CVE-2024-49026

Improper Neutralization of Special Elements used in a Command ('Command Injection') (CWE-77)

Published: Nov 12, 2024

010
CVSS 7.8EPSS 0.05%High
CVE info copied to clipboard

Summary

Microsoft Excel contains a Remote Code Execution Vulnerability. This is a Use After Free vulnerability that allows for Improper Neutralization of Special Elements used in a Command ('Command Injection'). The vulnerability has a CVSS v3.1 base score of 7.8, indicating high severity. It requires user interaction and has a local attack vector, but no privileges are required to exploit it.

Impact

If successfully exploited, this vulnerability could allow an attacker to execute arbitrary code with the same privileges as the user running Microsoft Excel. The impact on confidentiality, integrity, and availability is high, potentially leading to unauthorized access to sensitive information, modification of data, or disruption of system operations. Given the widespread use of Microsoft Excel in business environments, this vulnerability could have significant implications for organizational security if left unpatched.

Exploitation

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Patch

A patch is available for this vulnerability. Microsoft released a security update on November 12, 2024, to address this issue. The security team should prioritize applying this patch to all affected Microsoft Excel installations in the organization.

Mitigation

To mitigate this vulnerability, it is strongly recommended to apply the security update provided by Microsoft as soon as possible. In the meantime, implement the following measures: 1. Limit user permissions and implement the principle of least privilege to reduce the potential impact of exploitation. 2. Educate users about the risks of opening untrusted Excel files or clicking on suspicious links. 3. Consider using application whitelisting to prevent unauthorized executables from running. 4. Implement network segmentation to reduce the attack surface and limit lateral movement in case of a successful exploit. 5. Monitor for suspicious activities related to Microsoft Excel processes. 6. Keep all Microsoft Office products, especially Excel, up to date with the latest security patches.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Timeline

CVSS

A CVSS base score of 7.8 has been assigned.

Nov 12, 2024 at 5:55 PM / microsoft
First Article

Feedly found the first article mentioning CVE-2024-49026. See article

Nov 12, 2024 at 6:10 PM / Vulners.com RSS Feed
CVSS Estimate

Feedly estimated the CVSS score as HIGH

Nov 12, 2024 at 6:11 PM
CVE Assignment

NVD published the first details for CVE-2024-49026

Nov 12, 2024 at 6:15 PM
CVSS Estimate

Feedly estimated the CVSS score as MEDIUM

Nov 12, 2024 at 6:36 PM
Detection in Vulnerability Scanners

Detection for the vulnerability has been added to Nessus (210853)

Nov 13, 2024 at 2:15 AM
Detection in Vulnerability Scanners

Detection for the vulnerability has been added to Nessus (210854)

Nov 13, 2024 at 2:15 AM
EPSS

EPSS Score was set to: 0.05% (Percentile: 22.9%)

Nov 13, 2024 at 5:06 PM
EPSS

EPSS Score was set to: 0.05% (Percentile: 20.9%)

Nov 18, 2024 at 8:25 PM
Static CVE Timeline Graph

Affected Systems

Microsoft/office_long_term_servicing_channel
+null more

Patches

Microsoft
+null more

Attack Patterns

CAPEC-136: LDAP Injection
+null more

News

2024-45 - Adobe, Mozilla, Canonical, Red Hat, Microsoft, Google, Jenkins, GitHub, Spring 🗂️
Advisory Week Week 45, 2024 National Cyber Awareness System CISA Releases Nineteen Industrial Control Systems Advisories CISA Adds Two Known Exploited Vulnerabilities to Catalog Palo Alto Networks Emphasizes Hardening Guidance Fortinet Releases Security Updates for Multiple Products Microsoft Releases November 2024 Security Updates Adobe Releases Security Updates for Multiple Products Ivanti Releases Security Updates for Multiple Products JCDC’s Collaborative Efforts Enhance Cybersecurity for the 2024 Olympic and Paralympic Games Citrix Releases Security Updates for NetScaler and Citrix Session Recording CISA Releases Five Industrial Control Systems Advisories CISA, FBI, NSA, and International Partners Release Joint Advisory on 2023 Top Routinely Exploited Vulnerabilities CISA Adds Five Known Exploited Vulnerabilities to Catalog Adobe Security Bulletins and Advisories Security updates available for Adobe Photoshop APSB24-89 Security Updates Available for Adobe Commerce APSB24-90 Security Updates Available for Adobe Illustrator APSB24-66 APSB24-87 Security Update Available for Adobe InDesign APSB24-88 Security Updates Available for Adobe Bridge APSB24-77 Security Updates Available for Adobe Audition APSB24-83 Mozilla Security Advisories Security Vulnerabilities fixed in Thunderbird 132.0.1 mfsa2024-62 Security Vulnerabilities fixed in Thunderbird 128.4.3 mfsa2024-61 Ubuntu Security Notices Linux kernel vulnerabilities: USN-7089-6 / USN-7088-5 / USN-7089-5 / USN-7110-1 / USN-7089-4 / USN-7100-2 / USN-7100-1 GD Graphics Library vulnerability: USN-7112-1 Go vulnerabilities: USN-7111-1 / USN-7109-1 Linux kernel vulnerability:
Warning of 12 new vulnerabilities targeting domestic information systems - Vietnam.vn
... cyber attacks on systems in Vietnam. Through recording information ... Recently, Joint Stock Commercial Bank for Foreign Trade of Vietnam ...
Microsoft’s Security Update in November on High-Risk Vulnerabilities in Multiple Products
On November 13, NSFOCUS CERT detected that Microsoft released a security update patch for November, which fixed 89 security issues, including Windows, Microsoft SQL Server, Microsoft Office, Azure, Open Source Software, Microsoft Visual Studio, System Center and other widely used products, including high-risk vulnerabilities such as privilege escalation vulnerability and remote code execution vulnerability. Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Excel 2016 can no longer load add-ins after Nov. 2024 update KB5002653
A blog reader contacted me by email on November 13, 2024 and noted that after installing the KB5002653 update, no add-ins are loaded when Excel is started (I mentioned this in the article Patchday: Microsoft Office Updates (November 12, 2024) ). Blog reader kheldorn pointed in a comment to the reddit.com post Office addins broken after updates ?, where another user reports this error in Microsoft Excel 2016 and asks if anyone else is affected.
Excel 2016 can no longer load add-ins after Nov. 2024 update KB5002653
Blog reader kheldorn pointed in a comment to the reddit.com post Office addins broken after updates ?, where another user reports this error in Microsoft Excel 2016 and asks if anyone else is affected. A blog reader contacted me by email on November 13, 2024 and noted that after installing the KB5002653 update, no add-ins are loaded when Excel is started (I mentioned this in the article Patchday: Microsoft Office Updates (November 12, 2024) ).
See 33 more articles and social media posts

CVSS V3.1

Attack Vector:Local
Attack Complexity:Low
Privileges Required:None
User Interaction:Required
Scope:Unchanged
Confidentiality:High
Integrity:High
Availability Impact:High

Categories

Be the first to know about critical vulnerabilities

Collect, analyze, and share vulnerability reports faster using AI