Headlines

Microsoft issued patches for 91 CVE-rated vulnerabilities.

Of these, two are listed as being actively exploited: HTLM Hash Disclosure vulnerability and Windows Task Scheduler Elevation of Privilege.

A further two vulnerabilities are listed as publicly disclosed: Microsoft Exchange Server Spoofing Vulnerability and Active Directory Certificate Services Elevation of Privilege Vulnerability

Quorum Cyber Recommendations

Patching should be completed within your regular cycles and without delay. We do not at this time recommend expedited patching.

Microsoft Release Notes

November 2024 Security Updates – Release Notes – Security Update Guide – Microsoft

Key Vulnerability Details

TitleWindows Task Scheduler Elevation of Privilege Vulnerability
CVECVE-2024-49039
CVSS8.8
Reason for ConcernZero day with public exploit. Successful exploitation of this vulnerability could allow an attacker with low-level access to elevate their privileges on the system. This could potentially lead to full system compromise, as the attacker could gain the ability to execute arbitrary code with high-level privileges, access sensitive information, modify system configurations, and disrupt system availability.
Mitigations and other FactorsLocal access to a target device is required, plus to exploit this vulnerability an authenticated attacker would need to run a specially crafted application on the target system to elevate their privileges to a Medium Integrity Level.
CommentaryMicrosoft has not released details on how the exploit took place or who was responsible. Given that local access is required and user credentials are required for exploitation, we do not consider this to be worthy of expedited patching.
Threat Intelligence CommentWhile the CVE-2024-49039 vulnerability is concerning due to its high severity, the requirement for local access and authenticated credentials does provide a layer of mitigation. The fact that this is a zero day with a public exploit means that attackers are actively looking for opportunities to exploit it. The specific threat group(s) behind this has/have not been publicly identified at the time of writing.
LinkCVE-2024-49039 – Security Update Guide – Microsoft – Windows Task Scheduler Elevation of Privilege Vulnerability

 

TitleNTLM Hash Disclosure Spoofing Vulnerability
CVECVE-2024-43451
CVSS6.5
Reason for ConcernZero day with public exploit. If successfully exploited, this vulnerability could lead to a high impact on confidentiality. An attacker could potentially gain unauthorised access to sensitive information, including NTLM hashes. However, there is no impact on integrity or availability of the system.
Mitigations and other FactorsExploitation requires a user to interact with a malicious file, although Microsoft indicates that ‘interaction’ can be defined as a single click or a right click. CVSS-CIA scoring indicates that Integrity and Availability are not affected.
CommentaryLimited information was provided on how or where this was exploited in the wild.  Given a very specific user action is needed for exploitation, we do not consider this to be worthy of expedited patching.
Threat Intelligence CommentCVE-2024-43451 poses a moderate risk due to its impact on confidentiality and the ease of exploitation through minimal user interaction. While the requirement for specific user actions reduces the likelihood of widespread exploitation, the potential for unauthorised access to NTLM hashes should not be underestimated. The specific threat group(s) behind this has/have not been publicly identified at the time of writing.
LinkCVE-2024-43451 – Security Update Guide – Microsoft – NTLM Hash Disclosure Spoofing Vulnerability

 

TitleMicrosoft Exchange Server Spoofing Vulnerability
CVECVE-2024-49040
CVSS7.5
Reason for ConcernPublicly disclosed zero day. An attacker who successfully exploited this vulnerability could spoof the sender’s email address in emails to local recipients.
Mitigations and other FactorsWhile this can make phishing attacks more sophisticated and harder to detect, this vulnerability alone would not put your data at risk.
CommentaryPhishing is always a significant risk to any organisation and while it is important to patch this vulnerability, the main risk associated with it is that phishing will be harder to detect.
Threat Intelligence CommentCVE-2024-49040 represents a significant risk primarily because it makes phishing attacks more sophisticated and difficult to detect. An attacker who successfully exploited this vulnerability could spoof the sender’s email address in emails to local recipients. While the vulnerability itself doesn’t directly compromise data, the potential for high-impact phishing campaigns should not be underestimated. The specific threat group(s) behind this has/have not been publicly identified at the time of writing.
LinkCVE-2024-49040 – Security Update Guide – Microsoft – Microsoft Exchange Server Spoofing Vulnerability

 

TitleActive Directory Certificate Services Elevation of Privilege Vulnerability
CVECVE-2024-49019
CVSS7.8
Reason for ConcernPublicly disclosed zero day. An attacker who successfully exploited this vulnerability could gain domain administrator privileges.
Mitigations and other FactorsSuccessful exploitation of this vulnerability by an attacker requires abuse of the built-in version 1 certificate templates. The attacker needs to authenticate the network before an attack can be attempted.
CommentaryCheck if you have published any certificates created using a version 1 certificate template where the Source of subject name is set to “Supplied in the request” and the Enroll permissions are granted to a broader set of accounts, such as domain users or domain computers. Only this type of cert is vulnerable.
Threat Intelligence Comment CVE-2024-49019 represents a critical risk due to the potential for attackers to gain domain administrator privileges. The ability for an attacker to elevate privileges to such a high level could lead to widespread damage within the domain, making prompt and thorough action essential. The specific threat group(s) behind this has/have not been publicly identified at the time of writing.
LinkCVE-2024-49019 – Security Update Guide – Microsoft – Active Directory Certificate Services Elevation of Privilege Vulnerability

 

TitleAzure CycleCloud Remote Code Execution Vulnerability
CVECVE-2024-43602
CVSS9.9
Reason for ConcernCritical CVSS rating. This vulnerability could allow an attacker to execute arbitrary code remotely on affected Azure CycleCloud systems. Given the high impact on confidentiality, integrity, and availability, successful exploitation could lead to complete compromise of the targeted system.
Mitigations and other FactorsAn attacker would need to have basic user permissions before attempting an exploit. They would then need to send specially crafted requests to modify the configuration of an Azure CycleCloud cluster to gain Root level permissions enabling them to execute commands on any Azure CycleCloud cluster in the current instance and in some scenarios, compromise administrator credentials.
CommentaryGiven that authentication is required before an exploit can be attempted, there is some mitigation in place, however, patching should not be delayed.
Threat Intelligence CommentCVE-2024-43602 poses a significant threat due to its potential to grant attackers remote code execution capabilities. While authentication is required to exploit this vulnerability, the impact of a successful attack is severe. The specific threat group(s) behind this has/have not been publicly identified at the time of writing.
LinkCVE-2024-43602 – Security Update Guide – Microsoft – Azure CycleCloud Remote Code Execution Vulnerability

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content