CVE-2024-30088
published 2024-06-11CVE-2024-30088: Windows Kernel Elevation of Privilege Vulnerability
PriorityP187high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2024-11-05
Exploited in the wild
EPSS
68.20%
99.3th percentile
Windows Kernel Elevation of Privilege Vulnerability
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.20680 | 10.0.10240.20680 |
| microsoft | windows_10_1607 | < 10.0.14393.7070 | 10.0.14393.7070 |
| microsoft | windows_10_1809 | < 10.0.17763.5936 | 10.0.17763.5936 |
| microsoft | windows_10_21h2 | < 10.0.19044.4529 | 10.0.19044.4529 |
| microsoft | windows_10_22h2 | < 10.0.19045.4529 | 10.0.19045.4529 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.20680 | 10.0.10240.20680 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.7070 | 10.0.14393.7070 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.5936 | 10.0.17763.5936 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.5936 | 10.0.17763.5936 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.4529 | 10.0.19044.4529 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.4529 | 10.0.19045.4529 |
| microsoft | windows_11_21h2 | < 10.0.22000.3019 | 10.0.22000.3019 |
| microsoft | windows_11_22h2 | < 10.0.22621.3737 | 10.0.22621.3737 |
| microsoft | windows_11_23h2 | < 10.0.22631.3737 | 10.0.22631.3737 |
| microsoft | windows_11_version_21h2 | >= 10.0.22000.0 < 10.0.22000.3019 | 10.0.22000.3019 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.3737 | 10.0.22621.3737 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.3737 | 10.0.22631.3737 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.3737 | 10.0.22631.3737 |
| microsoft | windows_server_2016 | < 10.0.14393.7070 | 10.0.14393.7070 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.7070 | 10.0.14393.7070 |
| microsoft | windows_server_2019 | < 10.0.17763.5936 | 10.0.17763.5936 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.5936 | 10.0.17763.5936 |
| microsoft | windows_server_2022 | < 10.0.20348.2522 | 10.0.20348.2522 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.2527 | 10.0.20348.2527 |
| microsoft | windows_server_2022_23h2 | < 10.0.25398.950 | 10.0.25398.950 |
Detection & IOCsextracted from sources · hover to see the quote
registryHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\Notification Packages = scecli, psgfilter↗
- →Hunt for the PDB artifact string 'CVE-2024-30088-main' in memory or on disk, which indicates use of the public PoC-derived privilege escalation tool. ↗
- →Monitor for 'psgfilter.dll' being written to C:\Windows\System32 and the LSA Notification Packages registry value being modified to include 'psgfilter', indicating malicious password filter DLL registration for credential harvesting. ↗
- →Detect web shell activity by monitoring IIS/web server processes for HTTP requests containing both 'func' and 'command' header values, particularly 'func=Exc', which is used to execute PowerShell commands, upload, or download files. ↗
- →Detect ngrok usage on servers/domain controllers as a lateral movement and tunneling indicator associated with this campaign. ↗
- ·The exploit binary (p.enc / decoded payload) is derived from a public open-source PoC project for CVE-2024-30088; defenders should expect variants with different filenames but the same PDB path pattern or XOR-encoded delivery via a loader. ↗
- ·The vulnerability works on multiple versions of Windows 10 and 11; patching scope should not be limited to a single OS version. ↗
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.0HIGH
cisa7.0HIGH
vendor_msrc7.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft Windows Kernel TOCTOU Race Condition Vulnerability
cisa·2024-10-15·CVSS 7.0
CVE-2024-30088 [HIGH] CWE-367 Microsoft Windows Kernel TOCTOU Race Condition Vulnerability
Vulnerability: Microsoft Windows Kernel TOCTOU Race Condition Vulnerability
Affected: Microsoft Windows
Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-30088 ; https://nvd.nist.gov/vuln/detail/CVE-2024-30088
Remediation Due Date: 2024-11-05
Microsoft
Windows Kernel Elevation of Privilege Vulnerability
vendor_msrc·2024-06-11·CVSS 7.0
CVE-2024-30088 [HIGH] CWE-367 Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race condition.
