Quantcast
Channel: Tenable Blog
Viewing all articles
Browse latest Browse all 1935

Microsoft’s March 2024 Patch Tuesday Addresses 59 CVEs (CVE-2024-21407)

$
0
0
  1. 2Critical
  2. 57Important
  3. 0Moderate
  4. 0Low

Microsoft addresses 59 CVEs in its March2024 Patch Tuesday release with no zero-day or publicly disclosed vulnerabilities.

Microsoft patched 59 CVEs in its March 2024 Patch Tuesday release, with 2 rated critical and 57 rated as important.

This month’s update includes patches for:

  • .NET
  • Azure Data Studio
  • Azure SDK
  • Microsoft Authenticator
  • Microsoft Azure Kubernetes Service
  • Microsoft Dynamics
  • Microsoft Edge for Android
  • Microsoft Exchange Server
  • Microsoft Graphics Component
  • Microsoft Intune
  • Microsoft Office
  • Microsoft Office SharePoint
  • Microsoft QUIC
  • Microsoft Teams for Android
  • Microsoft WDAC ODBC Driver
  • Microsoft WDAC OLE DB provider for SQL
  • Microsoft Windows SCSI Class System File
  • Open Management Infrastructure
  • Outlook for Android
  • Role: Windows Hyper-V
  • Skype for Consumer
  • Software for Open Networking in the Cloud (SONiC)
  • SQL Server
  • Visual Studio Code
  • Windows AllJoyn API
  • Windows Cloud Files Mini Filter Driver
  • Windows Composite Image File System
  • Windows Compressed Folder
  • Windows Defender
  • Windows Error Reporting
  • Windows Hypervisor-Protected Code Integrity
  • Windows Installer
  • Windows Kerberos
  • Windows Kernel
  • Windows NTFS
  • Windows ODBC Driver
  • Windows OLE
  • Windows Print Spooler Components
  • Windows Standards-Based Storage Management Service
  • Windows Telephony Server
  • Windows Update Stack
  • Windows USB Hub Driver
  • Windows USB Print Driver
  • Windows USB Serial Driver

Elevation of privilege (EoP) vulnerabilities accounted for 40.7% of the vulnerabilities patched this month, followed by Remote code execution (RCE) at 30.5%.

Important

CVE-2024-21334 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

CVE-2024-21334 is a RCE affecting the open-source Open Management Infrastructure (OMI) management server. It was assigned a CVSSv3 score of 9.8 and is rated important. To exploit this vulnerability, a remote unauthenticated attacker could use a specially crafted request to trigger a use-after-free vulnerability. In addition, OMI received another patch this month, CVE-2024-21330 to address an EoP vulnerability.

In 2022, Microsoft patched two EoP flaws in OMI (CVE-2022-33640 and CVE-2022-29149), as well as an information disclosure vulnerability (CVE-2023-36043) in November 2023. This RCE is a first for OMI and despite the critical CVSS score, Microsoft rates this vulnerability as “Exploitation Less Likely” according to the Microsoft Exploitability Index.

Critical

CVE-2024-21407 | Windows Hyper-V Remote Code Execution Vulnerability

CVE-2024-21407 is a RCE vulnerability in Windows Hyper-V. This vulnerability was assigned a CVSSv3 score of 8.1 and is rated critical. Successful exploitation of this vulnerability requires that an attacker be authenticated and gather information about the target environment in order to craft their exploit. While the attack complexity is high, exploitation could result in code execution on the host server.

Including this month, nine RCE vulnerabilities affecting Windows Hyper-V have been disclosed since 2022, with seven of them rated as Critical. While these flaws generally are more difficult to exploit, successfully breaking out of a VM and executing code on the host is a significant risk and these flaws should be remediated quickly to avoid any potential misuse.

Important

CVE-2024-21433 | Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2024-21433 is an EoP vulnerability in Windows Print Spooler. This vulnerability is rated as ”Exploitation More Likely,” and was assigned a CVSSv3 score of 7.0. Exploitation of this vulnerability would require an attacker to win a race condition which could grant the attacker SYSTEM privileges.

Over the last few years, we’ve seen a sharp decline in the number of Print Spooler related vulnerabilities patched as part of Patch Tuesday since the disclosure of CVE-2021-34527, the original PrintNightmare vulnerability and the torrent of Print Spooler vulnerabilities that followed. In 2023, there were only four Print Spooler related bugs patched, including CVE-2023-35325, an information disclosure vulnerability in Print Spooler disclosed in July 2023, as well as three Print Spooler EoP vulnerabilities disclosed in January 2023. In 2022, there were 35 Print Spooler related vulnerabilities patched as part of Patch Tuesday, with the biggest concentration of disclosures occurring in April 2022, with 15 Print Spooler vulnerabilities patched.

