Full Report
The Patch Tuesday for November of 2024 includes 91 vulnerabilities, including two that Microsoft marked as “critical.” The remaining 89 vulnerabilities listed are classified as “important.”
Analysis Summary
# Vulnerability: November 2024 Microsoft Patch Tuesday Summary (Focusing on Critical and Exploited Issues)
## CVE Details
This summary focuses on the four "Critical" vulnerabilities and identified "Important" vulnerabilities with active exploitation or high likelihood of exploitation.
- **CVE ID:** CVE-2024-43639 (Critical)
- **CVE ID:** CVE-2024-43625 (Critical)
- **CVE ID:** CVE-2024-43602 (Critical)
- **CVE ID:** CVE-2024-43498 (Critical)
- **CVE ID:** CVE-2024-43451 (Important - Exploitation Detected)
- **CVE ID:** CVE-2024-49039 (Important - Exploitation Detected)
- **CVSS Score:** Not explicitly provided for all, generally inferred as High/Critical based on classification.
- **CWE:** Varies (Cryptography Error, Use-After-Free, etc.)
## Affected Systems
- **Products:** Windows (General), Hyper-V, Azure CycleCloud, .NET, Visual Studio, Microsoft Word, Windows NT OS Kernel, Windows DWM Core Library, Windows Kernel, Win32k, Active Directory Certificate Services, Windows SMB.
- **Versions:** Specific versions are not detailed in this summary, users must consult the Microsoft MSRC update guide.
- **Configurations:** Varies by CVE (e.g., requires basic user privileges for CVE-2024-43602, involves Windows networking stack for CVE-2024-43625).
## Vulnerability Description
The November 2024 Patch Tuesday release addresses 89 vulnerabilities, four of which are marked as "Critical."
1. **CVE-2024-43639 (RCE in Windows Kerberos):** A flaw in the Windows Kerberos cryptographic protocol that allows an attacker to achieve Remote Code Execution (RCE) by crafting a malicious application.
2. **CVE-2024-43625 (EoP in Hyper-V VMSwitch Driver):** A Use-After-Free vulnerability in the Hyper-V networking component (VMSwitch driver). An attacker sends specific network packets to the driver to exploit the UAF, gaining arbitrary code execution with elevated privileges on the host.
3. **CVE-2024-43602 (RCE in Azure CycleCloud):** An RCE flaw in Azure CycleCloud. An attacker with basic user privileges can exploit this by sending crafted packets to the cluster to achieve root access.
4. **CVE-2024-43498 (RCE in .NET/Visual Studio):** An RCE vulnerability in .NET and Visual Studio accessible to remote attackers by sending crafted packets to vulnerable web applications or loading crafted files.
5. **CVE-2024-43451 (NTLM Hash Disclosure):** A spoofing vulnerability that results in NTLM hash disclosure.
6. **CVE-2024-49039 (EoP in Windows Task Scheduler):** Privilege escalation flaw in the Task Scheduler.
## Exploitation
### Critical Flaws Status
- **CVE-2024-43639, CVE-2024-43625, CVE-2024-43602, CVE-2024-43498:** Exploitation status is **"Less likely,"** and active in-the-wild exploitation has **not** been detected by Microsoft.
### Important Flaws Status
- **CVE-2024-43451 & CVE-2024-49039:** Exploitation has been **detected** by Microsoft.
- **CVE-2024-49033, CVE-2024-43623, CVE-2024-43629, CVE-2024-43630, CVE-2024-43636, CVE-2024-49019, CVE-2024-43642:** Exploitation is assessed as **"More likely."**
- **Complexity:** Varies. CVE-2024-43625 is listed as **High**. Others are implied to be Low/Medium given the general classifications and RCE nature of some.
- **Attack Vector:** Primarily **Network** (for RCEs) or potentially **Local** for some EoP flaws.
## Impact
- **Confidentiality:** High (due to RCE capabilities).
- **Integrity:** High (due to RCE and Privilege Escalation capabilities).
- **Availability:** Medium to High (RCE or DoS potential varies).
## Remediation
### Patches
All identified vulnerabilities are addressed in the November 2024 Patch Tuesday updates. Users must apply the relevant security updates released on this date.
### Workarounds
No specific workarounds were detailed in the context for the "Critical" or exploited vulnerabilities, beyond the application of the official patches.
## Detection
- **Indicators of Compromise (IOCs):** Not specifically listed, but monitoring for unusual network traffic directed at Kerberos services (CVE-2024-43639) or Hyper-V host interaction (CVE-2024-43625) is advisable.
- **Detection Methods and Tools:**
* Talos is releasing new **Snort** rules: **62022, 62023, 64218-64224, 64229, 64232, and 64233.**
* Snort 3 rules released: **301064, 300612, 301065, 301066, and 301073.**
* Cisco Firewall customers should update their **SRU** (Security Response Update).
## References
- Vendor Advisories: Microsoft Security Response Center (MSRC) Update Guide (General Link: `msrc.microsoft.com/update-guide/`)
- Specific CVE links (use MSRC portal for viewing):
- CVE-2024-43639
- CVE-2024-43625
- CVE-2024-43602
- CVE-2024-43498
- CVE-2024-49033
- CVE-2024-43623
- CVE-2024-43629
- CVE-2024-43630
- CVE-2024-43636
- CVE-2024-49019
- CVE-2024-43642
- CVE-2024-43451
- CVE-2024-49039