Windows NT OS Kernel: Windows NT OS Kernel
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5039217
Reference: https://support.microsoft.c
GHSA
GHSA-h47v-33fm-j33g: Windows Kernel Elevation of Privilege Vulnerability
ghsa_unreviewed·2024-06-11
CVE-2024-30088 [HIGH] CWE-367 GHSA-h47v-33fm-j33g: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
VulnCheck
Microsoft Windows Kernel TOCTOU Race Condition Vulnerability
vulncheck·2024·CVSS 7.0
CVE-2024-30088 [HIGH] CWE-367 Microsoft Windows Kernel TOCTOU Race Condition Vulnerability
Microsoft Windows Kernel TOCTOU Race Condition Vulnerability
Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation.
Affected: Microsoft Windows
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.trendmicro.com/en_us/research/24/j/earth-simnavaz-cyberattacks-uae-gulf-regions.html; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://blog.polyswarm.io/2024-recap-iranian-threat-actor-activity; https://www.trustwave.com/en-us/resources/blogs/trustwave-blog/inside-apt34-oilrig-tools-techniques-and-global-cyber-threa
No detection rules found.
Tenable
Operation Epic Fury: Why exposure data changes everything about Iran's cyber-kinetic campaign
blogs_tenable·2026-03-17
Operation Epic Fury: Why exposure data changes everything about Iran's cyber-kinetic campaign
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Operation Epic Fury: cyber threat data in the Iran War
blogs_tenable·2026-03-17·CVSS 7.8
[HIGH] Operation Epic Fury: cyber threat data in the Iran War
Blog / Cyber Exposure Alerts
Subscribe
# Operation Epic Fury: Why exposure data changes everything about Iran's cyber-kinetic campaign
Robert Huber
March 17, 2026
13 Min Read
Iran's retaliatory campaign following Operation Epic Fury has collapsed the boundary between physical and digital warfare. Tenable's exposure data analysis across seven target countries reveals that the largest exploitable attack surface isn't the headline threat, it's a Microsoft Word N-day affecting nearly 14 million assets.
## Key takeaways:
1. Exposure data rebalances the threat picture. A Microsoft Word N-day (CVE-2026-21514) accounts for nearly 14 million of the 15.5 million affected assets across the seven target countries, two orders of magnitude more than the conflict's headline threats. Organizations
Tenable
CVE-2026-21514 FAQ: OLE bypass N-Day in Microsoft Word | Tenable®
blogs_tenable·2026-03-17·CVSS 7.8
CVE-2026-21514 [HIGH] CVE-2026-21514 FAQ: OLE bypass N-Day in Microsoft Word | Tenable®
Blog / Cyber Exposure Alerts
Subscribe
# FAQ on CVE-2026-21514: OLE bypass N-Day in Microsoft Word
Research Special Operations
March 17, 2026
10 Min Read
An N-day vulnerability in Microsoft Word exposes nearly 14 million assets. Attackers can exploit this flaw to bypass security prompts, enabling deployment of malware and establishing persistent access without triggering user warnings.
## Key takeaways:
1. CVE-2026-21514 is a Microsoft Word n-day that bypasses OLE and Mark-of-the-Web protections, executing payloads silently without triggering user security prompts
2. Tenable's exposure data analysis identified nearly 14 million affected assets across seven Tier-1 countries still vulnerable to CVE-2026-21514
3. Prioritize patching CVE-2026-21514 across all managed endpoints and deplo
Tenable
FAQ on CVE-2026-21514: OLE bypass N-Day in Microsoft Word
blogs_tenable·2026-03-17·CVSS 7.8
[HIGH] FAQ on CVE-2026-21514: OLE bypass N-Day in Microsoft Word
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Greynoiseio
The Noise in the Silence: Unmasking CISA's Hidden KEV Ransomware Updates
blogs_greynoiseio·2026-02-02
The Noise in the Silence: Unmasking CISA's Hidden KEV Ransomware Updates
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Tenable
Frequently Asked Questions About Iranian Cyber Operations
blogs_tenable·2025-06-27
Frequently Asked Questions About Iranian Cyber Operations
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Microsoft Patch Tuesday 2024 Year in Review
blogs_tenable·2024-12-10
Microsoft Patch Tuesday 2024 Year in Review
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
SolarWinds Web Help Desk flaw is now exploited in attacks
blogs_bleepingcomputer·2024-10-16·CVSS 9.1
[CRITICAL] SolarWinds Web Help Desk flaw is now exploited in attacks
## SolarWinds Web Help Desk flaw is now exploited in attacks
## Bill Toulas
CISA has added three flaws to its 'Known Exploited Vulnerabilities' (KEV) catalog, among which is a critical hardcoded credentials flaw in SolarWinds Web Help Desk (WHD) that the vendor fixed in late August 2024.
