National Cyber Warfare Foundation (NCWF) Forums


Patch Tuesday - July 2024


0 user ratings
2024-07-09 20:08:24
milo
Red Team (CNA)

 - archive -- 
Microsoft has published 139 vulnerabilities this July 2024 Patch Tuesday, two of which had already been seen exploited in the wild.

Patch Tuesday - July 2024

Microsoft is addressing 139 vulnerabilities this July 2024 Patch Tuesday, which is on the high side in terms of typical CVE counts. They’ve also republished details for 4 CVEs issued by other vendors that affect Microsoft products. Microsoft has evidence of in-the-wild exploitation for 2 of the vulnerabilities published today. At time of writing, none of the vulnerabilities patched today are listed in CISA’s Known Exploited Vulnerabilities catalog, though we can expect CVE-2024-38080 and CVE-2024-38112 to appear there in short order. Microsoft is also patching 5 critical remote code execution (RCE) vulnerabilities today.

Windows Hyper-V: zero-day EoP

CVE-2024-38080 is an elevation of privilege (EoP) vulnerability affecting Microsoft’s Hyper-V virtualization functionality. Successful exploitation will give an attacker SYSTEM-level privileges. Only more recent editions of Windows are affected; Windows 11 since version 21H2 and Windows Server 2022 (including Server Core).

Windows MSHTML Platform: zero-day Spoofing

The other vulnerability seen exploited in the wild this month is CVE-2024-38112, a Spoofing vulnerability affecting Microsoft’s MSHTML browser engine which can be found on all versions of Windows, including Server editions. User interaction is required for exploitation – for example, a threat actor would need to send the victim a malicious file and convince them to open it. Microsoft is characteristically cagey about what exactly can be spoofed here, though they do indicate that the associated Common Weakness Enumeration (CWE) is CWE-668: Exposure of Resource to Wrong Sphere, which is defined as providing unintended actors with inappropriate access to a resource.

SharePoint: critical post-auth RCE

Similar to a vulnerability seen in May, CVE-2024-38023 is a SharePoint vulnerability that could allow an authenticated attacker with Site Owner permissions or higher to upload a specially crafted file to a SharePoint Server, then craft malicious API requests to trigger deserialization of the file's parameters, thus enabling them to achieve remote code execution in the context of the SharePoint Server. The CVSS base score of 7.2 reflects the requirement of Site Owner privileges or higher to exploit the vulnerability.

Windows Imaging: critical RCE

All supported versions of Windows (and almost certainly unsupported versions as well) are vulnerable to CVE-2024-38060, a flaw in the Windows Imaging Component related to TIFF (Tagged Image File Format) image processing that could allow an attacker to execute arbitrary code on a system. The example scenario Microsoft provides is simply of an authenticated attacker uploading a specially crafted TIFF image to a server in order to exploit this.

Remote Desktop Licensing Service: multiple critical RCEs

Three critical CVEs related to the Windows Remote Desktop Licensing Service were patched this month. CVE-2024-38074, CVE-2024-38076, and CVE-2024-38077. All three of these carry a CVSS 3.1 base score of 9.8 – if you rely on the Remote Desktop licensing service, best get patching immediately. As a mitigation, consider disabling the service entirely until there is an opportunity to apply the update.

SQL Server

Microsoft has patched a host of CVEs affecting SQL Server, all with a CVSS 3.1 base score of 8.8 and allowing RCE. These specifically affect the OLE DB Provider, so not only do SQL Server instances need to be updated, but client code running vulnerable versions of the connection driver will also need to be addressed. For example, an attacker could use social engineering tactics to dupe an authenticated user into attempting to connect to a SQL Server database configured to return malicious data, allowing arbitrary code execution on the client.

Lifecycle update

Also in SQL Server news this month, Microsoft SQL Server 2014 moves past the end of extended support. From this point onward, Microsoft only guarantees to provide SQL Server 2014 security updates to customers who pay for the Extended Security Updates program.

