Microsoft’s March 2024 Patch Tuesday Addresses 59 CVEs (CVE-2024-21407)
- 2Critical
- 57Important
- 0Moderate
- 0Low
Microsoft addresses 59 CVEs in its March 2024 Patch Tuesday release with no zero-day or publicly disclosed vulnerabilities.
Microsoft patched 59 CVEs in its March 2024 Patch Tuesday release, with 2 rated critical and 57 rated as important.
This month’s update includes patches for:
- .NET
- Azure Data Studio
- Azure SDK
- Microsoft Authenticator
- Microsoft Azure Kubernetes Service
- Microsoft Dynamics
- Microsoft Edge for Android
- Microsoft Exchange Server
- Microsoft Graphics Component
- Microsoft Intune
- Microsoft Office
- Microsoft Office SharePoint
- Microsoft QUIC
- Microsoft Teams for Android
- Microsoft WDAC ODBC Driver
- Microsoft WDAC OLE DB provider for SQL
- Microsoft Windows SCSI Class System File
- Open Management Infrastructure
- Outlook for Android
- Role: Windows Hyper-V
- Skype for Consumer
- Software for Open Networking in the Cloud (SONiC)
- SQL Server
- Visual Studio Code
- Windows AllJoyn API
- Windows Cloud Files Mini Filter Driver
- Windows Composite Image File System
- Windows Compressed Folder
- Windows Defender
- Windows Error Reporting
- Windows Hypervisor-Protected Code Integrity
- Windows Installer
- Windows Kerberos
- Windows Kernel
- Windows NTFS
- Windows ODBC Driver
- Windows OLE
- Windows Print Spooler Components
- Windows Standards-Based Storage Management Service
- Windows Telephony Server
- Windows Update Stack
- Windows USB Hub Driver
- Windows USB Print Driver
- Windows USB Serial Driver
Elevation of privilege (EoP) vulnerabilities accounted for 40.7% of the vulnerabilities patched this month, followed by Remote code execution (RCE) at 30.5%.
CVE-2024-21334 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
CVE-2024-21334 is a RCE affecting the open-source Open Management Infrastructure (OMI) management server. It was assigned a CVSSv3 score of 9.8 and is rated important. To exploit this vulnerability, a remote unauthenticated attacker could use a specially crafted request to trigger a use-after-free vulnerability. In addition, OMI received another patch this month, CVE-2024-21330 to address an EoP vulnerability.
In 2022, Microsoft patched two EoP flaws in OMI (CVE-2022-33640 and CVE-2022-29149), as well as an information disclosure vulnerability (CVE-2023-36043) in November 2023. This RCE is a first for OMI and despite the critical CVSS score, Microsoft rates this vulnerability as “Exploitation Less Likely” according to the Microsoft Exploitability Index.
CVE-2024-21407 | Windows Hyper-V Remote Code Execution Vulnerability
CVE-2024-21407 is a RCE vulnerability in Windows Hyper-V. This vulnerability was assigned a CVSSv3 score of 8.1 and is rated critical. Successful exploitation of this vulnerability requires that an attacker be authenticated and gather information about the target environment in order to craft their exploit. While the attack complexity is high, exploitation could result in code execution on the host server.
Including this month, nine RCE vulnerabilities affecting Windows Hyper-V have been disclosed since 2022, with seven of them rated as Critical. While these flaws generally are more difficult to exploit, successfully breaking out of a VM and executing code on the host is a significant risk and these flaws should be remediated quickly to avoid any potential misuse.
CVE-2024-21433 | Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2024-21433 is an EoP vulnerability in Windows Print Spooler. This vulnerability is rated as ”Exploitation More Likely,” and was assigned a CVSSv3 score of 7.0. Exploitation of this vulnerability would require an attacker to win a race condition which could grant the attacker SYSTEM privileges.
Over the last few years, we’ve seen a sharp decline in the number of Print Spooler related vulnerabilities patched as part of Patch Tuesday since the disclosure of CVE-2021-34527, the original PrintNightmare vulnerability and the torrent of Print Spooler vulnerabilities that followed. In 2023, there were only four Print Spooler related bugs patched, including CVE-2023-35325, an information disclosure vulnerability in Print Spooler disclosed in July 2023, as well as three Print Spooler EoP vulnerabilities disclosed in January 2023. In 2022, there were 35 Print Spooler related vulnerabilities patched as part of Patch Tuesday, with the biggest concentration of disclosures occurring in April 2022, with 15 Print Spooler vulnerabilities patched.
