ADVISORY!

TLP : CLEAR

Date : 16/02/2024

REF NO : CERT / 2024/02/13

Microsoft Products Multiple Vulnerabilities

Severity Level: High

Components Affected

  • Browser
  • Azure
  • Developer Tools
  • Windows
  • Extended Security Updates (ESU)
  • Microsoft Dynamics
  • Microsoft Office
  • System Center
  • Exchange Server
  • Mariner

Overview

Exploit in the wild has been detected for CVE-2024-21410, affecting Microsoft Exchange Server. The vulnerability could be exploited by sending a crafted request to steal user’s NTLM hash.

Proof of Concept exploit code is publicly available for CVE-2024-21413, affecting Microsoft Outlook. The vulnerability could be exploited by clicking on a malicious URL and execute arbitrary code.

Description

 

Vulnerable ProductRisk LevelImpactsNotes
BrowserMedium Risk Medium RiskRemote Code Execution 
AzureMedium Risk Medium RiskRemote Code Execution
Elevation of Privilege
Spoofing
 
Developer ToolsMedium Risk Medium RiskRemote Code Execution
Denial of Service
 
WindowsMedium Risk Medium RiskDenial of Service
Elevation of Privilege
Information Disclosure
Remote Code Execution
Security Restriction Bypass
Spoofing

CVE-2024-21351  is being exploited in the wild. The vulnerability allows a malicious actor to inject code into SmartScreen and potentially gain code execution, which could potentially lead to some data exposure, lack of system availability, or both.

 

CVE-2024-21412  is being exploited in the wild.  The vulnerability could bypass Mark of the Web (MoTW) warnings in Windows.

Extended Security Updates (ESU)Medium Risk Medium RiskDenial of Service
Information Disclosure
Remote Code Execution
Elevation of Privilege
Spoofing
 
Microsoft DynamicsMedium Risk Medium RiskSpoofing
Information Disclosure
 
Microsoft OfficeMedium Risk High RiskRemote Code Execution
Elevation of Privilege
Information Disclosure

[Updated on 2024-02-16] 

CVE-2024-21413 Proof-Of-Concept is available in public. The vulnerability could be exploited by clicking a malicious URL and execute arbitrary code.

System CenterMedium Risk Medium RiskElevation of Privilege 
Exchange ServerMedium Risk High RiskElevation of Privilege

[Updated on 2024-02-16] 

CVE-2024-21410 is being exploited in the wild. The vulnerability could be exploited by sending a crafted request to steal user’s NTLM hash.

MarinerLow Risk Low Risk  

 

Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Elevation of Privilege
  • Denial of Service
  • Information Disclosure
  • Spoofing

Solution/ Workarounds

Before installation of the software, please visit the vendor web-site for more details.

  •  Apply fixes issued by the vendor.

Reference

Disclaimer : The information provided herein is on an “as is” basis, without warranty of any kind.

Sri Lanka Computer Emergency Readiness Team | Coordination Centre

Copyright © 2023 SRI LANKA CERT | CC