What’s New Wednesday: A Summary of September 2024’s Patch Tuesday September 11, 2024 – Posted in: Cyber Security, IT Support, News, What's New Wednesdays – Tags: , , , ,

The Microsoft monthly security update release is published on the second Tuesday of each month. It’s a good idea to restart your PC on the following Wednesday – today. We may well restart some of your servers overnight this week if a patch requires it.

NEW THIS WEDNESDAY

This month’s Patch Tuesday included security updates for 79 flaws and 4 actively exploited zero-day vulnerabilities patched. Overall Microsoft patched:

  • 30 Elevation of Privilege Vulnerabilities
  • 4 Security Feature Bypass Vulnerabilities
  • 23 Remote Code Execution Vulnerabilities
  • 11 Information Disclosure Vulnerabilities
  • 8 Denial of Service Vulnerabilities
  • 3 Spoofing Vulnerabilities

There were 4 actively exploited zero-day vulnerabilities patched, one of which is publicly disclosed:

CVE-2024-43491 – Microsoft Windows Update Remote Code Execution Vulnerability
a servicing stack flaw that allows remote code execution and rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 allowing an attacker to exploit these previously mitigated vulnerabilities.
CVE-2024-38226 – Microsoft Publisher Security Feature Bypass Vulnerability
bypasses the security protections against embedded macros used to block untrusted or malicious files in downloaded documents.
CVE-2024-38217 – Windows Mark of the Web Security Feature Bypass Vulnerability
publicly disclosed last month and believed to have been actively exploited since 2018. Allows specially crafted files to cause the file to be opened while bypassing Smart App Control and the Mark of the Web security warnings, resulting in a limited loss of integrity and availability of security features such as SmartScreen Application Reputation security check and/or the legacy Windows Attachment Services security prompt.
CVE-2024-38014 – Windows Installer Elevation of Privilege Vulnerability
allows attacks to gain SYSTEM privileges on Windows systems.

Releases from other software providers include:

  • Apache – fixed a critical OFBiz remote code execution vulnerability that was a bypass for previously fixed flaws.
  • Cisco – fixed multiple vulnerabilities this month, including a backdo
  • Eucleak – attack extracts ECDSA secret keys to clone YubiKey FIDO devices.
  • Fortinet – updates for flaws in Fortisandbox and FortiAnalyzer & FortiManager.
  • Google – fixed an actively exploited Pixel elevation of privileges flaw to other Android devices.
  • Ivanti – updates for critical vTM auth bypass with public exploit.
  • LiteSpeed Cache plugin for WordPress – fixes an unauthenticated account takeover issue.
  • SonicWall – an access control flaw fixed last month is now exploited in ransomware attacks.
  • Veeam – fixed a critical RCE vulnerability in Backup & Replication software.
  • Zyxel – warned of a critical OS command injection flaw in its routers.

