Target Industry 

Indiscriminate, opportunistic targeting. 

Overview  

Microsoft September 2024 Patch Tuesday addressed a total of 79 security vulnerabilities, four of which have been classified as actively exploited and one as a publicly disclosed zero-day vulnerability. A summary of the highlighted vulnerabilities has been outlined below:  

  • 30 Elevation of Privilege Vulnerabilities 
  • Four Security Feature Bypass Vulnerabilities 
  • 23 Remote Code Execution (RCE) Vulnerabilities 
  • 11 Information Disclosure Vulnerabilities 
  • Eight Denial of Service Vulnerabilities 
  • Three Spoofing Vulnerabilities. 

Today’s first critical zero-day vulnerability is CVE-2024-43491 (CVSSv3.1 base score 9.8) – Microsoft Windows Update Remote Code Execution Vulnerability. Microsoft fixed an RCE vulnerability caused by a regression in the Windows Servicing Stack that has rolled back fixes for some vulnerabilities affecting Optional Components on Windows 10 version 1507. Microsoft explains that an attacker could exploit these previously mitigated vulnerabilities on Windows 10, version 1507 (Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB) systems that have installed the Windows security update released on 12th March 2024 — KB5035858 (OS Build 10240.20526) or other updates released until August 2024. 

All later versions of Windows 10 are not impacted and this servicing stack vulnerability is addressed by installing the September 2024 Servicing stack update (SSU KB5043936) AND the September 2024 Windows security update (KB5043083), in that order. Although Windows 10 version 1507 reached the end of support (EOS) on 9th May 2017 for devices running the Pro, Home, Enterprise, Education, and Enterprise IoT editions, both Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB editions are still under support. 

The second important zero-day is CVE-2024-38014 (CVSSv3.1 base score 7.8) – Windows Installer Elevation of Privilege Vulnerability. Successful exploitation can grant the attacker SYSTEM privileges and despite the attack vector being local, both attack complexity and privilege requirements are also low, as well as no user interaction is required. This vulnerability was discovered by Michael Baer with SEC Consult Vulnerability Lab with no further details available yet. 

The next zero-day vulnerability is CVE-2024-38226 (CVSSv3.1 base score 7.3) – Microsoft Publisher Security Feature Bypass Vulnerability. Successful exploitation could allow an attacker to bypass Office macro policies used to block untrusted or malicious files. Microsoft confirmed that Preview Pane is not an attack vector and specified that attack would be carried out locally by a user with authentication to the targeted system. In this case the attacker would rely on social engineering, tricking the user into downloading and opening a specially crafted file from a website which could lead to a local attack on the victim computer. Attack complexity is considered to be low and no further details were provided. 

The last important fixed zero-day in this update is CVE-2024-38217 (CVSSv3.1 base score 5.4) – Windows Mark of the Web Security Feature Bypass Vulnerability. It was first publicly disclosed last month by Joe Desimone of Elastic Security, where they reported the technique called “LNK stomping”, which involves explorer.exe overwriting an existing LNK file. Successful exploitation can occur when a targeted user downloads and opens a malicious file hosted on an attacker-controlled server that would evade Mark of the Web (MOTW) defences and security features such as SmartScreen Application Reputation security check and/or the legacy Windows Attachment Services security prompt.  

Impact  

We have assessed that successful exploitation of the vulnerabilities outlined within the September 2024 Microsoft Patch Tuesday disclosure will result in the total loss of confidentiality, integrity, and availability of data within target systems.   

Vulnerability Detection 

Security patches for these vulnerabilities have been released by Microsoft. Previous product versions therefore remain vulnerable to potential exploitation.  

Affected Products 

A full list of the affected products pertaining to the September 2024 Patch Tuesday can be found on the Microsoft September 2024 Security Update page. 

Containment, Mitigations & Remediations 

It is strongly recommended that the relevant security patches are applied to the respective Microsoft products as soon as possible. The patches can be found directly at the Microsoft Patch Tuesday June 2024 Security Update page. 

Indicators of Compromise 

No specific Indicators of Compromise (IoCs) are available currently.  

Threat Landscape 

Last month, Microsoft published remediations for 89 security flaws within the August 2024 Patch Tuesday release, comprised of six actively exploited and three publicly disclosed zero-days. Microsoft fixed eight critical vulnerabilities, which included elevation of privileges, RCE, and information disclosure. 

Moving into the September disclosure, RCE and privilege escalation vulnerabilities continue to be leading attack vectors. Overall, the September 2024 Patch Tuesday disclosure resulted in the release of a lesser number of vulnerabilities this month with only one zero-day publicly disclosed.  

Threat Group 

No attribution to specific threat actors or groups has been identified at the time of writing.  

 Mitre Methodologies 

Tactics: 

  • TA0004: Privilege Escalation  

 

Common Weakness Enumeration (CWE) 

Further Information 

Rapid7 Patch Tuesday report

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content