* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Wednesday, July 16, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Black River Entertainment Adds Traci Hite As Director Of Promotion, Southeast – MusicRow.com

    Black River Entertainment Welcomes Traci Hite as New Director of Southeast Promotion

    Entertainment Business Master’s Grad Launched Nonprofit to Nurture Emerging Artists – Full Sail University

    Entertainment Business Master’s Grad Launched Nonprofit to Nurture Emerging Artists – Full Sail University

    Review: At the Huntington, the New Hollywood String Quartet recalls legendary studio musicians – Los Angeles Times

    Review: At the Huntington, the New Hollywood String Quartet recalls legendary studio musicians – Los Angeles Times

    Kehoe repeals paid sick leave, allows several counties in the Ozarks to have entertainment districts in bill signings – KY3

    Kehoe repeals paid sick leave, allows several counties in the Ozarks to have entertainment districts in bill signings – KY3

    Emily Deschanel was scolded during “Bones” season 1 for being ‘late and unprepared’: ‘I was just beside myself’ – Yahoo

    Emily Deschanel was scolded during “Bones” season 1 for being ‘late and unprepared’: ‘I was just beside myself’ – Yahoo

    How you can see new movies early – Yahoo

    Unlock the Secret to Watching New Movies Before Everyone Else!

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Guest columnist: China cutting corners on technology – The State Journal

    China’s Rapid Tech Advances Spark Worries About Cutting Corners

    Sentrycs’ Cyber Over RF technology integrated into Rafael’s combat-proven Drone Dome system – Defence Industry Europe

    Sentrycs’ Cyber Over RF Technology Boosts Rafael’s Battle-Tested Drone Dome System

    Nordic Air Defence raises $3 million to expand operations and advance drone defence technology – Defence Industry Europe

    Nordic Air Defence Lands $3 Million to Transform Drone Defense and Supercharge Operations

    China’s energy dominance in three charts – MIT Technology Review

    How China Is Powering Its Energy Dominance: A Visual Breakdown

    Meta Acquires AI Startup PlayAI to Enhance Voice Technology Capa – GuruFocus

    Meta Acquires AI Startup PlayAI to Revolutionize Voice Technology Capabilities

    Stallion Uranium Provides Update on Technology Data Acquisition Agreement – GlobeNewswire

    Stallion Uranium Announces Exciting Progress in Technology Data Acquisition Agreement

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Black River Entertainment Adds Traci Hite As Director Of Promotion, Southeast – MusicRow.com

    Black River Entertainment Welcomes Traci Hite as New Director of Southeast Promotion

    Entertainment Business Master’s Grad Launched Nonprofit to Nurture Emerging Artists – Full Sail University

    Entertainment Business Master’s Grad Launched Nonprofit to Nurture Emerging Artists – Full Sail University

    Review: At the Huntington, the New Hollywood String Quartet recalls legendary studio musicians – Los Angeles Times

    Review: At the Huntington, the New Hollywood String Quartet recalls legendary studio musicians – Los Angeles Times

    Kehoe repeals paid sick leave, allows several counties in the Ozarks to have entertainment districts in bill signings – KY3

    Kehoe repeals paid sick leave, allows several counties in the Ozarks to have entertainment districts in bill signings – KY3

    Emily Deschanel was scolded during “Bones” season 1 for being ‘late and unprepared’: ‘I was just beside myself’ – Yahoo

    Emily Deschanel was scolded during “Bones” season 1 for being ‘late and unprepared’: ‘I was just beside myself’ – Yahoo

    How you can see new movies early – Yahoo

    Unlock the Secret to Watching New Movies Before Everyone Else!

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Guest columnist: China cutting corners on technology – The State Journal

    China’s Rapid Tech Advances Spark Worries About Cutting Corners

    Sentrycs’ Cyber Over RF technology integrated into Rafael’s combat-proven Drone Dome system – Defence Industry Europe

    Sentrycs’ Cyber Over RF Technology Boosts Rafael’s Battle-Tested Drone Dome System

    Nordic Air Defence raises $3 million to expand operations and advance drone defence technology – Defence Industry Europe

    Nordic Air Defence Lands $3 Million to Transform Drone Defense and Supercharge Operations

    China’s energy dominance in three charts – MIT Technology Review

    How China Is Powering Its Energy Dominance: A Visual Breakdown

    Meta Acquires AI Startup PlayAI to Enhance Voice Technology Capa – GuruFocus

    Meta Acquires AI Startup PlayAI to Revolutionize Voice Technology Capabilities

    Stallion Uranium Provides Update on Technology Data Acquisition Agreement – GlobeNewswire

