CyberzSOC

Publication detail
← Back to advisories & guidance

2024-019: Critical Vulnerabilities in Microsoft Products ↗ source

February 14, 2024 CERT-EU Advisory

Summary

On February 13, 2024, Microsoft released its February 2024 Patch Tuesday advisory [1,2], addressing 73 vulnerabilities, two of which are exploited in the wild. It recommended applying updates as soon as possible on affected products. a malicious file, which could result in bypassing the SmartScreen user experience and potentially code injection into SmartScreen to achieve remote code execution. Microsoft has already seen evidence of exploitation in the wild. file can bypass the typical dialog, which warns that “files from the Internet can potentially harm your computer”. Microsoft has already seen evidence of exploitation in the wild. bypasses the Protected View Protocol, which leads to the leaking of local NTLM credential information and remote code execution (RCE). The Outlook Preview Pane is listed as an attack vector, and no user interaction is required. privilege vulnerability in Exchange. An attacker could use NTLM credentials previously acquired via another means to act as the victim on the Exchange server using an NTLM vulnerability in Defender for Endpoint Protection.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-21410 9.8 Critical Microsoft Exchange Server Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
CVE-2024-21413 9.8 Critical Microsoft Office Outlook Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerab…
CVE-2024-21412 8.1 High Microsoft Windows Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass.
CVE-2024-21315 7.8 High Microsoft Microsoft Defender for Endpoint for Windows Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability
CVE-2024-21351 7.6 High Microsoft Windows Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience and …

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.