Summary charts

Patch Tuesday - July 2024
Patch Tuesday - July 2024
Patch Tuesday - July 2024

Summary tables

Azure vulnerabilities

















































CVETitleExploited?Publicly disclosed?CVSSv3 base score
CVE-2024-38092Azure CycleCloud Elevation of Privilege VulnerabilityNoNo8.8
CVE-2024-35261Azure Network Watcher VM Extension Elevation of Privilege VulnerabilityNoNo7.8
CVE-2024-35266Azure DevOps Server Spoofing VulnerabilityNoNo7.6
CVE-2024-35267Azure DevOps Server Spoofing VulnerabilityNoNo7.6
CVE-2024-38086Azure Kinect SDK Remote Code Execution VulnerabilityNoNo6.4

Developer Tools vulnerabilities










































CVETitleExploited?Publicly disclosed?CVSSv3 base score
CVE-2024-35264.NET and Visual Studio Remote Code Execution VulnerabilityNoYes8.1
CVE-2024-38095.NET and Visual Studio Denial of Service VulnerabilityNoNo7.5
CVE-2024-30105.NET Core and Visual Studio Denial of Service VulnerabilityNoNo7.5
CVE-2024-38081.NET, .NET Framework, and Visual Studio Elevation of Privilege VulnerabilityNoNo7.3

