Microsoft patched CVE-2024-38061, an Important-severity Windows DCOM vulnerability that could let low-privileged users remotely activate a DCOM application on a domain controller and coerce NTLM authentication from a privileged interactive user. The issue affected scenarios in which members of groups such as Distributed COM Users or Performance Log Users could trigger sppui/slui.exe under the logged-on user’s context, potentially targeting Domain Administrator sessions.
An attacker could capture the coerced authentication and relay it to services such as SMB, including systems supporting Active Directory Certificate Services (AD CS), to obtain further privileges. Researchers demonstrated a path from relayed authentication to compromise of an AD CS server and ultimately Domain Admin access through certificate abuse; organizations should apply Microsoft’s update and treat the affected DCOM group memberships as Tier 0 privileges, while using protections such as Protected Users for administrative accounts to reduce NTLM-relay exposure.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Researchers submitted alleged Task Scheduler credential-based UAC-bypass and task-metadata log-poisoning findings to MSRC. MSRC reportedly said RegistrationInfo metadata is general descriptive data and did not consider the reported findings vulnerabilities.
Microsoft fixed the DCOM permissions bug during the July 2024 Patch Tuesday release and assigned it CVE-2024-38061 with an Important severity rating.
MSRC initially classified the DCOM issue as a critical fix, then downgraded its assessment to moderate severity and did not immediately service it.
A researcher disclosed a Windows DCOM permissions issue involving the sppui/slui.exe DCOM application to Microsoft Security Response Center. The issue allowed members of Distributed COM Users or Performance Log Users to remotely activate the object and coerce authentication from an interactive privileged user.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cymulate.com
Open sourcedecoder.cloud
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.