CyberzSOC

Publication detail
← Back to advisories & guidance

2024-116: Microsoft November 2024 Patch Tuesday ↗ source

November 13, 2024 CERT-EU Advisory

Summary

Two of these zero-days, CVE-2024-43451 (NTLM Hash Disclosure Spoofing) and CVE-2024-49039 (Windows Task Scheduler Elevation of Privilege), have been actively exploited. These vulnerabilities allow attackers to potentially gain unauthorised access or escalate privileges through minimal user interaction or crafted applications [1-4]. capture NTLMv2 hashes through minimal interaction with a malicious file, enabling authentication as the compromised user [3]. Medium Integrity level, enabling attackers to execute RPC functions usually restricted to the P2 FROM header, causing spoofed emails to appear legitimate [1]. It is highly recommended to install the latest patch available to mitigates these vulnerabilities.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-49039 8.8 High Microsoft Windows Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate pri…
CVE-2024-49019 7.8 High Microsoft Windows Server 2019 Active Directory Certificate Services Elevation of Privilege Vulnerability
CVE-2024-49040 7.5 High Microsoft Microsoft Exchange Server 2019 Cumulative Update 13 Microsoft Exchange Server Spoofing Vulnerability
CVE-2024-43451 6.5 Medium Microsoft Windows Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open …

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.