    Stallion Uranium Announces Exciting Progress in Technology Data Acquisition Agreement

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Hyper-V zero-day stands out on a busy Patch Tuesday

July 10, 2024
in Technology
Hyper-V zero-day stands out on a busy Patch Tuesday
Share on FacebookShare on Twitter

Microsoft has fixed almost 140 vulnerabilities in its latest monthly update, with a Hyper-V zero-day singled out for urgent attention


Alex Scroxton

By

Alex Scroxton,
Security Editor

Published: 09 Jul 2024 20:36

Security teams will have a busy few days ahead of them after Microsoft patched close to 140 new common vulnerabilities and exposures (CVEs) in its July Patch Tuesday update, including four zero-day exploits – one of them a third-party update via processor giant ARM.

The four zero-days are listed, in numerical order, as follows:

CVE-2024-35264, a remote code execution (RCE) vulnerability in .NET and Visual Studio. This vulnerability carries a CVSS score of 8.1, but in contrast, while a proof-of-concept exploit is circulating it does not yet seem to have been taken advantage of;
CVE-2024-37895, an information disclosure vulnerability affecting ARM. This bug carries a CVSS score of 5.9, but although it has been made public is also not yet being exploited;
CVE-2024-38080, an elevation of privilege (EoP) flaw in Windows Hyper-V. This vulnerability carries a CVSS score of 7.8, and is known to have been exploited in the wild, although no public exploit has been published;
CVE-2024-38112, a spoofing vulnerability in Windows MSHTML Platform. This vulnerability carries a CVSS score of 7.5. No public exploit is available but it is being used by as-yet unknown adversaries.

Zeroing in on the Hyper-V flaw, Mike Walters of patch management specialist Action1 said it posed “significant risk” to systems utilising Hyper-V – it appears relatively simple to exploit, with an attacker being able to gain admin rights with ease if they have obtained initial local access via, for example, a compromised user account within a virtual machine. Ultimately, it takes advantage of an integer overflow issue within Hyper-V.

“CVE-2024-38080 …  highlights a clear avenue for attackers to gain elevated privileges, jeopardising the confidentiality, integrity, and availability of multiple virtualised systems,” said Walters.

“When combined with other vulnerabilities such as remote code execution flaws or initial access exploits such as phishing or exploit kits, the attack vector becomes more sophisticated and damaging.

“Adopting a proactive security approach, including timely patching and strict adherence to robust security practices, is crucial for mitigating these risks effectively,” he added.

Saeed Abbasi, product manager, vulnerability at Qualys’ Threat Research Unit (TRU) added: “The impact is enormous since this vulnerability could grant attackers the highest level of system access that could enable the deployment of ransomware and other malicious attacks.

“While Microsoft has not disclosed the extent of active exploitation, the nature of the vulnerability makes it a prime target for attackers. Due to its potential for deep system control, this vulnerability is poised for increased exploitation attempts. The combination of low complexity and no user interaction requirement means it is likely to be rapidly incorporated into exploit kits, leading to widespread exploitation.

Abbasi added: “Furthermore, the ability to escalate privileges makes this vulnerability particularly detrimental for ransomware attacks, as it enables attackers to turn off security measures and spread more effectively across networks, thereby significantly amplifying the impact of such attacks.”

Meanwhile, Rob Reeves, principal cyber security engineer at Immersive Labs, ran the rule over the Windows MSHTLM platform vuln. “Details from Microsoft are scarce and only described as a ‘spoofing’ vulnerability, which requires social engineering in order to convince a user to execute a delivered file,” he said.

“It is assessed that the vulnerability likely might lead to remote Code execution, because of its linking to CWE-668: Exposure of Resource to Wrong Sphere and in the event of successful exploitation, leads to complete compromise of confidentiality, integrity and availability. The CVSS score of only 7.5, due to the difficulty in exploiting, is possibly only due to the complexity of the attack itself.

Reeves said that without more details from Microsoft or the original reporter – a Check Point researcher – it was hard to give specific guidance on next steps, but that given it affects all hosts from Windows Server 2008 R2 and beyond – including clients – and is seeing active exploitation, it should be prioritised for patching without delay.

In addition to the zero-days, the July 2024 update also lists five critical flaws, all RCE vulnerabilities, carrying CVSS scores of 7.2 to 9.8. Three of these relate to Windows Remote Desktop Licensing Service, one to Microsoft Windows Codecs Library, and the fifth to Microsoft SharePoint Server.