ESU Windows vulnerabilities



































































































































































































































































































































































































































































































CVETitleExploited?Publicly disclosed?CVSSv3 base score
CVE-2024-38077Windows Remote Desktop Licensing Service Remote Code Execution VulnerabilityNoNo9.8
CVE-2024-38074Windows Remote Desktop Licensing Service Remote Code Execution VulnerabilityNoNo9.8
CVE-2024-38053Windows Layer-2 Bridge Network Driver Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-38060Windows Imaging Component Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-38104Windows Fax Service Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-28899Secure Boot Security Feature Bypass VulnerabilityNoNo8.8
CVE-2024-37973Secure Boot Security Feature Bypass VulnerabilityNoNo8.4
CVE-2024-37984Secure Boot Security Feature Bypass VulnerabilityNoNo8.4
CVE-2024-37969Secure Boot Security Feature Bypass VulnerabilityNoNo8
CVE-2024-37970Secure Boot Security Feature Bypass VulnerabilityNoNo8
CVE-2024-37974Secure Boot Security Feature Bypass VulnerabilityNoNo8
CVE-2024-37986Secure Boot Security Feature Bypass VulnerabilityNoNo8
CVE-2024-37987Secure Boot Security Feature Bypass VulnerabilityNoNo8
CVE-2024-37971Secure Boot Security Feature Bypass VulnerabilityNoNo8
CVE-2024-37972Secure Boot Security Feature Bypass VulnerabilityNoNo8
CVE-2024-37975Secure Boot Security Feature Bypass VulnerabilityNoNo8
CVE-2024-37988Secure Boot Security Feature Bypass VulnerabilityNoNo8
CVE-2024-37989Secure Boot Security Feature Bypass VulnerabilityNoNo8
CVE-2024-38010Secure Boot Security Feature Bypass VulnerabilityNoNo8
CVE-2024-38011Secure Boot Security Feature Bypass VulnerabilityNoNo8
CVE-2024-38050Windows Workstation Service Elevation of Privilege VulnerabilityNoNo7.8
CVE-2024-38066Windows Win32k Elevation of Privilege VulnerabilityNoNo7.8
CVE-2024-30079Windows Remote Access Connection Manager Elevation of Privilege VulnerabilityNoNo7.8
CVE-2024-38070Windows LockDown Policy (WLDP) Security Feature Bypass VulnerabilityNoNo7.8
CVE-2024-38051Windows Graphics Component Remote Code Execution VulnerabilityNoNo7.8
CVE-2024-38085Windows Graphics Component Elevation of Privilege VulnerabilityNoNo7.8
CVE-2024-38079Windows Graphics Component Elevation of Privilege VulnerabilityNoNo7.8
CVE-2024-38034Windows Filtering Platform Elevation of Privilege VulnerabilityNoNo7.8
CVE-2024-38054Kernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityNoNo7.8
CVE-2024-38052Kernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityNoNo7.8
CVE-2024-38057Kernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityNoNo7.8
CVE-2024-39684Github: CVE-2024-39684 TenCent RapidJSON Elevation of Privilege VulnerabilityNoNo7.8
CVE-2024-38064Windows TCP/IP Information Disclosure VulnerabilityNoNo7.5
CVE-2024-38071Windows Remote Desktop Licensing Service Denial of Service VulnerabilityNoNo7.5
CVE-2024-38073Windows Remote Desktop Licensing Service Denial of Service VulnerabilityNoNo7.5
CVE-2024-38015Windows Remote Desktop Gateway (RD Gateway) Denial of Service VulnerabilityNoNo7.5
CVE-2024-38031Windows Online Certificate Status Protocol (OCSP) Server Denial of Service VulnerabilityNoNo7.5
CVE-2024-38067Windows Online Certificate Status Protocol (OCSP) Server Denial of Service VulnerabilityNoNo7.5
CVE-2024-38068Windows Online Certificate Status Protocol (OCSP) Server Denial of Service VulnerabilityNoNo7.5
CVE-2024-38112Windows MSHTML Platform Spoofing VulnerabilityYesNo7.5
CVE-2024-30098Windows Cryptographic Services Security Feature Bypass VulnerabilityNoNo7.5
CVE-2024-38091Microsoft WS-Discovery Denial of Service VulnerabilityNoNo7.5
CVE-2024-38061DCOM Remote Cross-Session Activation Elevation of Privilege VulnerabilityNoNo7.5
CVE-2024-3596CERT/CC: CVE-2024-3596 RADIUS Protocol Spoofing VulnerabilityNoNo7.5
CVE-2024-38033PowerShell Elevation of Privilege VulnerabilityNoNo7.3
CVE-2024-38025Microsoft Windows Performance Data Helper Library Remote Code Execution VulnerabilityNoNo7.2
CVE-2024-38019Microsoft Windows Performance Data Helper Library Remote Code Execution VulnerabilityNoNo7.2
CVE-2024-38028Microsoft Windows Performance Data Helper Library Remote Code Execution VulnerabilityNoNo7.2
CVE-2024-38044DHCP Server Service Remote Code Execution VulnerabilityNoNo7.2
CVE-2024-30081Windows NTLM Spoofing VulnerabilityNoNo7.1
CVE-2024-38022Windows Image Acquisition Elevation of Privilege VulnerabilityNoNo7
CVE-2024-38065Secure Boot Security Feature Bypass VulnerabilityNoNo6.8
CVE-2024-38058BitLocker Security Feature Bypass VulnerabilityNoNo6.8
CVE-2024-38013Microsoft Windows Server Backup Elevation of Privilege VulnerabilityNoNo6.7
CVE-2024-38049Windows Distributed Transaction Coordinator Remote Code Execution VulnerabilityNoNo6.6
CVE-2024-38030Windows Themes Spoofing VulnerabilityNoNo6.5
CVE-2024-38048Windows Network Driver Interface Specification (NDIS) Denial of Service VulnerabilityNoNo6.5
CVE-2024-38027Windows Line Printer Daemon Service Denial of Service VulnerabilityNoNo6.5
CVE-2024-38102Windows Layer-2 Bridge Network Driver Denial of Service VulnerabilityNoNo6.5
CVE-2024-38101Windows Layer-2 Bridge Network Driver Denial of Service VulnerabilityNoNo6.5
CVE-2024-38105Windows Layer-2 Bridge Network Driver Denial of Service VulnerabilityNoNo6.5
CVE-2024-38099Windows Remote Desktop Licensing Service Denial of Service VulnerabilityNoNo5.9
CVE-2024-38055Microsoft Windows Codecs Library Information Disclosure VulnerabilityNoNo5.5
CVE-2024-38056Microsoft Windows Codecs Library Information Disclosure VulnerabilityNoNo5.5
CVE-2024-38017Microsoft Message Queuing Information Disclosure VulnerabilityNoNo5.5
CVE-2024-35270Windows iSCSI Service Denial of Service VulnerabilityNoNo5.3
CVE-2024-30071Windows Remote Access Connection Manager Information Disclosure VulnerabilityNoNo4.7