FULL LIST OF MICROSOFT PATCHES

Vulnerable Service CVE ID Title Severity
.Azure CycleCloud CVE-2024-43469 Azure CycleCloud Remote Code Execution Vulnerability Important
.Azure Network Watcher CVE-2024-38188 Azure Network Watcher VM Agent Elevation of Privilege Vulnerability Important
.Azure Network Watcher CVE-2024-43470 Azure Network Watcher VM Agent Elevation of Privilege Vulnerability Important
.Azure Stack CVE-2024-38216 Azure Stack Hub Elevation of Privilege Vulnerability Critical
.Azure Stack CVE-2024-38220 Azure Stack Hub Elevation of Privilege Vulnerability Critical
.Azure Web Apps CVE-2024-38194 Azure Web Apps Elevation of Privilege Vulnerability Critical
.Dynamics Business Central CVE-2024-38225 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability Important
.Microsoft AutoUpdate (MAU) CVE-2024-43492 Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability Important
.Microsoft Dynamics 365 (on-premises) CVE-2024-43476 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Important
.Microsoft Graphics Component CVE-2024-38247 Windows Graphics Component Elevation of Privilege Vulnerability Important
.Microsoft Graphics Component CVE-2024-38250 Windows Graphics Component Elevation of Privilege Vulnerability Important
.Microsoft Graphics Component CVE-2024-38249 Windows Graphics Component Elevation of Privilege Vulnerability Important
.Microsoft Management Console CVE-2024-38259 Microsoft Management Console Remote Code Execution Vulnerability Important
.Microsoft Office Excel CVE-2024-43465 Microsoft Excel Elevation of Privilege Vulnerability Important
.Microsoft Office Publisher CVE-2024-38226 Microsoft Publisher Security Feature Bypass Vulnerability Important
.Microsoft Office SharePoint CVE-2024-38227 Microsoft SharePoint Server Remote Code Execution Vulnerability Important
.Microsoft Office SharePoint CVE-2024-43464 Microsoft SharePoint Server Remote Code Execution Vulnerability Critical
.Microsoft Office SharePoint CVE-2024-38018 Microsoft SharePoint Server Remote Code Execution Vulnerability Critical
.Microsoft Office SharePoint CVE-2024-38228 Microsoft SharePoint Server Remote Code Execution Vulnerability Important
.Microsoft Office SharePoint CVE-2024-43466 Microsoft SharePoint Server Denial of Service Vulnerability Important
.Microsoft Office Visio CVE-2024-43463 Microsoft Office Visio Remote Code Execution Vulnerability Important
.Microsoft Outlook for iOS CVE-2024-43482 Microsoft Outlook for iOS Information Disclosure Vulnerability Important
.Microsoft Streaming Service CVE-2024-38245 Kernel Streaming Service Driver Elevation of Privilege Vulnerability Important
.Microsoft Streaming Service CVE-2024-38241 Kernel Streaming Service Driver Elevation of Privilege Vulnerability Important
.Microsoft Streaming Service CVE-2024-38242 Kernel Streaming Service Driver Elevation of Privilege Vulnerability Important
.Microsoft Streaming Service CVE-2024-38244 Kernel Streaming Service Driver Elevation of Privilege Vulnerability Important
.Microsoft Streaming Service CVE-2024-38243 Kernel Streaming Service Driver Elevation of Privilege Vulnerability Important
.Microsoft Streaming Service CVE-2024-38237 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability Important
.Microsoft Streaming Service CVE-2024-38238 Kernel Streaming Service Driver Elevation of Privilege Vulnerability Important
.Power Automate CVE-2024-43479 Microsoft Power Automate Desktop Remote Code Execution Vulnerability Important
.Role: Windows Hyper-V CVE-2024-38235 Windows Hyper-V Denial of Service Vulnerability Important
.SQL Server CVE-2024-37338 Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability Important
.SQL Server CVE-2024-37980 Microsoft SQL Server Elevation of Privilege Vulnerability Important
.SQL Server CVE-2024-26191 Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability Important
.SQL Server CVE-2024-37339 Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability Important
.SQL Server CVE-2024-37337 Microsoft SQL Server Native Scoring Information Disclosure Vulnerability Important
.SQL Server CVE-2024-26186 Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability Important
.SQL Server CVE-2024-37342 Microsoft SQL Server Native Scoring Information Disclosure Vulnerability Important
.SQL Server CVE-2024-43474 Microsoft SQL Server Information Disclosure Vulnerability Important
.SQL Server CVE-2024-37335 Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability Important
.SQL Server CVE-2024-37966 Microsoft SQL Server Native Scoring Information Disclosure Vulnerability Important
.SQL Server CVE-2024-37340 Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability Important
.SQL Server CVE-2024-37965 Microsoft SQL Server Elevation of Privilege Vulnerability Important
.SQL Server CVE-2024-37341 Microsoft SQL Server Elevation of Privilege Vulnerability Important
.Windows Admin Center CVE-2024-43475 Microsoft Windows Admin Center Information Disclosure Vulnerability Important
.Windows AllJoyn API CVE-2024-38257 Microsoft AllJoyn API Information Disclosure Vulnerability Important
.Windows Authentication Methods CVE-2024-38254 Windows Authentication Information Disclosure Vulnerability Important
.Windows DHCP Server CVE-2024-38236 DHCP Server Service Denial of Service Vulnerability Important
.Windows Installer CVE-2024-38014 Windows Installer Elevation of Privilege Vulnerability Important
.Windows Kerberos CVE-2024-38239 Windows Kerberos Elevation of Privilege Vulnerability Important
.Windows Kernel-Mode Drivers CVE-2024-38256 Windows Kernel-Mode Driver Information Disclosure Vulnerability Important
.Windows Libarchive CVE-2024-43495 Windows libarchive Remote Code Execution Vulnerability Important
.Windows Mark of the Web (MOTW) CVE-2024-38217 Windows Mark of the Web Security Feature Bypass Vulnerability Important
.Windows Mark of the Web (MOTW) CVE-2024-43487 Windows Mark of the Web Security Feature Bypass Vulnerability Moderate
.Windows MSHTML Platform CVE-2024-43461 Windows MSHTML Platform Spoofing Vulnerability Important
.Windows Network Address Translation (NAT) CVE-2024-38119 Windows Network Address Translation (NAT) Remote Code Execution Vulnerability Critical
.Windows Network Virtualization CVE-2024-38232 Windows Networking Denial of Service Vulnerability Important
.Windows Network Virtualization CVE-2024-38233 Windows Networking Denial of Service Vulnerability Important
.Windows Network Virtualization CVE-2024-38234 Windows Networking Denial of Service Vulnerability Important
.Windows Network Virtualization CVE-2024-43458 Windows Networking Information Disclosure Vulnerability Important
.Windows PowerShell CVE-2024-38046 PowerShell Elevation of Privilege Vulnerability Important
.Windows Remote Access Connection Manager CVE-2024-38240 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Important
.Windows Remote Desktop Licensing Service CVE-2024-38231 Windows Remote Desktop Licensing Service Denial of Service Vulnerability Important
.Windows Remote Desktop Licensing Service CVE-2024-38258 Windows Remote Desktop Licensing Service Information Disclosure Vulnerability Important
.Windows Remote Desktop Licensing Service CVE-2024-43467 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Important
.Windows Remote Desktop Licensing Service CVE-2024-43454 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Important
.Windows Remote Desktop Licensing Service CVE-2024-38263 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Important
.Windows Remote Desktop Licensing Service CVE-2024-38260 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Important
.Windows Remote Desktop Licensing Service CVE-2024-43455 Windows Remote Desktop Licensing Service Spoofing Vulnerability Important
.Windows Security Zone Mapping CVE-2024-30073 Windows Security Zone Mapping Security Feature Bypass Vulnerability Important
.Windows Setup and Deployment CVE-2024-43457 Windows Setup and Deployment Elevation of Privilege Vulnerability Important
.Windows Standards-Based Storage Management Service CVE-2024-38230 Windows Standards-Based Storage Management Service Denial of Service Vulnerability Important
.Windows Storage CVE-2024-38248 Windows Storage Elevation of Privilege Vulnerability Important
.Windows TCP/IP CVE-2024-21416 Windows TCP/IP Remote Code Execution Vulnerability Important
.Windows TCP/IP CVE-2024-38045 Windows TCP/IP Remote Code Execution Vulnerability Important
.Windows Update CVE-2024-43491 Microsoft Windows Update Remote Code Execution Vulnerability Critical
.Windows Win32K – GRFX CVE-2024-38246 Win32k Elevation of Privilege Vulnerability Important
.Windows Win32K – ICOMP CVE-2024-38252 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability Important
.Windows Win32K – ICOMP CVE-2024-38253 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability Important

