Target Industry
Indiscriminate, opportunistic targeting.
Overview
Microsoft’s August 2024 Patch Tuesday addressed 88 vulnerabilities, six of which have been confirmed as actively exploited in the wild. A summary of the highlighted vulnerabilities is outlined below.
Firstly, there’s a Windows WinSock zero-day elevation of privilege (EoP), tracked as CVE-2024-38193 (CVSS Score: 7.8). This vulnerability has been exploited in the wild, has a low attack complexity, doesn’t require user interaction, and doesn’t require high privileges. Successful exploitation provides threat actors with SYSTEM privileges.
Microsoft also remediated a Microsoft Office zero-day spoofing vulnerability, tracked as CVE-2024-38200 (CVSS Score: 9.1). This spoofing vulnerability affects Microsoft Office 2016, Office LTSC, Office 2019, and 365 Apps for Enterprise, in both 32-bit and 64-bit editions. User interaction is required for compromise, with the threat actor having to lure victims into interacting with a malicious file.
A remote code execution (RCE) Microsoft Project zero-day vulnerability, CVE-2024-38189 (CVSSv3.1 score: 8.8), was also included. To successfully exploit this vulnerability, the attacker must convince the user to open a malicious file. This is only possible where the “Block macros from running in Office files from the Internet” policy is disabled, and the “VBA Macro Notification Settings” are set to a low enough level.
Microsoft remediated an Edge Internet Explorer zero-day EoP, tracked as CVE-2024-38178 (CVSS Score: 7.5). Although this vulnerability is already known to be exploited in the wild and all current versions of Windows are affected, it requires the attacker to not only convince a user to click a malicious link, but also to first prepare the target asset so that it uses Edge in Internet Explorer Mode.
Microsoft also disclosed a Windows Line Printer Daemon zero-day RCE vulnerability, tracked as CVE-2024-38199 (CVSS Score: 9.8). To exploit this vulnerability, an attacker needs to send a malicious print task to a shared vulnerable Windows Line Printer Daemon service across the network. While Windows products newer than Server 2012 don’t have this vulnerable component by default, patches are available for Windows Server 2008 SP2, Server 2022 23H2, and everything in between.
Microsoft also remediated a Windows SmartScreen zero-day MotW security bypass vulnerability, tracked as CVE-2024-38213 (CVSS Score: 6.5). To successfully exploit this vulnerability, an attacker will need to convince a user to open a malicious file. This vulnerability affects all current Windows products.
An EoP Windows Kernel zero-day vulnerability, CVE-2024-38106 (CVSSv3.1 score: 7.0), was also included. Successful exploitation of this vulnerability provides threat actors with SYSTEM privileges.
The final highlight of the August 2024 Patch Tuesday release is the discovery of a Windows Power Dependency Coordinator EoP zero-day vulnerability. Tracked as CVE-2024-38107, it has been assigned a CVSS 3.1 severity score of 7.8. This vulnerability requires no user interaction, has low attack complexity, requires low privileges, and successful exploitation provides threat actors with SYSTEM privileges.
Impact
We have assessed that successful exploitation of the vulnerabilities outlined within the August 2024 Microsoft Patch Tuesday disclosure will likely result in the total loss of confidentiality, integrity, and availability of data within target systems.
Vulnerability Detection
Security patches for the vulnerabilities reported on have been released by Microsoft. Previous product versions therefore remain vulnerable to potential exploitation.
Affected Products
A full list of the affected products pertaining to the August 2024 Patch Tuesday can be found on the Microsoft August 2024 Security Update page.
Containment, Mitigations & Remediations
It is strongly recommended that the relevant security patches are applied to the respective Microsoft products as soon as possible. The patches can be found directly on the Microsoft August 2024 Security Update page.
Indicators of Compromise
No specific Indicators of Compromise (IoCs) are available currently.
Threat Landscape
Last month, Microsoft published remediations for 142 security flaws within the July 2024 Patch Tuesday release, including two zero-days and around 56 RCE flaws. Moving into the August disclosure, RCE and privilege escalation vulnerabilities continue to be leading attack vectors, accounting for 41% and 34% of disclosed issues, respectively. Overall, the August 2024 Patch Tuesday disclosure resulted in the release of a significantly higher number of vulnerabilities, a stark contrast to the low number of flaw disclosures in recent months.
Threat Group
No attribution to specific threat actors or groups has been identified at the time of writing.
Mitre Methodologies
Tactics
– TA0004: Privilege Escalation
– TA0005: Defense Evasion
– TA0002: Execution
– TA0001: Initial Access
Common Weakness Enumeration (CWE)
– CWE-416: Use After Free
– CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
– CWE-20: Improper Input Validation
– CWE-843: Access of Resource Using Incompatible Type (‘Type Confusion’)
– CWE-693: Protection Mechanism Failure
– CWE-591: Sensitive Data Storage in Improperly Locked Memory
Further Information













