Rewterz
Quasar RAT aka CinaRAT – Active IOCs
July 12, 2024
Rewterz
Multiple Mozilla Firefox Products Vulnerabilities
July 12, 2024

Multiple Microsoft Windows Products Vulnerabilities

Severity

High

Analysis Summary

CVE-2024-38104 CVSS:8.8

Microsoft Windows could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an error in the Fax Service. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the victim machine.

CVE-2024-38105 CVSS:6.5

Microsoft Windows could allow a remote attacker from within the local network to cause a denial of service, caused by an error in the Layer-2 Bridge Network driver. By sending a specially crafted request, an attacker could exploit this vulnerability to cause a denial of service.

CVE-2024-38101 CVSS:6.5

Microsoft Windows could allow a remote attacker from within the local network to cause a denial of service, caused by an error in the Layer-2 Bridge Network driver. By sending a specially crafted request, an attacker could exploit this vulnerability to cause a denial of service.

CVE-2024-38112 CVSS:7.5

Microsoft Windows could allow a remote attacker to conduct spoofing attacks, caused by a flaw in the MSHTML Platform component. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to conduct a spoofing attack.

CVE-2024-38102 CVSS:6.5

Microsoft Windows could allow a remote attacker from within the local network to cause a denial of service, caused by an error in the Layer-2 Bridge Network driver. By sending a specially crafted request, an attacker could exploit this vulnerability to cause a denial of service.

CVE-2024-38017 CVSS:5.5

Microsoft Windows could allow a local authenticated attacker to obtain sensitive information, caused by a flaw in Message Queuing component. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain sensitive information and then use this information to launch further attacks against the affected system.

CVE-2024-38031 CVSS:7.5

Microsoft Windows is vulnerable to a denial of service, caused by a flaw in the Online Certificate Status Protocol (OCSP) Server component. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.

CVE-2024-38059 CVSS:7.8

Microsoft Windows could allow a local authenticated attacker to gain elevated privileges on the system, caused by a flaw in the Win32k component. By executing a specially crafted program, an authenticated attacker could exploit this vulnerability to execute arbitrary code with higher privileges.

CVE-2024-38022 CVSS:7

Microsoft Windows could allow a local authenticated attacker to gain elevated privileges on the system, caused by a flaw in the Image Acquisition component. By executing a specially crafted program, an authenticated attacker could exploit this vulnerability to execute arbitrary code with higher privileges.

CVE-2024-38091 CVSS:7.5

Microsoft Windows is vulnerable to a denial of service, caused by a flaw in the WS-Discovery component. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.

CVE-2024-26184 CVSS:6.8

Microsoft Windows could allow a remote authenticated attacker to bypass security restrictions, cause by a flaw in Secure Boot component. An attacker could exploit this vulnerability to bypass security feature to cause impact on confidentiality, integrity and availability.

CVE-2024-38070 CVSS:7.8

Microsoft Windows could allow a local authenticated attacker to bypass security restrictions, cause by a flaw in the LockDown Policy (WLDP) component. An attacker could exploit this vulnerability to bypass security feature to cause impact on confidentiality.

CVE-2024-21417 CVSS:8.8

Microsoft Windows could allow a local authenticated attacker to gain elevated privileges on the system, caused by a flaw in the Text Services Framework component. By executing a specially crafted program, an authenticated attacker could exploit this vulnerability to execute arbitrary code with higher privileges.

CVE-2024-30013 CVSS:8.8

Microsoft Windows could allow a remote attacker to execute arbitrary code on the system, caused by a flaw in the MultiPoint Services component. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.

CVE-2024-37974 CVSS:8

Microsoft Windows could allow a remote attacker to bypass security restrictions, cause by a flaw in Secure Boot component. An attacker could exploit this vulnerability to bypass security feature to cause impact on confidentiality, integrity and availability.

CVE-2024-30079 CVSS:7.8

Microsoft Windows could allow a local authenticated attacker to gain elevated privileges on the system, caused by a flaw in the Remote Access Connection Manager component. By executing a specially crafted program, an authenticated attacker could exploit this vulnerability to execute arbitrary code with higher privileges.

CVE-2024-38077 CVSS:9.8

Microsoft Windows could allow a remote attacker to execute arbitrary code on the system, caused by a flaw in the Remote Desktop Licensing Service component. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.

CVE-2024-38055 CVSS:5.5

Microsoft Windows could allow a local authenticated attacker to obtain sensitive information, caused by a flaw in the Codecs Library component. By persuading a victim to open a specially crafted content, an attacker could exploit this vulnerability to obtain sensitive information and then use this information to launch further attacks against the affected system.

