Patch Tuesday Drops: MSMQ RCE and Outlook Zero-Day Demand IMMEDIATE Attention
Heads up, folks! Microsoft just unleashed its June 2024 Patch Tuesday, and it’s a doozy. We’re talking critical remote code execution flaws and an actively exploited zero-day in Outlook that could be bad news for your organization.
The standout here is CVE-2024-30082[1], a critical Remote Code Execution (RCE) vulnerability in Microsoft Message Queuing (MSMQ) with a jaw-dropping CVSS score of 9.8. This beauty allows unauthenticated attackers to execute arbitrary code remotely by sending specially crafted MSMQ packets to a vulnerable server. If you’re running MSMQ, you’re exposed.
But wait, there’s more! We also have CVE-2024-30080[2], an elevation of privilege vulnerability in Microsoft Outlook that’s already being actively exploited in the wild. While not an RCE, its active exploitation makes it a top-tier threat. Attackers could gain SYSTEM privileges, making it a serious headache.
Okay, so what does this mean for you, the brave soul managing servers or writing code? Simple: Patch. Now. The MSMQ vulnerability (CVE-2024-30082) is a network-exploitable RCE, meaning attackers don’t need user interaction. If your MSMQ port (1801, 2103, 2105, 2107) is exposed, even internally, you’re a prime target. For the Outlook zero-day (CVE-2024



