{"id":24152,"date":"2024-03-13T08:10:09","date_gmt":"2024-03-13T16:10:09","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2024\/03\/13\/news-17882\/"},"modified":"2024-03-13T08:10:09","modified_gmt":"2024-03-13T16:10:09","slug":"news-17882","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2024\/03\/13\/news-17882\/","title":{"rendered":"Microsoft Patch Tuesday March 2024 includes critical Hyper-V flaws"},"content":{"rendered":"\n<p>The March 2024 Patch Tuesday update includes patches for <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2024-Mar\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">61 Microsoft vulnerabilities<\/a>. Only two of the vulnerabilities are rated critical and both of these are found in Windows Hyper-V.<\/p>\n<p>Hyper-V is a hardware virtualization product that allows you to run multiple operating systems as virtual machines (VMs) on Windows. A virtual machine is a computer program that emulates a physical computer. A physical \u201chost\u201d computer can run multiple separate \u201cguest\u201d VMs that are isolated from each other, and from the host. The physical resources of the host are allocated to the VMs by a software layer called the hypervisor, which acts an intermediary between the host and guests.<\/p>\n<p>The Common Vulnerabilities and Exposures (CVE) database lists publicly disclosed computer security flaws. The Hyper-V CVEs patched in this round of updates are:<\/p>\n<p><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-21407\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2024-21407<\/a> is a Windows Hyper-V Remote Code Execution (RCE) vulnerability with a <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2020\/05\/how-cvss-works-characterizing-and-scoring-vulnerabilities\">CVSS score<\/a> of 8.1 out of 10. Microsoft says exploitation is less likely since this vulnerability would require an authenticated attacker on a guest to send specially crafted file operation requests to hardware resources on the VM which could result in remote code execution on the host server.<\/p>\n<p>This means the attacker would need a good deal of information about the specific environment, and to take additional actions prior to exploitation to prepare the target environment.<\/p>\n<p><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-21408\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2024-21408<\/a> is a Windows Hyper-V Denial of Service (DOS) vulnerability with a CVSS score of 5.5 out of 10. This means an attacker could target a host machine from a guest and cause it to crash or stop functioning. However, Microsoft did not provide any additional details on how this DOS could occur.<\/p>\n<p>The attention for Hyper-V is remarkable since only a week earlier, VMware\u00a0<a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/03\/patch-now-vmware-escape-flaws-are-so-serious-even-end-of-life-software-gets-a-fix\" target=\"_blank\" rel=\"noreferrer noopener\">released security updates<\/a>\u00a0to fix critical sandbox escape vulnerabilities in VMware ESXi, Workstation, Fusion, and Cloud Foundation. VMware ESXi and Hyper-V are both designed to handle large-scale virtualization deployments.<\/p>\n<p>Another vulnerability worth mentioning is <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-21334\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2024-21334<\/a>, which has a CVSS score of 9.8 out of 10. It&#8217;s an Open Management Infrastructure (OMI) RCE vulnerability that affects System Center Operations Manager (SCOM). SCOM is a set of tools in Microsoft&#8217;s System Center for infrastructure monitoring and application performance management. A remote, unauthenticated attacker could exploit this vulnerability by accessing the OMI instance from the internet and sending specially crafted requests to trigger a use-after-free vulnerability.<\/p>\n<p>OMI is an open source technology for environment management software products for Linux and Unix-based systems. The OMI project was set up to implement standards-based management so that every device in the world can be managed in a clear, consistent, and coherent way.<\/p>\n<p>Use-after-free vulnerabilities are the result of the incorrect use of dynamic memory during a program\u2019s operation. If, after freeing a memory location, a program does not clear the pointer to that memory, an attacker can exploit the error to manipulate the program. Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.<\/p>\n<p>Microsoft states that if the Linux machines do not need network listening, OMI incoming ports can be disabled. In other cases, customers running affected versions of SCOM (System Center Operations Manager 2019 and 2022) should update to OMI version 1.8.1-0.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-other-vendors\">Other vendors<\/h2>\n<p>Other vendors have synchronized their periodic updates with Microsoft. Here are few major ones that you may find in your environment.<\/p>\n<p><strong>Adobe<\/strong>&nbsp;has released security updates to address vulnerabilities in several products:<\/p>\n<ul>\n<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/experience-manager\/apsb24-05.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Adobe Experience Manager<\/a><\/li>\n<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/premiere_pro\/apsb24-12.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Adobe Premiere Pro<\/a><\/li>\n<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb24-14.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Adobe ColdFusion<\/a><\/li>\n<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/bridge\/apsb24-15.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Adobe Bridge<\/a><\/li>\n<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/lightroom\/apsb24-17.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Adobe Lightroom<\/a><\/li>\n<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/animate\/apsb24-19.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Adobe Animate<\/a><\/li>\n<\/ul>\n<p>The&nbsp;<strong>Android<\/strong>&nbsp;Security Bulletin for February contains details of <a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2024-03-01\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">security vulnerabilities<\/a> for patch level 2024-03-05 or later.<\/p>\n<p><strong>Apple <\/strong>has released a <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/03\/update-your-iphones-and-ipads-now-apple-patches-security-vulnerabilities-in-ios-and-ipados\">security update for iOS and iPadOS<\/a> to patch two zero-day vulnerabilities<\/p>\n<p><strong>SAP<\/strong>&nbsp;has released its&nbsp;<a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/march-2024.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">March 2024 Patch Day<\/a>&nbsp;updates.<\/p>\n<hr class=\"wp-block-separator has-text-color has-cyan-bluish-gray-color has-alpha-channel-opacity has-cyan-bluish-gray-background-color has-background is-style-wide\" \/>\n<p><strong>We don\u2019t just report on vulnerabilities\u2014we identify them, and prioritize action.<\/strong><\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Keep vulnerabilities in tow by using\u00a0<a href=\"https:\/\/www.malwarebytes.com\/business\/vulnerability-patch-management\">ThreatDown Vulnerability and Patch Management<\/a>.<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/03\/microsoft-patch-tuesday-march-2024-includes-critical-hyper-v-flaws\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Microsoft patched 61 vulnerabilities in the March 2024 Patch Tuesday round, including two critical flaws in Hyper-V. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[31051,31066,31067,22783,20790,10516,32,31068,19245,31069],"class_list":["post-24152","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-cve-2024-21334","tag-cve-2024-21407","tag-cve-2024-21408","tag-exploits-and-vulnerabilities","tag-hyper-v","tag-microsoft","tag-news","tag-omi","tag-patch-tuesday","tag-scom"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24152","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=24152"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24152\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=24152"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=24152"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=24152"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}