Fixes for two critical-severity Hyper-V bugs and an open Management Infrastructure (OMI) flaw with a CVSS v3 rating of 9.8 were among 60 vulnerabilities Microsoft addressed in this month’s Patch Tuesday releases.While March’s total patch count was relatively low and, according to Microsoft, did not include any actively exploited vulnerabilities, researchers still found several of the newly disclosed flaws “interesting”.Tenable research engineer Satnam Narang said this month’s patching of 60 CVEs compared to an average of 86 patches Microsoft had issued in March over the last four years. Numbers for the first quarter of the year were also down, with 181 CVEs patched so far in 2024 compared to an average of 237 during the first quarter between 2020 and 2023.“It’s unclear why there have been less CVEs patched this year. These numbers are more akin to the figures we saw in the first quarter of 2018 and 2019,” he said.Hyper-V and OMI flaws require urgent patchingThe software giant urged users to prioritize patching the two critical Hyper-V vulnerabilities. The first (tracked as CVE-2024-21407) allowed an attacker to remotely execute malicious code on a system running Hyper-V, opening the door for them to take complete control of the system.“This vulnerability stands out this month, and is uniquely alarming due to its direct enablement of code execution,” said Saeed Abbasi, vulnerability research manager at Qualys.Abbasi said while an attack exploiting the flaw was complex, requiring an attacker to gather environment-specific information, “this should not be a reason to delay patching, as the potential consequences of a successful exploit are severe”.The second Hyper-V bug (CVE-2024-21408) was a denial of service (Dos) vulnerability that could allow an attacker to crash the service, preventing access to virtual machine.“Microsoft does not indicate how extensive the DoS is or if the system automatically recovers, but considering its rating, the bug likely shuts down the entire system,” said Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative.The OMI vulnerability (CVE-2024-21334), with a near-maximum CVSS rating of 9.8 out of 10, allowed attackers to execute arbitrary code on exposed OMI instances by sending specially crafted requests that exploit a use-after-free error.“Given OMI's role in managing IT environments, the potential impact is vast, affecting potentially numerous systems accessible online,” Abbasi said.Childs added that while Microsoft considered it one of the vulnerabilities less likely to be exploited “it’s a very juicy target. It’s on TCP port 5986 by default, so I expect to see a lot of scanning on that port in the very near future”.
API security, Network Security
March Patch Tuesday: Microsoft fixes two critical Hyper-V flaws

An In-Depth Guide to Network Security
Get essential knowledge and practical strategies to fortify your network security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



