CyberzSOC

Publication detail
← Back to advisories & guidance

2024-080: Multiple Critical Vulnerabilities in Microsoft Products ↗ source

August 14, 2024 CERT-EU Advisory

Summary

This Patch Tuesday also fixes six critical vulnerabilities [1,2]. We highlight here the most critical vulnerabilities, but it is highly recommended to deploy Microsoft patches for all 89 vulnerabilities identified. CVE-2024-38063, with a CVSS score 9.8, is a Windows TCP/IP Remote Code Execution Vulnerability that could allow an unauthenticated attacker to repeatedly send IPv6 packets, which include specially crafted packets, to a Windows machine which could enable remote code execution [3]. CVE-2024-38140, with a CVSS score 9.8, is a Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability that could allow an unauthenticated attacker to exploit the vulnerability by sending specially crafted packets to a Windows Pragmatic General Multicast (PGM) open socket on the server, without any interaction from the user [4]. CVE-2024-38199, with a CVSS score 9.8, is a zero-day Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability that could allow an unauthenticated attacker to send a specially crafted print task to a shared vulnerable Windows Line Printer Daemon (LPD) service across a network.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-38063 9.8 Critical Microsoft Windows 10 Version 1809 Windows TCP/IP Remote Code Execution Vulnerability
CVE-2024-38140 9.8 Critical Microsoft Windows 10 Version 1809 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVE-2024-38199 9.8 Critical Microsoft Windows 10 Version 1809 Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
CVE-2024-38108 9.3 Critical Microsoft Azure Stack Hub Azure Stack Hub Spoofing Vulnerability
CVE-2024-38109 9.1 Critical Microsoft Azure Health Bot An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a …
CVE-2024-38159 9.1 Critical Microsoft Windows 10 Version 1607 Windows Network Virtualization Remote Code Execution Vulnerability
CVE-2024-38160 9.1 Critical Microsoft Windows 10 Version 1607 Windows Network Virtualization Remote Code Execution Vulnerability

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.