Microsoft Rolls Out August Patch Tuesday Updates—90 Vulnerabilities Addressed, Five Under Active Exploitation
Microsoft has unveiled its latest Patch Tuesday updates, targeting a significant 90 vulnerabilities within the Windows platform. Among these, the Microsoft Security Response Center has identified five critical zero-day flaws that are currently under active attack. These issues are so severe that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has incorporated them into the Known Exploited Vulnerabilities Catalog, setting a compliance deadline of September 3 for updates.
Essential Update Recommendations to Mitigate Emerging Threats
The September 3 deadline set by CISA primarily applies to federal civilian executive branch agencies under the U.S. Government Binding Operational Directive 22-01. However, this timeline is a crucial guideline for all organizations and individuals aiming to enhance their cybersecurity posture. CISA emphasizes that the KEV catalog is a resource for the broader cybersecurity community, offering vital information to help manage vulnerabilities and counteract threats effectively. For most consumers, applying the latest Patch Tuesday updates will suffice, but organizations with rigorous testing protocols must prioritize these KEV entries in their patch management strategies.
Detailed Overview of the August 2024 Windows Zero-Day Vulnerabilities
- CVE-2024-38178: This vulnerability involves a memory corruption issue in the Windows scripting engine, which could enable remote code execution. Affecting Windows 10, Windows 11, and Windows Server 2012 and later, it is rated 7.6 on the severity scale. Chris Goettl from Ivanti advises treating this vulnerability with high priority due to its significant risk.
- CVE-2024-38213: This flaw in the Windows ‘Mark of the Web’ feature could allow attackers to bypass SmartScreen protections on Windows 10, Windows 11, and Windows Server 2012 and beyond. Kev Breen from Immersive Labs notes that while this vulnerability on its own is less dangerous, it can be part of a broader exploit chain and should be addressed promptly.
- CVE-2024-38193: This vulnerability involves an elevation of privilege in the Windows ancillary function driver for WinSock, impacting Windows 10, Windows 11, and Windows Server 2008 and later. Adam Barnett of Rapid7 highlights the importance of addressing this issue immediately due to its potential for SYSTEM-level privilege escalation with minimal complexity.
- CVE-2024-38106: A Windows kernel vulnerability that allows elevation of privilege by manipulating inadequately protected memory. Affecting Windows 10, Windows 11, and Windows Server 2016 and later, this issue requires precise timing to exploit, according to Mike Walters of Action1.
- CVE-2024-38107: This use-after-free vulnerability in the Windows power dependency coordinator could lead to arbitrary code execution or system control. Walters notes that while an attacker needs local access to exploit this flaw, its potential impacts include disabling security mechanisms and deploying malware.
In summary, staying vigilant and updating systems promptly are crucial steps to mitigate the risks posed by these newly disclosed vulnerabilities.