GLOSSARY

  • Authentication – proving who you are so you can be given access to what you need/have rights to.
  • MFA – multi-factor authentication, proving who you are in multiple ways, something you know (like a password or pin), something you are (a fingerprint or retina scan), something you have (like your phone – proved with a code).
  • Vulnerability – a defect in software that could allow an attacker to gain control of a system or service.
  • Patch – a change to a piece of software, released after sale, to fix a problem or add a feature.
  • Zero Day – Microsoft classifies a vulnerability as a zero-day if it is publicly disclosed or actively exploited with no official fix available.
  • Actively Exploited – an actively exploited vulnerability is one that is being used by malicious actors.
  • DDOS / DOS – (Distributed) Denial of Service attack, a method of swamping a service or server with so many false queries at once that it is forced offline.
  • Disclosed – a disclosed vulnerability is one that the software creators have published, meaning that it can be easily found out about by anyone who knows where to look.
  • CVE ID – CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws, the ID is the number assigned to that vulnerability.
  • Severity – a disclosed vulnerability is one that the software creators have published, meaning that it can be easily found out about by anyone who knows where to look.
  • Security Feature Bypass Vulnerabilities – allow for intruders to bypass security features such as password protection or MFA.
  • Remote Code Execution Vulnerabilities – allow people to remotely trigger potentially malicious code on your device.
  • Information Disclosure Vulnerabilities – allow the wrong people access to your data.
  • Denial of Service Vulnerabilities – allow a DOS/DDOS attack to succeed.
  • Spoofing Vulnerabilities – allow someone to pretend to be you/your systems.

If you have any concerns about cybersecurity, or would like to discuss any other IT Support needs you might have please give us a call on 01245 265100 or email us at . To stay up to date with our regular What’s New Wednesday emails and receive industry news straight to your inbox, subscribe to our newsletters in the top right.