SolarWinds Web Help Desk is an IT help desk suite used by 300,000 customers worldwide, including government agencies, large corporations, and healthcare organizations.
The SolarWinds flaw is tracked as CVE-2024-28987 and is caused by hardcoded credentials, a username of "helpdeskIntegrationUser" and password of "dev-C4F8025E7". Using these credentials, remote unauthenticated attackers could potentially access WHD endpoints and access or modify data without restriction.
SolarWinds issued a hotfix four
Bleepingcomputer
Iranian hackers now exploit Windows flaw to elevate privileges
blogs_bleepingcomputer·2024-10-13·CVSS 7.0
CVE-2024-3008 [HIGH] Iranian hackers now exploit Windows flaw to elevate privileges
## Iranian hackers now exploit Windows flaw to elevate privileges
## Bill Toulas
The Iranian state-sponsored hacking group APT34, aka OilRig, has recently escalated its activities with new campaigns targeting government and critical infrastructure entities in the United Arab Emirates and the Gulf region.
In these attacks, spotted by Trend Micro researchers, OilRig deployed a novel backdoor, targeting Microsoft Exchange servers to steal credentials, and also exploited the Windows CVE-2024-30088 flaw to elevate their privileges on compromised devices.
Apart from the activity, Trend Micro has also made a connection between OilRig and FOX Kitten, another Iran-based APT group involved in ransomware attacks.
## Latest OilRig attack chain
The attacks seen by Trend Micro begin with the explo
Trendmicro
Earth Simnavaz (aka APT34) Levies Advanced Cyberattacks Against Middle East
blogs_trendmicro·2024-10-11·CVSS 7.0
[HIGH] Earth Simnavaz (aka APT34) Levies Advanced Cyberattacks Against Middle East
APT und gezielte Angriffe
## Earth Simnavaz (aka APT34) Levies Advanced Cyberattacks Against Middle East
Trend Micro's investigation into the recent activity of Earth Simnavaz provides new insights into the APT group’s evolving tactics and the immediate threat it poses to sectors in the Middle East.
By: Mohamed Fahmy, Bahaa Yamany, Ahmed Kamal, Nick Dai Oct 11, 2024 Read time: ( words)
Save to Folio
## Summary
Trend Micro researchers have been monitoring a cyber espionage group known as Earth Simnavaz, also referred to as APT34 and OilRig, which has been actively targeting leading entities in the Middle East.
The group utilizes sophisticated tactics that include deploying backdoors that leverage Microsoft Exchange servers for credentials theft, and exploiting vulnerabilities like CV
Trendmicro
Earth Simnavaz (aka APT34) Levies Advanced Cyberattacks Against Middle East
blogs_trendmicro·2024-10-11·CVSS 7.0
[HIGH] Earth Simnavaz (aka APT34) Levies Advanced Cyberattacks Against Middle East
APT y ataques dirigidos
## Earth Simnavaz (aka APT34) Levies Advanced Cyberattacks Against Middle East
Trend Micro's investigation into the recent activity of Earth Simnavaz provides new insights into the APT group’s evolving tactics and the immediate threat it poses to sectors in the Middle East.
By: Mohamed Fahmy, Bahaa Yamany, Ahmed Kamal, Nick Dai Oct 11, 2024 Read time: ( words)
Save to Folio
## Summary
Trend Micro researchers have been monitoring a cyber espionage group known as Earth Simnavaz, also referred to as APT34 and OilRig, which has been actively targeting leading entities in the Middle East.
The group utilizes sophisticated tactics that include deploying backdoors that leverage Microsoft Exchange servers for credentials theft, and exploiting vulnerabilities like CVE-
Trendmicro
Earth Simnavaz (aka APT34) Levies Advanced Cyberattacks Against Middle East
blogs_trendmicro·2024-10-11·CVSS 7.0
[HIGH] Earth Simnavaz (aka APT34) Levies Advanced Cyberattacks Against Middle East
APT & Targeted Attacks
## Earth Simnavaz (aka APT34) Levies Advanced Cyberattacks Against Middle East
Trend Micro's investigation into the recent activity of Earth Simnavaz provides new insights into the APT group’s evolving tactics and the immediate threat it poses to sectors in the Middle East.
