Rewterz
Donot APT Group Targeting Pakistan – Active IOCs
October 17, 2024
Rewterz
PatchWork APT Threat Actor Group – Active IOCs
October 17, 2024

Multiple Microsoft Windows Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2024-43542 CVSS:6.5

Windows Mobile Broadband Driver Denial of Service Vulnerability

CVE-2024-43540 CVSS:6.5

Windows Mobile Broadband Driver Denial of Service Vulnerability

CVE-2024-43541 CVSS:7.5

Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability

CVE-2024-43538 CVSS:6.5

Windows Mobile Broadband Driver Denial of Service Vulnerability

CVE-2024-43534 CVSS:6.5

Windows Graphics Component Information Disclosure Vulnerability

CVE-2024-43573 CVSS:6.5

Windows MSHTML Platform Spoofing Vulnerability

CVE-2024-43543 CVSS:6.8

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

CVE-2024-43554 CVSS:5.5

Windows Kernel-Mode Driver Information Disclosure Vulnerability

Impact

  • Information Disclosure
  • Denial of Service
  • Code Execution
  • Gain Access

Indicators of Compromise

CVE

  • CVE-2024-43542
  • CVE-2024-43540
  • CVE-2024-43541
  • CVE-2024-43538
  • CVE-2024-43534
  • CVE-2024-43573
  • CVE-2024-43543
  • CVE-2024-43554

Affected Vendors

Microsoft

Affected Products

  • Microsoft Windows 10 Version 1809 - 10.0.0
  • Microsoft Windows 10 Version 22H2 - 10.0.0
  • Microsoft Windows 11 version 21H2 - 10.0.0
  • Microsoft Windows 11 version 22H2 - 10.0.0
  • Microsoft Windows Server 2019 - 10.0.0
  • Microsoft Windows Server 2008 Service Pack 2 - 6.0.0
  • Microsoft Windows Server 2019 (Server Core installation) - 10.0.0
  • Microsoft Windows Server 2008 Service Pack 2 (Server Core installation) - 6.0.0
  • Microsoft Windows Server 2008 R2 Service Pack 1 - 6.1.0
  • Microsoft Windows Server 2012 R2 (Server Core installation) - 6.3.0
  • Microsoft Windows Server 2012 R2 - 6.3.0

Remediation

Use Microsoft Automatic Update to apply the appropriate patch for your system, or the Microsoft Security Update Guide to search for available patches.

CVE-2024-43542

CVE-2024-43540

CVE-2024-43541

CVE-2024-43538

CVE-2024-43534

CVE-2024-43573

CVE-2024-43543

CVE-2024-43554