Saturday, July 19, 2025
  • Login
No Result
View All Result
APN News
  • News
    • National
    • International
    • States
    • Views
    • Crime & Corruption
    • Headlines
    • Breaking News
    • Canada’s privacy commissioner launches investigation over the use of facial recognition technology
  • Business
    • Banking
    • Finance
    • Economy
    • Be an informer to I-T dept; earn up to Rs 5 crore
    • Markets
  • Tech & Industry
    • Tech
    • Auto
    • Information Technology
    • Telecom
    • Oil & Natural Gas
    • Gravitational wave event likely signaled birth of black hole
  • Entertainment
    • Malayalam Film
    • Media
    • Music
    • Shawn Mendes Released Highly Anticipated Self-Titled Album Today
    • Youth
      • Fashion
      • Kids
      • Life Style
  • Education
    • Campus News
    • ITM University, Gurgaon Student Palash Chhabra Represents Varsity at Google Student Ambassador Summit
  • Health
    • Medical News
    • Maharshi Shushruta, The Great Grandfather of Surgery!
  • Tourism
    • Travel
    • Food&Beverages
    • “Keraliya Ayurveda is Credible and Authentic”
    • Hospitality
  • Sports
  • Editor’s column
  • Magazine
  • News
    • National
    • International
    • States
    • Views
    • Crime & Corruption
    • Headlines
    • Breaking News
    • Canada’s privacy commissioner launches investigation over the use of facial recognition technology
  • Business
    • Banking
    • Finance
    • Economy
    • Be an informer to I-T dept; earn up to Rs 5 crore
    • Markets
  • Tech & Industry
    • Tech
    • Auto
    • Information Technology
    • Telecom
    • Oil & Natural Gas
    • Gravitational wave event likely signaled birth of black hole
  • Entertainment
    • Malayalam Film
    • Media
    • Music
    • Shawn Mendes Released Highly Anticipated Self-Titled Album Today
    • Youth
      • Fashion
      • Kids
      • Life Style
  • Education
    • Campus News
    • ITM University, Gurgaon Student Palash Chhabra Represents Varsity at Google Student Ambassador Summit
  • Health
    • Medical News
    • Maharshi Shushruta, The Great Grandfather of Surgery!
  • Tourism
    • Travel
    • Food&Beverages
    • “Keraliya Ayurveda is Credible and Authentic”
    • Hospitality
  • Sports
  • Editor’s column
  • Magazine
No Result
View All Result
APN News
No Result
View All Result
Home General

May 2024 Patch Tuesday: Comment from Satnam Narang, Sr. Staff Research Engineer, Tenable

by NS
May 15, 2024
in General
0
0
SHARES
29
VIEWS
Share on FacebookShare on Twitter

 “Microsoft patched 59 CVEs in its May 2024 Patch Tuesday release, down from 147 CVEs last month, which was the highest in Patch Tuesday history. 

“This month, Microsoft patched two zero-day vulnerabilities that were exploited in the wild – CVE-2024-30051, an elevation of privilege flaw in the DWM Core Library in Microsoft Windows and CVE-2024-30040, a security feature bypass in the MSHTML (Trident) Engine in Microsoft Windows.

“CVE-2024-30051 is used as part of post-compromise activity to elevate privileges as a local attacker. Typically, zero-day exploitation of an elevation of privilege flaw is often associated with targeted attack campaigns. However, we know that post-patch, threat actors continue to find success using privilege escalation flaws. For instance, a recent joint cybersecurity advisory about the Black Basta ransomware group from CISA, FBI, HHS and MS-ISAC notes the use of multiple privilege escalation flaws by Black Basta affiliates as part of their ransomware activity. CVE-2024-30051 is used to gain initial access into a target environment and requires the use of social engineering tactics via email, social media or instant messaging to convince a target to open a specially crafted document file. Once exploited, the attacker can bypass OLE mitigations in Microsoft 365 and Microsoft Office, which are security features designed to protect end users from malicious files.

“CVE-2024-30051 is the second DWM Core Library zero day that was exploited in the wild in at least the last six months. Microsoft patched CVE-2023-36033 in November 2023. No details are public at this time for either flaw, but it is possible that in-the-wild exploitation may be linked to the same threat actor either through the discovery of another privilege escalation flaw in the same library. Alternatively,CVE-2024-30051 could be the result of a patch bypass–an incomplete fix for CVE-2023-36033.