By: Mohamed Fahmy, Bahaa Yamany, Ahmed Kamal, Nick Dai 2024/10/11 Read time: ( words)
Save to Folio
## Summary
Trend Micro researchers have been monitoring a cyber espionage group known as Earth Simnavaz, also referred to as APT34 and OilRig, which has been actively targeting leading entities in the Middle East.
The group utilizes sophisticated tactics that include deploying backdoors that leverage Microsoft Exchange servers for credentials theft, and exploiting vulnerabilities like CVE-202
Trendmicro
Earth Simnavaz (aka APT34) Levies Advanced Cyberattacks Against Middle East
blogs_trendmicro·2024-10-11·CVSS 7.0
[HIGH] Earth Simnavaz (aka APT34) Levies Advanced Cyberattacks Against Middle East
APT & Targeted Attacks
## Earth Simnavaz (aka APT34) Levies Advanced Cyberattacks Against Middle East
Trend Micro's investigation into the recent activity of Earth Simnavaz provides new insights into the APT group’s evolving tactics and the immediate threat it poses to sectors in the Middle East.
By: Mohamed Fahmy, Bahaa Yamany, Ahmed Kamal, Nick Dai Oct 11, 2024 Read time: ( words)
Save to Folio
## Summary
Trend Micro researchers have been monitoring a cyber espionage group known as Earth Simnavaz, also referred to as APT34 and OilRig, which has been actively targeting leading entities in the Middle East.
The group utilizes sophisticated tactics that include deploying backdoors that leverage Microsoft Exchange servers for credentials theft, and exploiting vulnerabilities like CVE-2
Trendmicro
Earth Simnavaz (aka APT34) Levies Advanced Cyberattacks Against Middle East
blogs_trendmicro·2024-10-11·CVSS 7.0
[HIGH] Earth Simnavaz (aka APT34) Levies Advanced Cyberattacks Against Middle East
APT & Targeted Attacks
# Earth Simnavaz (aka APT34) Levies Advanced Cyberattacks Against Middle East
Trend Micro's investigation into the recent activity of Earth Simnavaz provides new insights into the APT group’s evolving tactics and the immediate threat it poses to sectors in the Middle East.
By: Mohamed Fahmy, Bahaa Yamany, Ahmed Kamal, Nick Dai
2024/10/11
Read time: ( words)
Save to Folio
#### Summary
- Trend Micro researchers have been monitoring a cyber espionage group known as Earth Simnavaz, also referred to as APT34 and OilRig, which has been actively targeting leading entities in the Middle East.
- The group utilizes sophisticated tactics that include deploying backdoors that leverage Microsoft Exchange servers for credentials theft, and exploiting vulnerabilities like CV
Tenable
Microsoft’s June 2024 Patch Tuesday Addresses 49 CVEs
blogs_tenable·2024-06-11
Microsoft’s June 2024 Patch Tuesday Addresses 49 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
The June 2024 Security Update Review
blogs_trendmicro·2024-06-11
The June 2024 Security Update Review
# The June 2024 Security Update Review
Get the June 2024 security update and review.