Microsoft Dynamics vulnerabilities





















CVETitleExploited?Publicly disclosed?CVSSv3 base score
CVE-2024-30061Microsoft Dynamics 365 (On-Premises) Information Disclosure VulnerabilityNoNo7.3

Microsoft Office vulnerabilities
























































CVETitleExploited?Publicly disclosed?CVSSv3 base score
CVE-2024-38021Microsoft Office Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-32987Microsoft SharePoint Server Information Disclosure VulnerabilityNoNo7.5
CVE-2024-38023Microsoft SharePoint Server Remote Code Execution VulnerabilityNoNo7.2
CVE-2024-38024Microsoft SharePoint Server Remote Code Execution VulnerabilityNoNo7.2
CVE-2024-38094Microsoft SharePoint Remote Code Execution VulnerabilityNoNo7.2
CVE-2024-38020Microsoft Outlook Spoofing VulnerabilityNoNo6.5

SQL Server vulnerabilities
























































































































































































































































































CVETitleExploited?Publicly disclosed?CVSSv3 base score
CVE-2024-38088SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-38087SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-21332SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-21333SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-21335SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-21373SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-21398SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-21414SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-21415SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-21428SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-37318SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-37332SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-37331SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-35271SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-35272SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-20701SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-21303SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-21308SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-21317SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-21331SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-21425SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-37319SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-37320SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-37321SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-37322SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-37323SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-37324SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-21449SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-37326SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-37327SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-37328SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-37329SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-37330SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-37333SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-37336SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-28928SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-35256SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-37334Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityNoNo8.8

System Center vulnerabilities





















CVETitleExploited?Publicly disclosed?CVSSv3 base score
CVE-2024-38089Microsoft Defender for IoT Elevation of Privilege VulnerabilityNoNo9.1

Windows vulnerabilities


























































































































































CVETitleExploited?Publicly disclosed?CVSSv3 base score
CVE-2024-38076Windows Remote Desktop Licensing Service Remote Code Execution VulnerabilityNoNo9.8
CVE-2024-21417Windows Text Services Framework Elevation of Privilege VulnerabilityNoNo8.8
CVE-2024-30013Windows MultiPoint Services Remote Code Execution VulnerabilityNoNo8.8
CVE-2024-37981Secure Boot Security Feature Bypass VulnerabilityNoNo8
CVE-2024-37977Secure Boot Security Feature Bypass VulnerabilityNoNo8
CVE-2024-37978Secure Boot Security Feature Bypass VulnerabilityNoNo8
CVE-2024-38062Windows Kernel-Mode Driver Elevation of Privilege VulnerabilityNoNo7.8
CVE-2024-38080Windows Hyper-V Elevation of Privilege VulnerabilityYesNo7.8
CVE-2024-38100Windows File Explorer Elevation of Privilege VulnerabilityNoNo7.8
CVE-2024-38059Win32k Elevation of Privilege VulnerabilityNoNo7.8
CVE-2024-38043PowerShell Elevation of Privilege VulnerabilityNoNo7.8
CVE-2024-38047PowerShell Elevation of Privilege VulnerabilityNoNo7.8
CVE-2024-38517Github: CVE-2024-38517 TenCent RapidJSON Elevation of Privilege VulnerabilityNoNo7.8
CVE-2024-38078Xbox Wireless Adapter Remote Code Execution VulnerabilityNoNo7.5
CVE-2024-38072Windows Remote Desktop Licensing Service Denial of Service VulnerabilityNoNo7.5
CVE-2024-38032Microsoft Xbox Remote Code Execution VulnerabilityNoNo7.1
CVE-2024-38069Windows Enroll Engine Security Feature Bypass VulnerabilityNoNo7
CVE-2024-26184Secure Boot Security Feature Bypass VulnerabilityNoNo6.8
CVE-2024-37985Arm: CVE-2024-37985 Systematic Identification and Characterization of Proprietary PrefetchersNoYes5.9
CVE-2024-38041Windows Kernel Information Disclosure VulnerabilityNoNo5.5




Source: Rapid7
Source Link: https://blog.rapid7.com/2024/07/09/patch-tuesday-july-2024/


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2024 - National Cyber Warfare Foundation - All rights reserved worldwide.