For May 2024 Patch Tuesday, Microsoft has released fixes for 59 CVE-numbered vulnerabilities, including two zero-days actively exploited by attackers.
CVE-2024-30051 is a heap-based buffer overflow vulnerability affecting the Windows DWM Core Library that can be exploited to elevate attackers' privileges on a target system.
Researchers from Kaspersky, DBAPPSecurity WeBin Lab, Google Threat Analysis Group and Google Mandiant have been credited with reporting it so it has been speculated that the attacks leveraging it are widespread. Kaspersky researchers Boris Larin and Mert Degirmenci have shared more details: CVE-2024-30051 is being leveraged in conjuction with Qakbot and other malware.
CVE-2024-30040 is a vulnerability that allows attackers to bypasses OLE mitigations in Microsoft 365 and Microsoft Office.
Microsoft does not say who reported the vulnerability or explains the nature of the attacks for which it is being leveraged.
He also singled out CVE-2024-30050, a moderately severe vulnerability that may allow attackers to bypass the protections provided by Windows Mark of the Web controls, because this type of security feature bypass is quite in vogue with ransomware gangs at the moment.
This Cyber News was published on www.helpnetsecurity.com. Publication date: Tue, 14 May 2024 19:13:05 +0000