By: Dustin Childs
2024/06/11
Read time: ( words)
Save to Folio
Somehow, we’ve made it to the sixth patch Tuesday of 2024, and Microsoft and Adobe have released their regularly scheduled updates. Take a break from your regular activities and join us as we review the details of their latest security alerts. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for June 2024
For June, Adobe released 10 patches addressing 165(!) CVEs in Adobe Cold Fusion, Photoshop, Experience Manager, Audition, Media Encoder, FrameMaker Publishing Server, Adobe Commerce, Substance 3D Stager, Creative Cloud Desktop, and Acrobat Android. The fix for Experience Ma
Qualys
Microsoft & Adobe June 2024 Patch Tuesday: Critical Updates & Fixes | Qualys
blogs_qualys·2024-06-11
Microsoft & Adobe June 2024 Patch Tuesday: Critical Updates & Fixes | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for June 2024
- Adobe Patches for June 2024
- Zero-day Vulnerability Patched in June Patch Tuesday Edition
- Critical Severity Vulnerability Patched in June Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
- Rapid Response withPatch Management (PM)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- Qualys Monthly Webinar Series
Microsoft’s June Patch Tuesday is here, bringing fixes for vulnerabilities impacting its multiple products. This month’s release highlights the ongoing battle against cybersecurity threats, from critical updates to important fixes. Let’s dive into the crucial
Qualys
Microsoft and Adobe Patch Tuesday, June 2024 Security Update Review
blogs_qualys·2024-06-11
Microsoft and Adobe Patch Tuesday, June 2024 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for June 2024
Adobe Patches for June 2024
Zero-day Vulnerability Patched in June Patch Tuesday Edition
Critical Severity Vulnerability Patched in June Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
Rapid Response withPatch Management (PM)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Qualys Monthly Webinar Series
Microsoft’s June Patch Tuesday is here, bringing fixes for vulnerabilities impacting its multiple products. This month’s release highlights the ongoing battle against cybersecurity threats, from critical updates to important fixes. Let’s dive into the crucial insights fro
Talos
Only one critical issue disclosed as part of Microsoft Patch Tuesday
blogs_talos·2024-06-11·CVSS 8.0
CVE-2024-30080 [HIGH] Only one critical issue disclosed as part of Microsoft Patch Tuesday
Microsoft released its monthly security update Tuesday, disclosing 49 vulnerabilities across its suite of products and software.
Of those there is only one critical vulnerability. Every other security issues disclosed this month is considered "important."
The lone critical security issue is CVE-2024-30080, a remote code execution vulnerability due to a use-after-free (UAF) issue in the HTTP handling function of Microsoft Message Queuing (MSMQ) messages.
An adversary can send a specially crafted malicious MSMQ packet to an MSMQ server, potentially allowing them to perform remote code execution on the server side. Microsoft considers this vulnerability “more likely” to be exploited.
There is also a remote code execution vulnerability in Microsoft Outlook, CVE-2024-30103. By successfully
Trendmicro
The June 2024 Security Update Review
blogs_trendmicro·2024-06-11
The June 2024 Security Update Review
## The June 2024 Security Update Review
Get the June 2024 security update and review.
By: Dustin Childs 2024/06/11 Read time: ( words)
Save to Folio
Somehow, we’ve made it to the sixth patch Tuesday of 2024, and Microsoft and Adobe have released their regularly scheduled updates. Take a break from your regular activities and join us as we review the details of their latest security alerts. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for June 2024
For June, Adobe released 10 patches addressing 165(!) CVEs in Adobe Cold Fusion, Photoshop, Experience Manager, Audition, Media Encoder, FrameMaker Publishing Server, Adobe Commerce, Substance 3D Stager, Creative Cloud Desktop, and Acrobat Android. The fix for Experience Ma
Talos
Only one critical issue disclosed as part of Microsoft Patch Tuesday
blogs_talos·2024-06-11·CVSS 8.0
CVE-2024-30080 [HIGH] Only one critical issue disclosed as part of Microsoft Patch Tuesday
## Only one critical issue disclosed as part of Microsoft Patch Tuesday
Microsoft released its monthly security update Tuesday, disclosing 49 vulnerabilities across its suite of products and software.
Of those there is only one critical vulnerability. Every other security issues disclosed this month is considered "important."
The lone critical security issue is CVE-2024-30080 , a remote code execution vulnerability due to a use-after-free (UAF) issue in the HTTP handling function of Microsoft Message Queuing (MSMQ) messages.
An adversary can send a specially crafted malicious MSMQ packet to an MSMQ server, potentially allowing them to perform remote code execution on the server side. Microsoft considers this vulnerability “more likely” to be exploited.
There is also a remote code exec
Threat Intel
OilRig (OilRig, COBALT GYPSY, IRN2)
threat_intel
OilRig (OilRig, COBALT GYPSY, IRN2)
# Threat Actor Profile: OilRig
ATT&CK ID: G0049
Also known as: OilRig, COBALT GYPSY, IRN2, APT34, Helix Kitten, Evasive Serpens, Hazel Sandstorm, EUROPIUM, ITG13, Earth Simnavaz, Crambus, TA452
Suspected origin: Iran
## Overview
OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nati
2024-06-11
Published
2024-10-15
Added to CISA KEV
Exploited in the wild