Microsoft Addresses 6 Critical Zero-Day Vulnerabilities Actively Targeted by Hackers

Microsoft has rolled out its Patch Tuesday update for August 2024, addressing 90 security issues. Among these, six zero-day vulnerabilities have been actively exploited across a range of Microsoft products and services, including Windows, Office, Azure, Dynamics, and Edge.

The presence of multiple zero-day vulnerabilities, particularly those currently being exploited, underscores the urgency of this Patch Tuesday. It is crucial for organizations to implement these patches promptly to reduce the risk of attacks.

The August update also tackles several significant vulnerabilities, such as those in the Windows Reliable Multicast Transport Driver and Windows TCP/IP, which could potentially lead to remote code execution.

Six Actively Exploited Zero-Days

CVE-2024-38178: Scripting Engine Memory Corruption Vulnerability
This flaw allows remote code execution when an authenticated user clicks a specially crafted URL in Microsoft Edge’s Internet Explorer Mode. Discovered by AhnLab and South Korea’s National Cyber Security Center, this vulnerability may be linked to state-sponsored APT campaigns.

CVE-2024-38193: Windows Ancillary Function Driver for WinSock Privilege Escalation
Researchers from Gen Digital (formerly Symantec) found this bug, which grants SYSTEM-level privileges on Windows systems. Given its nature, it’s a likely candidate for ransomware attacks.

CVE-2024-38213: Windows Mark of the Web Security Feature Bypass
This vulnerability allows attackers to circumvent the SmartScreen security feature, potentially enabling malicious files to evade detection. It was identified by a researcher from Trend Micro’s Zero Day Initiative.

CVE-2024-38106: Windows Kernel Privilege Escalation Vulnerability
This flaw in the Windows Kernel can be exploited to gain SYSTEM privileges by winning a race condition. Though classified as “high complexity,” it has been successfully exploited in the wild.

CVE-2024-38107: Windows Power Dependency Coordinator Privilege Escalation
This vulnerability affects the Windows Power Dependency Coordinator, a component of Modern Standby, and can be exploited to achieve SYSTEM-level access.

CVE-2024-38189: Microsoft Project Remote Code Execution Vulnerability
This remote code execution flaw in Microsoft Project is triggered by maliciously crafted files. While it requires certain security features to be disabled, it has been seen in active attacks.

It is highly recommended that organizations and individuals apply these security updates immediately to avoid potential exploitation.

Microsoft has not released detailed information regarding the extent of these exploits, but security experts caution that some of these vulnerabilities could rapidly become focal points for ransomware attacks if they haven’t already.

Beyond the six actively exploited zero-days, Microsoft has also addressed three other publicly disclosed vulnerabilities and is working on a fix for a tenth publicly known zero-day.

As always, users and system administrators should review the full list of patched vulnerabilities and prioritize updates based on their specific risk environments and system configurations.

More Articles & Posts