Gamers beware

Finally, another RCE vulnerability in the Xbox Wireless Adapter has also drawn some attention, aptly demonstrating the importance of securing consumer devices and networks, which can be just as useful an element of a threat actor’s attack chain as any cloud server vulnerability affecting an enterprise.

Tracked as CVE-2024-38078, the flaw becomes exploitable if an attacker is in close physical proximity of the target system and has gathered specific information on the target environment.

Although this complexity makes it less likely it will be exploited, if it was to happen, an attacker could send a malicious networking packet to an adjacent system employing the adapter, and from there achieve RCE.

“In a work-from-home setup, securing all devices, including IoT devices like alarm systems and smart TVs, is essential. Attackers can exploit this vulnerability to gain unauthorised access and compromise sensitive information. The distance with which Wi-Fi signals can be detected, intercepted, and broadcasted is commonly underestimated, further heightening the risk of this vulnerability,” said Ryan Braunstein, Automox security operations team lead.

“To mitigate these threats, apply regular updates to all devices and adopt strong network security measures like robust passwords and encryption.

“Educating all employees, friends, and family members about the importance of keeping devices patched and updated may not make you popular at parties, but can definitely reduce the 2am phone calls,” added Braunstein.

Read more on Application security and coding requirements


SolarWinds Serv-U vulnerability under attack

ArielleWaldman

By: Arielle Waldman


Black Basta ransomware crew may be exploiting Microsoft zero-day

AlexScroxton

By: Alex Scroxton


RCE flaw and DNS zero-day top list of Patch Tuesday bugs

AlexScroxton

By: Alex Scroxton


Microsoft delivers 51 fixes for June Patch Tuesday

TomWalat

By: Tom Walat

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : Computer Weekly – https://www.computerweekly.com/news/366592779/Hyper-V-zero-day-stands-out-on-a-busy-Patch-Tuesday

Tags: Hyper-Vtechnologyzero-day
Previous Post

Chinese spies target vulnerable home office kit to run cyber attacks

Next Post

Non-Fungible Tokens (NFTs) and Brand Building

The Bird Flu Story No One Is Telling – Scientific American

The Untold Story of Bird Flu: What You Need to Know

July 15, 2025
Combining science and policy for a unified global soil biodiversity observatory – Nature

Building a Global Soil Biodiversity Observatory: Bridging Science and Policy for a Sustainable Future

July 15, 2025
Quality of scientific papers questioned as academics ‘overwhelmed’ by the millions published – The Guardian

Are Scientific Papers Losing Quality as Academics Struggle to Keep Up with Millions Published?

July 15, 2025
Lower your risk of early death by some 40% with this lifestyle change – CNN

Lower your risk of early death by some 40% with this lifestyle change – CNN

July 15, 2025
Palmer leads Chelsea to incredible, improbable Club World Cup romp over PSG – ESPN

Palmer leads Chelsea to incredible, improbable Club World Cup romp over PSG – ESPN

July 15, 2025
Feds Collins: solid economy gives Fed time to decide its next interest rate move – Forexlive | Forex News, Technical Analysis & Trading Tools

Feds Collins: solid economy gives Fed time to decide its next interest rate move – Forexlive | Forex News, Technical Analysis & Trading Tools

July 15, 2025
Black River Entertainment Adds Traci Hite As Director Of Promotion, Southeast – MusicRow.com

Black River Entertainment Welcomes Traci Hite as New Director of Southeast Promotion

July 15, 2025
Stormont Vail Health dermatology specialist talks sun safety at walk with an APP – WIBW

Top Dermatology Tips for Staying Safe in the Sun During Your Next Community Walk

July 15, 2025
Young voters seek authentic representation in politics, says Brett Cooper – Fox News

Young Voters Rally for True Representation in Politics, Urging Real Change

July 15, 2025
Guest columnist: China cutting corners on technology – The State Journal

China’s Rapid Tech Advances Spark Worries About Cutting Corners

July 15, 2025

Categories

Archives

July 2025
MTWTFSS
 123456
78910111213
14151617181920
21222324252627
28293031 
« Jun    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (722)
  • Economy (745)
  • Entertainment (21,632)
  • General (15,913)
  • Health (9,783)
  • Lifestyle (753)
  • News (22,149)
  • People (747)
  • Politics (756)
  • Science (15,964)
  • Sports (21,243)
  • Technology (15,729)
  • World (729)

Recent News

The Bird Flu Story No One Is Telling – Scientific American

The Untold Story of Bird Flu: What You Need to Know

July 15, 2025
Combining science and policy for a unified global soil biodiversity observatory – Nature

Building a Global Soil Biodiversity Observatory: Bridging Science and Policy for a Sustainable Future

July 15, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version