CSIRT Toscana

Aggiornamenti Mensili Microsoft (AL01/240313/CSIRT-ITA)

Data:
13 Marzo 2024 07:00

Sintesi

Microsoft ha rilasciato gli aggiornamenti di sicurezza mensili che risolvono un totale di 60 nuove vulnerabilità.

Rischio

Stima d’impatto della vulnerabilità sulla comunità di riferimento: ALTO/ARANCIONE (66,41/100)1.

Tipologia

  • Remote Code Execution
  • Elevation of Privilege
  • Tampering
  • Security Feature Bypass
  • Information Disclosure
  • Spoofing
  • Denial of Service

Prodotti e versioni affette

  • .NET
  • Azure Data Studio
  • Azure SDK
  • Microsoft Authenticator
  • Microsoft Azure Kubernetes Service
  • Microsoft Dynamics
  • Microsoft Edge for Android
  • Microsoft Exchange Server
  • Microsoft Graphics Component
  • Microsoft Intune
  • Microsoft Office
  • Microsoft Office SharePoint
  • Microsoft QUIC
  • Microsoft Teams for Android
  • Microsoft WDAC ODBC Driver
  • Microsoft WDAC OLE DB provider for SQL
  • Microsoft Windows SCSI Class System File
  • Open Management Infrastructure
  • Outlook for Android
  • Skype for Consumer
  • Software for Open Networking in the Cloud (SONiC)
  • SQL Server
  • Visual Studio Code
  • Windows AllJoyn API
  • Windows Cloud Files Mini Filter Driver
  • Windows Composite Image File System
  • Windows Compressed Folder
  • Windows Defender
  • Windows Error Reporting
  • Windows Hyper-V
  • Windows Hypervisor-Protected Code Integrity
  • Windows Installer
  • Windows Kerberos
  • Windows Kernel
  • Windows NTFS
  • Windows ODBC Driver
  • Windows OLE
  • Windows Print Spooler Components
  • Windows Standards-Based Storage Management Service
  • Windows Telephony Server
  • Windows Update Stack
  • Windows USB Hub Driver
  • Windows USB Serial Driver

Azioni di mitigazione

In linea con le dichiarazioni del vendor, si raccomanda di procedere all’aggiornamento dei prodotti impattati attraverso l’apposita funzione di Windows Update.

Identificatori univoci vulnerabilità

CVE-ID
CVE-2024-26177 CVE-2024-21426 CVE-2024-21431 CVE-2024-26181
CVE-2024-21433 CVE-2024-21441 CVE-2024-21334 CVE-2024-21436
CVE-2024-21448 CVE-2024-20671 CVE-2024-26201 CVE-2024-26169
CVE-2024-21443 CVE-2024-21440 CVE-2024-26176 CVE-2024-26190
CVE-2024-21438 CVE-2024-21446 CVE-2024-26199 CVE-2024-21450
CVE-2023-28746 CVE-2024-21430 CVE-2024-21444 CVE-2024-26185
CVE-2024-26165 CVE-2024-26159 CVE-2024-26182 CVE-2024-26197
CVE-2024-26170 CVE-2024-26198 CVE-2024-26161 CVE-2024-21419
CVE-2024-21434 CVE-2024-26166 CVE-2024-21411 CVE-2024-21439
CVE-2024-21330 CVE-2024-26162 CVE-2024-21421 CVE-2024-21407
CVE-2024-26173 CVE-2024-26203 CVE-2024-21437 CVE-2024-21429
CVE-2024-21427 CVE-2024-21432 CVE-2024-26174 CVE-2024-26204
CVE-2024-26160 CVE-2024-26164 CVE-2024-21408 CVE-2024-21435
CVE-2024-21445 CVE-2024-21418 CVE-2024-26178 CVE-2024-21390
CVE-2024-21400 CVE-2024-21392 CVE-2024-21442 CVE-2024-21451

Riferimenti

https://msrc.microsoft.com/update-guide/releaseNote/2024-Mar

https://msrc.microsoft.com/update-guide (NB: filtro: patch tuesday – March 2024)

1La presente stima è effettuata tenendo conto di diversi parametri, tra i quali: CVSS, disponibilità di patch/workaround e PoC, diffusione dei software/dispositivi interessati nella comunità di riferimento.

Il presente articolo è un prodotto originale di csirt.gov.it, riproposto qui a solo scopo di aumentarne la visibilità.