Target Industry
Indiscriminate, opportunistic targeting.
Overview
Microsoft September 2024 Patch Tuesday addressed a total of 79 security vulnerabilities, four of which have been classified as actively exploited and one as a publicly disclosed zero-day vulnerability. A summary of the highlighted vulnerabilities has been outlined below:
- 30 Elevation of Privilege Vulnerabilities
- Four Security Feature Bypass Vulnerabilities
- 23 Remote Code Execution (RCE) Vulnerabilities
- 11 Information Disclosure Vulnerabilities
- Eight Denial of Service Vulnerabilities
- Three Spoofing Vulnerabilities.
Today’s first critical zero-day vulnerability is CVE-2024-43491 (CVSSv3.1 base score 9.8) – Microsoft Windows Update Remote Code Execution Vulnerability. Microsoft fixed an RCE vulnerability caused by a regression in the Windows Servicing Stack that has rolled back fixes for some vulnerabilities affecting Optional Components on Windows 10 version 1507. Microsoft explains that an attacker could exploit these previously mitigated vulnerabilities on Windows 10, version 1507 (Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB) systems that have installed the Windows security update released on 12th March 2024 — KB5035858 (OS Build 10240.20526) or other updates released until August 2024.
All later versions of Windows 10 are not impacted and this servicing stack vulnerability is addressed by installing the September 2024 Servicing stack update (SSU KB5043936) AND the September 2024 Windows security update (KB5043083), in that order. Although Windows 10 version 1507 reached the end of support (EOS) on 9th May 2017 for devices running the Pro, Home, Enterprise, Education, and Enterprise IoT editions, both Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB editions are still under support.
The second important zero-day is CVE-2024-38014 (CVSSv3.1 base score 7.8) – Windows Installer Elevation of Privilege Vulnerability. Successful exploitation can grant the attacker SYSTEM privileges and despite the attack vector being local, both attack complexity and privilege requirements are also low, as well as no user interaction is required. This vulnerability was discovered by Michael Baer with SEC Consult Vulnerability Lab with no further details available yet.
The next zero-day vulnerability is CVE-2024-38226 (CVSSv3.1 base score 7.3) – Microsoft Publisher Security Feature Bypass Vulnerability. Successful exploitation could allow an attacker to bypass Office macro policies used to block untrusted or malicious files. Microsoft confirmed that Preview Pane is not an attack vector and specified that attack would be carried out locally by a user with authentication to the targeted system. In this case the attacker would rely on social engineering, tricking the user into downloading and opening a specially crafted file from a website which could lead to a local attack on the victim computer. Attack complexity is considered to be low and no further details were provided.
The last important fixed zero-day in this update is CVE-2024-38217 (CVSSv3.1 base score 5.4) – Windows Mark of the Web Security Feature Bypass Vulnerability. It was first publicly disclosed last month by Joe Desimone of Elastic Security, where they reported the technique called “LNK stomping”, which involves explorer.exe overwriting an existing LNK file. Successful exploitation can occur when a targeted user downloads and opens a malicious file hosted on an attacker-controlled server that would evade Mark of the Web (MOTW) defences and security features such as SmartScreen Application Reputation security check and/or the legacy Windows Attachment Services security prompt.
Impact
We have assessed that successful exploitation of the vulnerabilities outlined within the September 2024 Microsoft Patch Tuesday disclosure will result in the total loss of confidentiality, integrity, and availability of data within target systems.
Vulnerability Detection
Security patches for these vulnerabilities have been released by Microsoft. Previous product versions therefore remain vulnerable to potential exploitation.
Affected Products
A full list of the affected products pertaining to the September 2024 Patch Tuesday can be found on the Microsoft September 2024 Security Update page.
Containment, Mitigations & Remediations
It is strongly recommended that the relevant security patches are applied to the respective Microsoft products as soon as possible. The patches can be found directly at the Microsoft Patch Tuesday June 2024 Security Update page.
Indicators of Compromise
No specific Indicators of Compromise (IoCs) are available currently.
Threat Landscape
Last month, Microsoft published remediations for 89 security flaws within the August 2024 Patch Tuesday release, comprised of six actively exploited and three publicly disclosed zero-days. Microsoft fixed eight critical vulnerabilities, which included elevation of privileges, RCE, and information disclosure.
Moving into the September disclosure, RCE and privilege escalation vulnerabilities continue to be leading attack vectors. Overall, the September 2024 Patch Tuesday disclosure resulted in the release of a lesser number of vulnerabilities this month with only one zero-day publicly disclosed.
Threat Group
No attribution to specific threat actors or groups has been identified at the time of writing.
Mitre Methodologies
Tactics:
- TA0001: Initial Access
- TA0002: Execution
- TA0003: Persistence
- TA0004: Privilege Escalation
- TA0005: Defense Evasion
- TA0040: Impact
Common Weakness Enumeration (CWE)
Further Information













