What’s New Wednesday: A Summary of June 2024’s Patch Tuesday June 12, 2024 – Posted in: IT Support, News, What's New Wednesdays – Tags: , , , ,

The Microsoft monthly security update release is published on the second Tuesday of each month. It’s a good idea to restart your PC on the following Wednesday – today. We may well restart some of your servers overnight this week if a patch requires it.

NEW THIS WEDNESDAY

Yesterday’s Patch Tuesday included security updates for 51 flaws, 18 remote code execution vulnerabilities and 1 publicaly disclosed zero-day vulnerability. Overall Microsoft patched:

  • 25 Elevation of Privilege Vulnerabilities
  • 18 Remote Code Execution Vulnerabilities
  • 3 Information Disclosure Vulnerabilities
  • 5 Denial of Service Vulnerabilities

There was one zero-day vulnerability patched:
CVE-2023-50868 – MITRE: CVE-2023-50868 NSEC3
an attacker could exploit standard DNSSEC protocols intended for DNS integrity by using excessive resources on a resolver, causing a denial of service for legitimate users.

Releases from other software providers include:

  • ARM – an actively exploited bug in Mali GPU kernel drivers.
  • Apple – 21 security flaws in the visionOS 1.2 release.
  • Cisco – security updates for its Cisco Finesse and Webex
  • Cox – an API auth bypass bug that impacted million of modems.
  • F5 – security updates for two high-severity BIG-IP Next Central Manager API flaws.
  • PHP – a critical remote code execution flaw that is now actively exploited in ransomware attacks.
  • TikTok – an exploited zero-day, zero-click flaw in their direct messages feature.
  • VMware – 3 zero-day bugs exploited at Pwn2Own 2024.
  • Zyxel – an emergency remote code execution patch for end-of-life NAS devices.

FULL LIST OF MICROSOFT PATCHES

Vulnerable Service CVE ID Title Severity
Azure Data Science Virtual Machines CVE-2024-37325 Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability Important
Azure File Sync CVE-2024-35253 Microsoft Azure File Sync Elevation of Privilege Vulnerability Important
Azure Monitor CVE-2024-35254 Azure Monitor Agent Elevation of Privilege Vulnerability Important
Azure SDK CVE-2024-35255 Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability Important
Azure Storage Library CVE-2024-35252 Azure Storage Movement Client Library Denial of Service Vulnerability Important
Dynamics Business Central CVE-2024-35248 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability Important
Dynamics Business Central CVE-2024-35249 Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability Important
Microsoft Dynamics CVE-2024-35263 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability Important
Microsoft Edge (Chromium-based) CVE-2024-5498 Chromium: CVE-2024-5498 Use after free in Presentation API Unknown
Microsoft Edge (Chromium-based) CVE-2024-5493 Chromium: CVE-2024-5493 Heap buffer overflow in WebRTC Unknown
Microsoft Edge (Chromium-based) CVE-2024-5497 Chromium: CVE-2024-5497 Out of bounds memory access in Keyboard Inputs Unknown
Microsoft Edge (Chromium-based) CVE-2024-5495 Chromium: CVE-2024-5495 Use after free in Dawn Unknown
Microsoft Edge (Chromium-based) CVE-2024-5499 Chromium: CVE-2024-5499 Out of bounds write in Streams API Unknown
Microsoft Edge (Chromium-based) CVE-2024-5494 Chromium: CVE-2024-5494 Use after free in Dawn Unknown
Microsoft Edge (Chromium-based) CVE-2024-5496 Chromium: CVE-2024-5496 Use after free in Media Session Unknown
Microsoft Office CVE-2024-30101 Microsoft Office Remote Code Execution Vulnerability Important
Microsoft Office CVE-2024-30104 Microsoft Office Remote Code Execution Vulnerability Important
Microsoft Office Outlook CVE-2024-30103 Microsoft Outlook Remote Code Execution Vulnerability Important
Microsoft Office SharePoint CVE-2024-30100 Microsoft SharePoint Server Remote Code Execution Vulnerability Important
Microsoft Office Word CVE-2024-30102 Microsoft Office Remote Code Execution Vulnerability Important
Microsoft Streaming Service CVE-2024-30090 Microsoft Streaming Service Elevation of Privilege Vulnerability Important
Microsoft Streaming Service CVE-2024-30089 Microsoft Streaming Service Elevation of Privilege Vulnerability Important
Microsoft WDAC OLE DB provider for SQL CVE-2024-30077 Windows OLE Remote Code Execution Vulnerability Important
Microsoft Windows CVE-2023-50868 MITRE: CVE-2023-50868 NSEC3 closest encloser proof can exhaust CPU Important
Microsoft Windows Speech CVE-2024-30097 Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability Important
Visual Studio CVE-2024-30052 Visual Studio Remote Code Execution Vulnerability Important
Visual Studio CVE-2024-29060 Visual Studio Elevation of Privilege Vulnerability Important
Visual Studio CVE-2024-29187 GitHub: CVE-2024-29187 WiX Burn-based bundles are vulnerable to binary hijack when run as SYSTEM Important
Windows Cloud Files Mini Filter Driver CVE-2024-30085 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Important
Windows Container Manager Service CVE-2024-30076 Windows Container Manager Service Elevation of Privilege Vulnerability Important
Windows Cryptographic Services CVE-2024-30096 Windows Cryptographic Services Information Disclosure Vulnerability Important
Windows DHCP Server CVE-2024-30070 DHCP Server Service Denial of Service Vulnerability Important
Windows Distributed File System (DFS) CVE-2024-30063 Windows Distributed File System (DFS) Remote Code Execution Vulnerability Important
Windows Event Logging Service CVE-2024-30072 Microsoft Event Trace Log File Parsing Remote Code Execution Vulnerability Important
Windows Kernel CVE-2024-30068 Windows Kernel Elevation of Privilege Vulnerability Important
Windows Kernel CVE-2024-30064 Windows Kernel Elevation of Privilege Vulnerability Important
Windows Kernel-Mode Drivers CVE-2024-30084 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability Important
Windows Kernel-Mode Drivers CVE-2024-35250 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability Important
Windows Link Layer Topology Discovery Protocol CVE-2024-30075 Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability Important
Windows Link Layer Topology Discovery Protocol CVE-2024-30074 Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability Important
Windows NT OS Kernel CVE-2024-30099 Windows Kernel Elevation of Privilege Vulnerability Important
Windows NT OS Kernel CVE-2024-30088 Windows Kernel Elevation of Privilege Vulnerability Important
Windows Perception Service CVE-2024-35265 Windows Perception Service Elevation of Privilege Vulnerability Important
Windows Remote Access Connection Manager CVE-2024-30069 Windows Remote Access Connection Manager Information Disclosure Vulnerability Important
Windows Routing and Remote Access Service (RRAS) CVE-2024-30095 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important
Windows Routing and Remote Access Service (RRAS) CVE-2024-30094 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important
Windows Server Service CVE-2024-30062 Windows Standards-Based Storage Management Service Remote Code Execution Vulnerability Important
Windows Server Service CVE-2024-30080 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Critical
Windows Standards-Based Storage Management Service CVE-2024-30083 Windows Standards-Based Storage Management Service Denial of Service Vulnerability Important
Windows Storage CVE-2024-30093 Windows Storage Elevation of Privilege Vulnerability Important
Windows Themes CVE-2024-30065 Windows Themes Denial of Service Vulnerability Important
Windows Wi-Fi Driver CVE-2024-30078 Windows Wi-Fi Driver Remote Code Execution Vulnerability Important
Windows Win32 Kernel Subsystem CVE-2024-30086 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability Important
Windows Win32K – GRFX CVE-2024-30087 Win32k Elevation of Privilege Vulnerability Important
Windows Win32K – GRFX CVE-2024-30091 Win32k Elevation of Privilege Vulnerability Important
Windows Win32K – GRFX CVE-2024-30082 Win32k Elevation of Privilege Vulnerability Important
Winlogon CVE-2024-30067 Winlogon Elevation of Privilege Vulnerability Important
Winlogon CVE-2024-30066 Winlogon Elevation of Privilege Vulnerability Important

