Target Industry 

Indiscriminate, opportunistic targeting. 

Overview  

Microsoft’s August 2024 Patch Tuesday addressed 88 vulnerabilities, six of which have been confirmed as actively exploited in the wild. A summary of the highlighted vulnerabilities is outlined below. 

Firstly, there’s a Windows WinSock zero-day elevation of privilege (EoP), tracked as CVE-2024-38193 (CVSS Score: 7.8). This vulnerability has been exploited in the wild, has a low attack complexity, doesn’t require user interaction, and doesn’t require high privileges. Successful exploitation provides threat actors with SYSTEM privileges. 

Microsoft also remediated a Microsoft Office zero-day spoofing vulnerability, tracked as CVE-2024-38200 (CVSS Score: 9.1). This spoofing vulnerability affects Microsoft Office 2016, Office LTSC, Office 2019, and 365 Apps for Enterprise, in both 32-bit and 64-bit editions. User interaction is required for compromise, with the threat actor having to lure victims into interacting with a malicious file. 

A remote code execution (RCE) Microsoft Project zero-day vulnerability, CVE-2024-38189 (CVSSv3.1 score: 8.8), was also included. To successfully exploit this vulnerability, the attacker must convince the user to open a malicious file. This is only possible where the “Block macros from running in Office files from the Internet” policy is disabled, and the “VBA Macro Notification Settings” are set to a low enough level. 

Microsoft remediated an Edge Internet Explorer zero-day EoP, tracked as CVE-2024-38178 (CVSS Score: 7.5). Although this vulnerability is already known to be exploited in the wild and all current versions of Windows are affected, it requires the attacker to not only convince a user to click a malicious link, but also to first prepare the target asset so that it uses Edge in Internet Explorer Mode. 

Microsoft also disclosed a Windows Line Printer Daemon zero-day RCE vulnerability, tracked as CVE-2024-38199 (CVSS Score: 9.8). To exploit this vulnerability, an attacker needs to send a malicious print task to a shared vulnerable Windows Line Printer Daemon service across the network. While Windows products newer than Server 2012 don’t have this vulnerable component by default, patches are available for Windows Server 2008 SP2, Server 2022 23H2, and everything in between. 

Microsoft also remediated a Windows SmartScreen zero-day MotW security bypass vulnerability, tracked as CVE-2024-38213 (CVSS Score: 6.5). To successfully exploit this vulnerability, an attacker will need to convince a user to open a malicious file. This vulnerability affects all current Windows products. 

An EoP Windows Kernel zero-day vulnerability, CVE-2024-38106 (CVSSv3.1 score: 7.0), was also included. Successful exploitation of this vulnerability provides threat actors with SYSTEM privileges. 

The final highlight of the August 2024 Patch Tuesday release is the discovery of a Windows Power Dependency Coordinator EoP zero-day vulnerability. Tracked as CVE-2024-38107, it has been assigned a CVSS 3.1 severity score of 7.8. This vulnerability requires no user interaction, has low attack complexity, requires low privileges, and successful exploitation provides threat actors with SYSTEM privileges. 

Impact  

We have assessed that successful exploitation of the vulnerabilities outlined within the August 2024 Microsoft Patch Tuesday disclosure will likely result in the total loss of confidentiality, integrity, and availability of data within target systems. 

Vulnerability Detection 

Security patches for the vulnerabilities reported on have been released by Microsoft. Previous product versions therefore remain vulnerable to potential exploitation. 

Affected Products 

A full list of the affected products pertaining to the August 2024 Patch Tuesday can be found on the Microsoft August 2024 Security Update page. 

Containment, Mitigations & Remediations 

It is strongly recommended that the relevant security patches are applied to the respective Microsoft products as soon as possible. The patches can be found directly on the Microsoft August 2024 Security Update page. 

Indicators of Compromise 

No specific Indicators of Compromise (IoCs) are available currently. 

Threat Landscape 

Last month, Microsoft published remediations for 142 security flaws within the July 2024 Patch Tuesday release, including two zero-days and around 56 RCE flaws. Moving into the August disclosure, RCE and privilege escalation vulnerabilities continue to be leading attack vectors, accounting for 41% and 34% of disclosed issues, respectively. Overall, the August 2024 Patch Tuesday disclosure resulted in the release of a significantly higher number of vulnerabilities, a stark contrast to the low number of flaw disclosures in recent months. 

Threat Group 

No attribution to specific threat actors or groups has been identified at the time of writing. 

Mitre Methodologies 

Tactics 

TA0004: Privilege Escalation 

TA0005: Defense Evasion 

TA0002: Execution 

TA0001: Initial Access 

Common Weakness Enumeration (CWE) 

CWE-416: Use After Free 

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor 

CWE-20: Improper Input Validation 

CWE-843: Access of Resource Using Incompatible Type (‘Type Confusion’) 

CWE-693: Protection Mechanism Failure 

CWE-591: Sensitive Data Storage in Improperly Locked Memory 

Further Information 

Tenable  

Rapid7  

Bleeping Computer  

 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content