| CVE-2024-30098 | Windows Cryptographic Services Security Feature Bypass Vulnerability | Important |
| CVE-2024-38044 | DHCP Server Service Remote Code Execution Vulnerability | Important |
| CVE-2024-38049 | Windows Distributed Transaction Coordinator Remote Code Execution Vulnerability | Important |
| CVE-2024-38069 | Windows Enroll Engine Security Feature Bypass Vulnerability | Important |
| CVE-2024-38104 | Windows Fax Service Remote Code Execution Vulnerability | Important |
| CVE-2024-38034 | Windows Filtering Platform Elevation of Privilege Vulnerability | Important |
| CVE-2024-38022 | Windows Image Acquisition Elevation of Privilege Vulnerability | Important |
| CVE-2024-38105 | Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability | Important |
| CVE-2024-38053 | Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability | Important |
| CVE-2024-38102 | Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability | Important |
| CVE-2024-38101 | Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability | Important |
| CVE-2024-35270 | Windows iSCSI Service Denial of Service Vulnerability | Important |
| CVE-2024-38041 | Windows Kernel Information Disclosure Vulnerability | Important |
| CVE-2024-38062 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Important |
| CVE-2024-38070 | Windows LockDown Policy (WLDP) Security Feature Bypass Vulnerability | Important |
| CVE-2024-38017 | Microsoft Message Queuing Information Disclosure Vulnerability | Important |
| CVE-2024-38112 | Windows MSHTML Platform Spoofing Vulnerability | Important |
| CVE-2024-30013 | Windows MultiPoint Services Remote Code Execution Vulnerability | Important |
| CVE-2024-30081 | Windows NTLM Spoofing Vulnerability | Important |
| CVE-2024-38068 | Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability | Important |
| CVE-2024-38067 | Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability | Important |
| CVE-2024-38031 | Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability | Important |
| CVE-2024-38028 | Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability | Important |
| CVE-2024-38019 | Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability | Important |
| CVE-2024-38025 | Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability | Important |
| CVE-2024-38043 | PowerShell Elevation of Privilege Vulnerability | Important |
| CVE-2024-38047 | PowerShell Elevation of Privilege Vulnerability | Important |
| CVE-2024-38033 | PowerShell Elevation of Privilege Vulnerability | Important |
| CVE-2024-30071 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | Important |
| CVE-2024-30079 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | Important |
| CVE-2024-38015 | Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | Important |
| CVE-2024-38071 | Windows Remote Desktop Licensing Service Denial of Service Vulnerability | Important |
| CVE-2024-38073 | Windows Remote Desktop Licensing Service Denial of Service Vulnerability | Important |
| CVE-2024-38072 | Windows Remote Desktop Licensing Service Denial of Service Vulnerability | Important |
| CVE-2024-38099 | Windows Remote Desktop Licensing Service Denial of Service Vulnerability | Important |
| CVE-2024-38065 | Secure Boot Security Feature Bypass Vulnerability | Important |
| CVE-2024-37986 | Secure Boot Security Feature Bypass Vulnerability | Important |
| CVE-2024-37981 | Secure Boot Security Feature Bypass Vulnerability | Important |
| CVE-2024-37987 | Secure Boot Security Feature Bypass Vulnerability | Important |
| CVE-2024-28899 | Secure Boot Security Feature Bypass Vulnerability | Important |
| CVE-2024-26184 | Secure Boot Security Feature Bypass Vulnerability | Important |
| CVE-2024-38011 | Secure Boot Security Feature Bypass Vulnerability | Important |
| CVE-2024-37984 | Secure Boot Security Feature Bypass Vulnerability | Important |
| CVE-2024-37988 | Secure Boot Security Feature Bypass Vulnerability | Important |
| CVE-2024-37977 | Secure Boot Security Feature Bypass Vulnerability | Important |
| CVE-2024-37978 | Secure Boot Security Feature Bypass Vulnerability | Important |
| CVE-2024-37974 | Secure Boot Security Feature Bypass Vulnerability | Important |
| CVE-2024-38010 | Secure Boot Security Feature Bypass Vulnerability | Important |
| CVE-2024-37989 | Secure Boot Security Feature Bypass Vulnerability | Important |
| CVE-2024-37970 | Secure Boot Security Feature Bypass Vulnerability | Important |
| CVE-2024-37975 | Secure Boot Security Feature Bypass Vulnerability | Important |
| CVE-2024-37972 | Secure Boot Security Feature Bypass Vulnerability | Important |
| CVE-2024-37973 | Secure Boot Security Feature Bypass Vulnerability | Important |
| CVE-2024-37971 | Secure Boot Security Feature Bypass Vulnerability | Important |
| CVE-2024-37969 | Secure Boot Security Feature Bypass Vulnerability | Important |
| CVE-2024-38013 | Microsoft Windows Server Backup Elevation of Privilege Vulnerability | Important |
| CVE-2024-38064 | Windows TCP/IP Information Disclosure Vulnerability | Important |
| CVE-2024-38030 | Windows Themes Spoofing Vulnerability | Important |
| CVE-2024-38085 | Windows Graphics Component Elevation of Privilege Vulnerability | Important |
| CVE-2024-38066 | Windows Win32k Elevation of Privilege Vulnerability | Important |
| CVE-2024-38059 | Win32k Elevation of Privilege Vulnerability | Important |
| CVE-2024-38050 | Windows Workstation Service Elevation of Privilege Vulnerability | Important |
| CVE-2024-38032 | Microsoft Xbox Remote Code Execution Vulnerability | Important |
| CVE-2024-38078 | Xbox Wireless Adapter Remote Code Execution Vulnerability | Important |
| CVE-2024-39684 | Github: CVE-2024-39684 TenCent RapidJSON Elevation of Privilege Vulnerability | Moderate |
| CVE-2024-38517 | Github: CVE-2024-38517 TenCent RapidJSON Elevation of Privilege Vulnerability | Moderate |
| CVE-2024-38020 | Microsoft Outlook Spoofing Vulnerability | Moderate |


