6.5 CVE-2024-38213

CISA Kev Catalog Brute Force Patch
 

Windows Mark of the Web Security Feature Bypass Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2024-38213

Categories

CWE-NVD-noinfo

CWE-693 : Protection Mechanism Failure
This weakness covers three distinct situations. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.

References

secure@microsoft.com Patch


 

CPE

cpe start end
Configuration 1
cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:*:* < 10.0.10240.20680
cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:*:* < 10.0.14393.7070
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:* < 10.0.17763.5936
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:* < 10.0.19044.4529
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:* < 10.0.19045.4529
cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:* < 10.0.22000.3019
cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:* < 10.0.22621.3737
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:* < 10.0.22631.3737
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*:* < 6.2.9200.24919
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:* < 10.0.14393.7070
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:* < 10.0.17763.5936
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:* < 10.0.20348.2522
cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:* < 10.0.25398.950


REMEDIATION


Patch

Url
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38213


EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
No known exploits

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
1 Accessing Functionality Not Properly Constrained by ACLs
High
107 Cross Site Tracing
Very High
127 Directory Indexing
Medium
17 Using Malicious Files
Very High
20 Encryption Brute Forcing
Low
22 Exploiting Trust in Client
High
237 Escaping a Sandbox by Calling Code in Another Language
Very High
36 Using Unpublished Interfaces or Functionality
High
477 Signature Spoofing by Mixing Signed and Unsigned Content
High
480 Escaping Virtualization
Very High
51 Poison Web Service Registry
Very High
57 Utilizing REST's Trust in the System Resource to Obtain Sensitive Data
Very High
59 Session Credential Falsification through Prediction
High
65 Sniff Application Code
High
668 Key Negotiation of Bluetooth Attack (KNOB)
High
74 Manipulating State
High
87 Forceful Browsing
High


MITRE


Techniques

id description
T1040 Network Sniffing
T1083 File and Directory Discovery
T1565.002 Data Manipulation: Transmitted Data Manipulation
T1574.005 Hijack Execution Flow: Executable Installer File Permissions Weakness
T1574.010 Hijack Execution Flow: ServicesFile Permissions Weakness
T1611 Escape to Host
© 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Mitigations

id description
T1040 In cloud environments, ensure that users are not granted permissions to create or modify traffic mirrors unless this is explicitly required.
T1565.002 Encrypt all important data flows to reduce the impact of tailored modifications on data in transit.
T1574.005 Limit privileges of user accounts and groups so that only authorized administrators can interact with service changes and service binary target path locations. Deny execution from user directories such as file download directories and temp directories where able.
T1574.010 Limit privileges of user accounts and groups so that only authorized administrators can interact with service changes and service binary target path locations. Deny execution from user directories such as file download directories and temp directories where able.
T1611 Ensure containers are not running as root by default and do not use unnecessary privileges or mounted components. In Kubernetes environments, consider defining Pod Security Standards that prevent pods from running privileged containers.
© 2022 The MITRE Corporation. Esta obra se reproduce y distribuye con el permiso de The MITRE Corporation.