CVE | Description | Patch Tuesday Release |
---|---|---|
CVE-2023-35325 | Windows Print Spooler Information Disclosure Vulnerability | Jul 2023 |
CVE-2023-21678 | Windows Print Spooler Elevation of Privilege Vulnerability | Jan 2023 |
CVE-2023-21765 | Windows Print Spooler Elevation of Privilege Vulnerability | Jan 2023 |
CVE-2023-21760 | Windows Print Spooler Elevation of Privilege Vulnerability | Jan 2023 |
CVE-2022-44681 | Windows Print Spooler Elevation of Privilege Vulnerability | Dec 2022 |
CVE-2022-44678 | Windows Print Spooler Elevation of Privilege Vulnerability | Dec 2022 |
CVE-2022-41073 | Windows Print Spooler Elevation of Privilege Vulnerability | Nov 2022 |
CVE-2022-38028 | Windows Print Spooler Elevation of Privilege Vulnerability | Oct 2022 |
CVE-2022-38005 | Windows Print Spooler Elevation of Privilege Vulnerability | Sep 2022 |
CVE-2022-35755 | Windows Print Spooler Elevation of Privilege Vulnerability | Aug 2022 |
CVE-2022-35793 | Windows Print Spooler Elevation of Privilege Vulnerability | Aug 2022 |
CVE-2022-22022 | Windows Print Spooler Elevation of Privilege Vulnerability | Jul 2022 |
CVE-2022-22041 | Windows Print Spooler Elevation of Privilege Vulnerability | Jul 2022 |
CVE-2022-30206 | Windows Print Spooler Elevation of Privilege Vulnerability | Jul 2022 |
CVE-2022-30226 | Windows Print Spooler Elevation of Privilege Vulnerability | Jul 2022 |
CVE-2022-29104 | Windows Print Spooler Elevation of Privilege Vulnerability | May 2022 |
CVE-2022-29132 | Windows Print Spooler Elevation of Privilege Vulnerability | May 2022 |
CVE-2022-29114 | Windows Print Spooler Information Disclosure Vulnerability | May 2022 |
CVE-2022-29140 | Windows Print Spooler Information Disclosure Vulnerability | May 2022 |
CVE-2022-26796 | Windows Print Spooler Elevation of Privilege Vulnerability | Apr 2022 |
CVE-2022-26802 | Windows Print Spooler Elevation of Privilege Vulnerability | Apr 2022 |
CVE-2022-26795 | Windows Print Spooler Elevation of Privilege Vulnerability | Apr 2022 |
CVE-2022-26801 | Windows Print Spooler Elevation of Privilege Vulnerability | Apr 2022 |
CVE-2022-26791 | Windows Print Spooler Elevation of Privilege Vulnerability | Apr 2022 |
CVE-2022-26790 | Windows Print Spooler Elevation of Privilege Vulnerability | Apr 2022 |
CVE-2022-26794 | Windows Print Spooler Elevation of Privilege Vulnerability | Apr 2022 |
CVE-2022-26793 | Windows Print Spooler Elevation of Privilege Vulnerability | Apr 2022 |
CVE-2022-26786 | Windows Print Spooler Elevation of Privilege Vulnerability | Apr 2022 |
CVE-2022-26789 | Windows Print Spooler Elevation of Privilege Vulnerability | Apr 2022 |
CVE-2022-26797 | Windows Print Spooler Elevation of Privilege Vulnerability | Apr 2022 |
CVE-2022-26798 | Windows Print Spooler Elevation of Privilege Vulnerability | Apr 2022 |
CVE-2022-26792 | Windows Print Spooler Elevation of Privilege Vulnerability | Apr 2022 |
CVE-2022-26787 | Windows Print Spooler Elevation of Privilege Vulnerability | Apr 2022 |
CVE-2022-26803 | Windows Print Spooler Elevation of Privilege Vulnerability | Apr 2022 |
CVE-2022-23284 | Windows Print Spooler Elevation of Privilege Vulnerability | Mar 2022 |
CVE-2022-22718 | Windows Print Spooler Elevation of Privilege Vulnerability | Feb 2022 |
CVE-2022-21999 | Windows Print Spooler Elevation of Privilege Vulnerability | Feb 2022 |
CVE-2022-21997 | Windows Print Spooler Elevation of Privilege Vulnerability | Feb 2022 |
CVE-2022-22717 | Windows Print Spooler Elevation of Privilege Vulnerability | Feb 2022 |
CVE-2024-21443, CVE-2024-26173, CVE-2024-26176, CVE-2024-26178 and CVE-2024-26182 | Windows Kernel Elevation of Privilege Vulnerability
CVE-2024-21443, CVE-2024-26173, CVE-2024-26176, CVE-2024-26178 and CVE-2024-26182 are EoP vulnerabilities affecting the Windows Kernel. These vulnerabilities are all rated as important, and each was assigned a CVSSv3 score of 7.8 with the exception of CVE-2024-21443 which was scored as 7.3. CVE-2024-26182 was the only Windows Kernel EoP rated as “Exploitation More Likely.” Successful exploitation of these vulnerabilities could lead to an attacker gaining SYSTEM privileges.
CVE-2024-21441, CVE-2024-21444, CVE-2024-21450, CVE-2024-26161 and CVE-2024-26166 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
CVE-2024-21441, CVE-2024-21444, CVE-2024-21450, CVE-2024-26161 and CVE-2024-26166 are RCE vulnerabilities affecting the Microsoft WDAC OLE DB provider for SQL Server. These vulnerabilities are rated as important, and were assigned CVSSV3 scores of 8.8. Successful exploitation requires an authenticated user to be enticed to connect to a malicious SQL database. Once a connection is made, specially crafted replies can be sent to the client in order to exploit the vulnerability and allow the execution of arbitrary code.
Tenable Solutions
A list of all the plugins released for Tenable’s March 2024 Patch Tuesday update can be found here. As always, we recommend patching systems as soon as possible and regularly scanning your environment to identify those systems yet to be patched.
For more specific guidance on best practices for vulnerability assessments, please refer to our blog post on How to Perform Efficient Vulnerability Assessments with Tenable.
Get more information
- Microsoft's March 2024 Security Updates
- Tenable plugins for Microsoft March 2024 Patch Tuesday Security Updates
Join Tenable's Security Response Team on the Tenable Community.
Learn more about https://www.tenable.com/products/tenable-one">Tenable One, the Exposure Management Platform for the modern attack surface.
Related Articles
- Exposure Management