GLOSSARY

  • Authentication – proving who you are so you can be given access to what you need/have rights to.
  • MFA – multi-factor authentication, proving who you are in multiple ways, something you know (like a password or pin), something you are (a fingerprint or retina scan), something you have (like your phone – proved with a code).
  • Vulnerability – a defect in software that could allow an attacker to gain control of a system or service.
  • Patch – a change to a piece of software, released after sale, to fix a problem or add a feature.
  • Zero Day – Microsoft classifies a vulnerability as a zero-day if it is publicly disclosed or actively exploited with no official fix available.
  • Actively Exploited – an actively exploited vulnerability is one that is being used by malicious actors.
  • DDOS / DOS – (Distributed) Denial of Service attack, a method of swamping a service or server with so many false queries at once that it is forced offline.
  • Disclosed – a disclosed vulnerability is one that the software creators have published, meaning that it can be easily found out about by anyone who knows where to look.
  • CVE ID – CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws, the ID is the number assigned to that vulnerability.
  • Severity – a disclosed vulnerability is one that the software creators have published, meaning that it can be easily found out about by anyone who knows where to look.
  • Security Feature Bypass Vulnerabilities – allow for intruders to bypass security features such as password protection or MFA.
  • Remote Code Execution Vulnerabilities – allow people to remotely trigger potentially malicious code on your device.
  • Information Disclosure Vulnerabilities – allow the wrong people access to your data.
  • Denial of Service Vulnerabilities – allow a DOS/DDOS attack to succeed.
  • Spoofing Vulnerabilities – allow someone to pretend to be you/your systems.

If you have any concerns about cybersecurity, or would like to discuss any other IT Support needs you might have please give us a call on 01245 265100 or email us at . To stay up to date with our regular What’s New Wednesday emails and receive industry news straight to your inbox, subscribe to our newsletters in the top right.