“CVE-2024-30040 is the first vulnerability in MSHTML disclosed in 2024. It was preceded by eight MSHTML vulnerabilities that were patched in 2023 from February 2023 through December 2023. Of the previous eight flaws, CVE-2023-32046, an elevation of privilege vulnerability, was the only one exploited in the wild as a zero-day and patched in July 2023.

“The SharePoint vulnerability (CVE-2024-30044) is notable as it is the only vulnerability rated as “Critical” in this month’s release. While this vulnerability is also considered one of several vulnerabilities that are more likely to be exploited, exploitation requires an attacker to be authenticated to a vulnerable SharePoint Server with Site Owner permissions (or higher) first and to take additional steps in order to exploit this flaw, which makes this flaw less likely to be widely exploited as most attackers follow the path of least resistance.” – Satnam Narang, Sr. Staff Research Engineer, Tenable

NS

NS

Next Post
SOCC Unveils A New Era In Paediatric Care: Second Opinion Online Consultations For Children

SOCC Unveils A New Era In Paediatric Care: Second Opinion Online Consultations For Children

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent News

Supernatural thriller Nikita Roy starring Sonakshi Sinha collects 1 cr + worldwide, sees rising audience demand

Supernatural thriller Nikita Roy starring Sonakshi Sinha collects 1 cr + worldwide, sees rising audience demand

July 19, 2025
Hon’ble Prime Minister Laid The Foundation Stone of Rs 1950 Crore City Gas Distribution (CGD) Project in Bankura and Purulia Districts of West Bengal

Hon’ble Prime Minister Laid The Foundation Stone of Rs 1950 Crore City Gas Distribution (CGD) Project in Bankura and Purulia Districts of West Bengal

July 19, 2025
National Workshop Advances Integration of Vocational Education: State Boards Stepping into Dual Role as Awarding Bodies

National Workshop Advances Integration of Vocational Education: State Boards Stepping into Dual Role as Awarding Bodies

July 19, 2025
MIT-WPU Hosts NSRTC 2025, Uniting India’s Top Scientific Minds to Drive Innovation for 2047 Vision

MIT-WPU Hosts NSRTC 2025, Uniting India’s Top Scientific Minds to Drive Innovation for 2047 Vision

July 19, 2025

CII IGBC Strengthens Andhra Pradesh’s Green Vision with Capacity Building Programme for APCRDA Officials

July 19, 2025

APNNEWS owned by a Group of Journalists is a 24 X 7 news portal spearheaded by veteran journalist Suresh Kumar.

Facebook Twitter Youtube

Categories

  • Corporate News
  • Finance
  • Tech & Industry
  • Education
  • Health
  • Life Style
  • Real Estate
  • Sports
  • Entertainment
  • New Products
  • Environment
  • Religion

Company

  • About Us
  • Terms of Service
  • Disclaimer
  • Contact Us
  • APN NEWS RSS
  • Advertise with Us
  • Your Ad Choices

APNNEWS owned by a Group of Journalists is a 24 X 7 news portal spearheaded by veteran journalist Suresh Kumar.

Facebook X-twitter Youtube
  • About Us
  • Terms of Service
  • Your Ad Choices
  • Advertise with Us
  • Contact Us
  • Disclaimer

© 2024 APN NEWS, All Rights Reserved.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • News
    • National
    • International
    • States
    • Views
    • Crime & Corruption
    • Headlines
    • Breaking News
    • Canada’s privacy commissioner launches investigation over the use of facial recognition technology
  • Business
    • Banking
    • Finance
    • Economy
    • Be an informer to I-T dept; earn up to Rs 5 crore
    • Markets
  • Tech & Industry
    • Tech
    • Auto
    • Information Technology
    • Telecom
    • Oil & Natural Gas
    • Gravitational wave event likely signaled birth of black hole
  • Entertainment
    • Malayalam Film
    • Media
    • Music
    • Shawn Mendes Released Highly Anticipated Self-Titled Album Today
    • Youth
      • Fashion
      • Kids
      • Life Style
  • Education
    • Campus News
    • ITM University, Gurgaon Student Palash Chhabra Represents Varsity at Google Student Ambassador Summit
  • Health
    • Medical News
    • Maharshi Shushruta, The Great Grandfather of Surgery!
  • Tourism
    • Travel
    • Food&Beverages
    • “Keraliya Ayurveda is Credible and Authentic”
    • Hospitality
  • Sports
  • Editor’s column
  • Magazine

© 2024 APN NEWS, All Rights Reserved.