CVEDescriptionPatch Tuesday Release
CVE-2023-35325Windows Print Spooler Information Disclosure VulnerabilityJul 2023
CVE-2023-21678Windows Print Spooler Elevation of Privilege VulnerabilityJan 2023
CVE-2023-21765Windows Print Spooler Elevation of Privilege VulnerabilityJan 2023
CVE-2023-21760Windows Print Spooler Elevation of Privilege VulnerabilityJan 2023
CVE-2022-44681Windows Print Spooler Elevation of Privilege VulnerabilityDec 2022
CVE-2022-44678Windows Print Spooler Elevation of Privilege VulnerabilityDec 2022
CVE-2022-41073Windows Print Spooler Elevation of Privilege VulnerabilityNov 2022
CVE-2022-38028Windows Print Spooler Elevation of Privilege VulnerabilityOct 2022
CVE-2022-38005Windows Print Spooler Elevation of Privilege VulnerabilitySep 2022
CVE-2022-35755Windows Print Spooler Elevation of Privilege VulnerabilityAug 2022
CVE-2022-35793Windows Print Spooler Elevation of Privilege VulnerabilityAug 2022
CVE-2022-22022Windows Print Spooler Elevation of Privilege VulnerabilityJul 2022
CVE-2022-22041Windows Print Spooler Elevation of Privilege VulnerabilityJul 2022
CVE-2022-30206Windows Print Spooler Elevation of Privilege VulnerabilityJul 2022
CVE-2022-30226Windows Print Spooler Elevation of Privilege VulnerabilityJul 2022
CVE-2022-29104Windows Print Spooler Elevation of Privilege VulnerabilityMay 2022
CVE-2022-29132Windows Print Spooler Elevation of Privilege VulnerabilityMay 2022
CVE-2022-29114Windows Print Spooler Information Disclosure VulnerabilityMay 2022
CVE-2022-29140Windows Print Spooler Information Disclosure VulnerabilityMay 2022
CVE-2022-26796Windows Print Spooler Elevation of Privilege VulnerabilityApr 2022
CVE-2022-26802Windows Print Spooler Elevation of Privilege VulnerabilityApr 2022
CVE-2022-26795Windows Print Spooler Elevation of Privilege VulnerabilityApr 2022
CVE-2022-26801Windows Print Spooler Elevation of Privilege VulnerabilityApr 2022
CVE-2022-26791Windows Print Spooler Elevation of Privilege VulnerabilityApr 2022
CVE-2022-26790Windows Print Spooler Elevation of Privilege VulnerabilityApr 2022
CVE-2022-26794Windows Print Spooler Elevation of Privilege VulnerabilityApr 2022
CVE-2022-26793Windows Print Spooler Elevation of Privilege VulnerabilityApr 2022
CVE-2022-26786Windows Print Spooler Elevation of Privilege VulnerabilityApr 2022
CVE-2022-26789Windows Print Spooler Elevation of Privilege VulnerabilityApr 2022
CVE-2022-26797Windows Print Spooler Elevation of Privilege VulnerabilityApr 2022
CVE-2022-26798Windows Print Spooler Elevation of Privilege VulnerabilityApr 2022
CVE-2022-26792Windows Print Spooler Elevation of Privilege VulnerabilityApr 2022
CVE-2022-26787Windows Print Spooler Elevation of Privilege VulnerabilityApr 2022
CVE-2022-26803Windows Print Spooler Elevation of Privilege VulnerabilityApr 2022
CVE-2022-23284Windows Print Spooler Elevation of Privilege VulnerabilityMar 2022
CVE-2022-22718Windows Print Spooler Elevation of Privilege VulnerabilityFeb 2022
CVE-2022-21999Windows Print Spooler Elevation of Privilege VulnerabilityFeb 2022
CVE-2022-21997Windows Print Spooler Elevation of Privilege VulnerabilityFeb 2022
CVE-2022-22717Windows Print Spooler Elevation of Privilege VulnerabilityFeb 2022
Important

CVE-2024-21443, CVE-2024-26173, CVE-2024-26176, CVE-2024-26178 and CVE-2024-26182 | Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-21443, CVE-2024-26173, CVE-2024-26176, CVE-2024-26178 and CVE-2024-26182 are EoP vulnerabilities affecting the Windows Kernel. These vulnerabilities are all rated as important, and each was assigned a CVSSv3 score of 7.8 with the exception of CVE-2024-21443 which was scored as 7.3. CVE-2024-26182 was the only Windows Kernel EoP rated as “Exploitation More Likely.” Successful exploitation of these vulnerabilities could lead to an attacker gaining SYSTEM privileges.

Important

CVE-2024-21441, CVE-2024-21444, CVE-2024-21450, CVE-2024-26161 and CVE-2024-26166 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

CVE-2024-21441, CVE-2024-21444, CVE-2024-21450, CVE-2024-26161 and CVE-2024-26166 are RCE vulnerabilities affecting the Microsoft WDAC OLE DB provider for SQL Server. These vulnerabilities are rated as important, and were assigned CVSSV3 scores of 8.8. Successful exploitation requires an authenticated user to be enticed to connect to a malicious SQL database. Once a connection is made, specially crafted replies can be sent to the client in order to exploit the vulnerability and allow the execution of arbitrary code.

Tenable Solutions

A list of all the plugins released for Tenable’s March 2024 Patch Tuesday update can be found here. As always, we recommend patching systems as soon as possible and regularly scanning your environment to identify those systems yet to be patched.

For more specific guidance on best practices for vulnerability assessments, please refer to our blog post on How to Perform Efficient Vulnerability Assessments with Tenable.

Get more information

Join Tenable's Security Response Team on the Tenable Community.

Learn more about https://www.tenable.com/products/tenable-one">Tenable One, the Exposure Management Platform for the modern attack surface.


Viewing all articles
Browse latest Browse all 1935

Trending Articles