Rewterz
North Korean APT Kimsuky aka Black Banshee – Active IOCs
October 15, 2024
Rewterz
FormBook Malware – Active IOCs
October 15, 2024

Multiple Microsoft Windows Vulnerabilities

Severity

High

Analysis Summary

CVE-2024-43611 CVSS:8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2024-43592 CVSS:8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2024-43593 CVSS:8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2024-43589 CVSS:8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2024-43584 CVSS:7.7

Windows Scripting Engine Security Feature Bypass Vulnerability

CVE-2024-43575 CVSS:7.5

Windows Hyper-V Denial of Service Vulnerability

CVE-2024-43564 CVSS:8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2024-43563 CVSS:7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Impact

  • Code Execution
  • Security Bypass
  • Denial of Service
  • Privilege Escalation

Indicators of Compromise

CVE

  • CVE-2024-43611
  • CVE-2024-43592
  • CVE-2024-43593
  • CVE-2024-43589
  • CVE-2024-43584
  • CVE-2024-43575
  • CVE-2024-43564
  • CVE-2024-43563

Affected Vendors

Microsoft

Affected Products

  • Microsoft Windows Server 2022
  • Microsoft Windows 11 version 21H2 - 10.0.0
  • Microsoft Windows 11 version 22H2 - 10.0.0
  • Microsoft Windows Server 2016 - 10.0.0
  • Microsoft Windows Server 2019 - 10.0.0
  • Microsoft Windows Server 2008 Service Pack 2 - 6.0.0
  • Microsoft Windows Server 2019 (Server Core installation) - 10.0.0
  • Microsoft Windows Server 2022 - 10.0.0
  • Microsoft Windows Server 2016 (Server Core installation) - 10.0.0
  • Microsoft Windows Server 2008 Service Pack 2 (Server Core installation) - 6.0.0
  • Microsoft Windows Server 2012 R2 (Server Core installation) - 6.3.0

Remediation

Use Microsoft Automatic Update to apply the appropriate patch for your system, or the Microsoft Security Update Guide to search for available patches.

CVE-2024-43611

CVE-2024-43592

CVE-2024-43593

CVE-2024-43589

CVE-2024-43584

CVE-2024-43575

CVE-2024-43564

CVE-2024-43563