Patch Tuesday Microsoft's monthly patch drop has arrived, delivering a mere 61 CVE-tagged vulnerabilities – none listed as under active attack or already known to the public. We'll hold our judgement until tomorrow to see if Exploit Wednesday lives up to its name. But in the meantime, here's a look at Redmond's security bugs. Two of the latest patches are listed as critical and both affect Windows Hyper-V hypervisor. Oddly, the two critical bugs didn't receive the highest CVSS ratings – but more on that in a bit. CVE-2024-21407, a critical remote code execution (RCE) vulnerability in Hyper-V with an 8.1 CVSS severity rating, is listed as "exploitation less likely" by Redmond. "This vulnerability would require an authenticated attacker on a guest VM to send specially crafted file operation requests on the VM to hardware resources on the VM which could result in remote code execution on the host server," according to the security update. The Zero Day Initiative's Dustin Childs noted that this type of flaw – often called a "guest-to-host escape" – could be used to manipulate other guest OSes on the server. "It's a shame we won't see this bug get exploited at Pwn2Own next week, where it could have won $250,000," Childs lamented. "Maybe next year." Or maybe on VMware, which last week revealed its own sandbox escape flaw. The second critical vulnerability, CVE-2024-21408, is a denial of service (DOS) flaw in Hyper-V that earned a 5.5 CVSS rating as it means an attacker could send a...
March Patch Tuesday fixes Hyper-V guest-host escape
The Register
·Jessica Lyons
·Published Mar 13, 2024
·Updated
Affected Software
20 affected components
Microsoft Hyper-V
Microsoft Open Management Infrastructure
Microsoft Azure Kubernetes Service Confidential Containers
Adobe Experience Manager
Adobe Premiere Pro
Adobe ColdFusion
Adobe Bridge
Adobe Lightroom
Adobe Animate
Intel Xeon processors
Intel BIOS firmware
SAP SAP Build Apps
SAP SAP NetWeaver AS Java
Cisco Cisco SD-WAN vManage software
Cisco Cisco Secure Client
Google Android
Fortinet FortiOS
Fortinet FortiProxy
Fortinet FortiClient Enterprise Management Server
Fortinet FortiWLM MEA for FortiManager
Frequently Asked Questions
1
What is the focus of the March 2024 Patch Tuesday article?
The article discusses the release of Microsoft's March Patch Tuesday, which addresses various vulnerabilities, including a Hyper-V guest-host escape issue.
2
How many vulnerabilities were addressed during this Patch Tuesday?
A total of 61 CVE-tagged vulnerabilities were addressed in the March 2024 Patch Tuesday update.
3
Which key Microsoft product had a critical vulnerability fixed?
Microsoft Hyper-V was highlighted as having a critical vulnerability fixed in the latest patch.
4
What type of vulnerabilities does the article mention are not present in this patch?
The article states that none of the fixed vulnerabilities are listed as under active attack or previously known to the public.
5
Which companies' products are mentioned as being affected by the March Patch Tuesday updates?
The affected products come from Microsoft, Adobe, Intel, SAP, Cisco, Fortinet, and Google.