Target Industry 

Indiscriminate, opportunistic targeting. 

Overview  

Microsoft June 2024 Patch Tuesday: five security flaws were patched as part of 51 total security vulnerabilities addressed by Microsoft. One of these has been classified as a publicly disclosed zero-day vulnerability, one as a critical vulnerability and the other as high. A summary of the highlighted vulnerabilities has been outlined below. 

First up is CVE-2024-30080 (CVSSv3.1 score 9.8), a critical remote code execution (RCE) vulnerability affecting all current versions of Windows. Threat actors would send a specially crafted malicious packet to a Microsoft Messaging Queue (MSMQ) server, which then results in RCE on the server side. Although it has not been exploited in the wild, this flaw has a high CVSSv3 base score due to the network attack vector, low attack complexity, and lack of required privileges. The main mitigation involves checking the configuration of Windows message queuing service and ensure it is disabled. The Microsoft advisory provides almost no detail about the nature of the exploit itself. 

The next two patches involved are related to Microsoft Office Remote Code Execution. CVE-2024-30101 (CVSSv3.1 score 7.5) exploitation involves a user opening a malicious email with an affected version of Microsoft Outlook and then performing specific actions to trigger the vulnerability. Although Preview Pane is an attack vector, additional user interaction is necessary, requiring an attacker to win a race condition. On the other hand [CVE-2024-30104 (CVSSv3.1 score 7.8) does not have Preview Pane as an attack vector and entirely depends on the user opening a malicious file. 

SharePoint received a patch this month regarding CVE-2024-30100 (CVSSv3.1 score: 7.8), another RCE vulnerability with no detailed breakdown, with the only information stating that the weakness is CWE-426: Untrusted Search Path, which could lead to an elevation of privilege. The attack complexity is low, attack vector is local and exploitation requires user interaction. 

The last one, CVE-2023-50868 (CVSSv3.1 score: 7.5), was created by MITRE on behalf of DNSSEC and involves the flaw in DNSSEC validation, which can lead to denial of service for legitimate users. In this zero-day vulnerability, an attacker could exploit standard DNSSEC protocols intended for DNS integrity by using excessive CPU resources on a resolver. If the resolver uses NSEC3 to respond to the request, it will perform thousands of iterations of a hash function allowing the exploit to take place. Windows has provided necessary patching for all the current versions of Windows Server. 

Impact  

We have assessed that successful exploitation of the vulnerabilities outlined within the June 2024 Microsoft Patch Tuesday disclosure will result in the total loss of confidentiality, integrity, and availability of data within target systems.  

Vulnerability Detection 

Security patches for the vulnerabilities reported on have been released by Microsoft. Previous product versions therefore remain vulnerable to potential exploitation. 

Affected Products 

A full list of the affected products pertaining to the June 2024 Patch Tuesday can be found on the Microsoft June 2024 Security Update page. 

Containment, Mitigations & Remediations 

It is strongly recommended that the relevant security patches are applied to the respective Microsoft products as soon as possible. The patches can be found directly at the Microsoft Patch Tuesday June 2024 Security Guide. 

Indicators of Compromise 

No specific Indicators of Compromise (IoCs) are available currently. 

Threat Landscape 

Last month, Microsoft published remediations for 61 security flaws within the May 2024 Patch Tuesday release, including three publicly disclosed zero days and one critical vulnerability, a Microsoft SharePoint Server Remote Code Execution Vulnerability CVE-2024-30044.  

Moving into the June disclosure, RCE and privilege escalation vulnerabilities continue to be leading attack vectors. Overall, the June 2024 Patch Tuesday disclosure resulted in the release of fewer vulnerabilities this month with only one zero-day disclosed. 

Threat Group 

No attribution to specific threat actors or groups has been identified at the time of writing.  

Mitre Methodologies 

Tactics: 

  • TA0004 – Privilege Escalation 

 Common Weakness Enumeration (CWE) 

  • CVE-2024-30080, CVE-2024-30101: CWE-416 Use After Free – CVE-2024-30101: CWE-77 – Improper Neutralization of Special Elements used in a Command (‘Command Injection’) 
  • CVE-2024-30104: CWE- 59 – Improper Link Resolution Before File Access (‘Link Following’) 
  • CVE-2024-30100: CWE- 426 – Untrusted Search Path 
  • CVE-2023-50868: No known weakness to date. 

Further Information 

Microsoft June 2024 Patch Tuesday Security Update 

 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content