Exploits

Microsoft Discloses Actively Exploited Vulnerabilities in September 2024 Patch

Published  ·  2 min read

On Tuesday, Microsoft disclosed the active exploitation of three new security vulnerabilities as part of its Patch Tuesday update for September 2024. The monthly update addresses 79 vulnerabilities, including seven Critical, 71 Important, and one Moderate severity flaws. Additionally, 26 vulnerabilities in Chromium-based Edge have been resolved since last month's release.

Actively Exploited Vulnerabilities:

  1. CVE-2024-38014 (CVSS score: 7.8) – Windows Installer Elevation of Privilege Vulnerability.
  2. CVE-2024-38217 (CVSS score: 5.4) – Windows Mark-of-the-Web (MotW) Security Feature Bypass Vulnerability.
  3. CVE-2024-38226 (CVSS score: 7.3) – Microsoft Publisher Security Feature Bypass Vulnerability.
  4. CVE-2024-43491 (CVSS score: 9.8) – Microsoft Windows Update Remote Code Execution Vulnerability (Treated as actively exploited).

Exploitation of CVE-2024-38226 and CVE-2024-38217 can bypass critical security features that prevent Microsoft Office macros from running. Attackers need to convince targets to open a crafted file from an attacker-controlled server, with CVE-2024-38226 requiring the attacker to have local access to the system. The CVE-2024-43491 vulnerability, related to a rollback of fixes for Optional Components on Windows 10 (version 1507), allows attackers to exploit previously patched vulnerabilities on systems running outdated versions of Windows 10.

Fixes for CVE-2024-43491:

The issue can be resolved by installing the September 2024 Servicing Stack Update (SSU KB5043936) followed by the September 2024 Windows Security Update (KB5043083).

Additional Vulnerability Disclosures by Other Vendors:

Several other vendors have also released security updates to address vulnerabilities in their software products, including Adobe, Cisco, Fortinet, Google, Intel, Lenovo, Mozilla, SAP, and Zyxel. The vulnerabilities span various platforms, from operating systems to cloud services and hardware, reflecting a wide array of potential security risks.

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067