CVE-2024-38064 CVSS:7.5

Microsoft Windows could allow a remote attacker to obtain sensitive information, caused by a flaw in the TCP/IP component. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.

CVE-2024-37989 CVSS:8

Microsoft Windows could allow a remote attacker to bypass security restrictions, cause by a flaw in the Secure Boot component. An attacker could exploit this vulnerability to bypass security feature to cause impact on confidentiality, integrity and availability.

Impact

  • Denial of Service
  • Gain Access
  • Code Execution
  • Security Bypass
  • Privilege Escalation
  • Information Disclosure

Indicators of Compromise

CVE

  • CVE-2024-38104
  • CVE-2024-38105
  • CVE-2024-38101
  • CVE-2024-38112
  • CVE-2024-38102
  • CVE-2024-38017
  • CVE-2024-38031
  • CVE-2024-38059
  • CVE-2024-38022
  • CVE-2024-38091
  • CVE-2024-26184
  • CVE-2024-38070
  • CVE-2024-21417
  • CVE-2024-30013
  • CVE-2024-37974
  • CVE-2024-30079
  • CVE-2024-30077
  • CVE-2024-38055
  • CVE-2024-38064
  • CVE-2024-37989

Affected Vendors

Microsoft

Affected Products

  • Microsoft Windows 10 for 32-bit Systems
  • Microsoft Windows 10 for x64-based Systems
  • Microsoft Windows Server 2022
  • Microsoft Windows Server 2022 23H2
  • Microsoft Windows 10 Version 1607 for 32-bit Systems 1607
  • Microsoft Windows 10 Version 1607 for x64-based Systems 1607
  • Microsoft Windows 10 Version 1809 for 32-bit Systems 1809
  • Microsoft Windows 10 Version 1809 for ARM64-based Systems 1809
  • Microsoft Windows 10 Version 1809 for x64-based Systems 1809
  • Microsoft Windows 10 Version 21H2 for 32-bit Systems 21H2
  • Microsoft Windows 10 Version 21H2 for ARM64-based Systems 21H2
  • Microsoft Windows 10 Version 21H2 for x64-based Systems 21H2
  • Microsoft Windows 10 Version 22H2 for 32-bit Systems 22H2
  • Microsoft Windows 10 Version 22H2 for ARM64-based Systems 22H2
  • Microsoft Windows 10 Version 22H2 for x64-based Systems 22H2
  • Microsoft Windows 11 Version 22H2 for ARM64-based Systems 22H2
  • Microsoft Windows 11 Version 22H2 for x64-based Systems 22H2
  • Microsoft Windows 11 Version 23H2 for ARM64-based Systems 23H2
  • Microsoft Windows 11 Version 23H2 for x64-based Systems 23H2
  • Microsoft Windows 11 version 21H2 for ARM64-based Systems 22H2
  • Microsoft Windows 11 version 21H2 for x64-based Systems 22H2
  • Microsoft Windows Server 2008 for 32-bit Systems Service Pack 2 23H2
  • Microsoft Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 23H2
  • Microsoft Windows Server 2008 for x64-based Systems Service Pack 2 23H2
  • Microsoft Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 23H2
  • Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1 23H2
  • Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 23H2
  • Microsoft Windows Server 2012 23H2
  • Microsoft Windows Server 2012 (Server Core installation) 23H2
  • Microsoft Windows Server 2012 R2 23H2
  • Microsoft Windows Server 2012 R2 (Server Core installation) 23H2
  • Microsoft Windows Server 2016 23H2
  • Microsoft Windows Server 2016 (Server Core installation) 23H2
  • Microsoft Windows Server 2019 23H2
  • Microsoft Windows Server 2019 (Server Core installation) 23H2
  • Microsoft Windows Server 2022 (Server Core installation) 23H2

Remediation

Use Microsoft Automatic Update to apply the appropriate patch for your system, or the Microsoft Security Update Guide to search for available patches.

CVE-2024-38104

CVE-2024-38105

CVE-2024-38101

CVE-2024-38112

CVE-2024-38102

CVE-2024-38017

CVE-2024-38031

CVE-2024-38059

CVE-2024-38022

CVE-2024-38091

CVE-2024-26184

CVE-2024-38070

CVE-2024-21417

CVE-2024-30013

CVE-2024-37974

CVE-2024-30079

CVE-2024-30077

CVE-2024-38055

CVE-2024-38064

CVE-2024-37989