Rewterz
Rewterz Threat Alert – SideWinder APT Group aka Rattlesnake – Active IOCs
January 12, 2024
Rewterz
Rewterz Threat Update – Cloud and SaaS Platforms Targeted by New Python-Based FBot Malware
January 12, 2024

Rewterz Threat Advisory – Multiple Microsoft Products Vulnerabilities

Severity

High

Analysis Summary

CVE-2024-21325 CVSS:7.8

Microsoft Printer Metadata Troubleshooter Tool could allow a remote attacker to execute arbitrary code on the system. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system.

CVE-2024-21318 CVSS:8.8

Microsoft SharePoint Server could allow a remote authenticated attacker to execute arbitrary code on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the SharePoint server.

CVE-2024-20656 CVSS:7.8

Microsoft Visual Studio could allow a local authenticated attacker to gain elevated privileges on the system. By executing a specially crafted program, an authenticated attacker could exploit this vulnerability to obtain SYSTEM privileges.

Impact

  • Privilege Escalation
  • Code Execution

Indicators Of Compromise

CVE

  • CVE-2024-21325
  • CVE-2024-21319
  • CVE-2024-20656

Affected Vendors

Microsoft

Affected Products

  • Microsoft SharePoint Enterprise Server 2016
  • Microsoft Visual Studio 2019 16.0
  • Microsoft Visual Studio 2019 16.1
  • Microsoft Visual Studio 2019 16.2
  • Microsoft Visual Studio 2019 16.3
  • Microsoft Visual Studio 2019 16.4
  • Microsoft Visual Studio 2019 16.5
  • Microsoft Visual Studio 2019 16.6
  • Microsoft Visual Studio 2019 16.7
  • Microsoft Visual Studio 2019 16.8
  • Microsoft Visual Studio 2019 16.9
  • Microsoft Visual Studio 2019 16.10
  • Microsoft SharePoint Server 2019
  • Microsoft Visual Studio 2017 15.9
  • Microsoft Visual Studio 2015 Update 3
  • Microsoft Visual Studio 2022 17.2
  • Microsoft Visual Studio 2022 17.4
  • Microsoft Visual Studio 2022 17.6
  • Microsoft Printer Metadata Troubleshooter Tool
  • Microsoft SharePoint Server Subscription

Remediation

Use Microsoft Automatic Update to apply the appropriate patch for your system, or the Microsoft Security Update Guide to search for available patches.

CVE-2024-21325

CVE-2024-21319

CVE-2024-20656