Quantcast
Channel: eternal-todo.com aggregator
Viewing all articles
Browse latest Browse all 12054

SANS Internet Storm Center, InfoCON: green: Microsoft May 2019 Patch Tuesday, (Tue, May 14th)

$
0
0

This month we got patches for 79 vulnerabilities from Microsoft and 1 from Adobe. From those, 23 are critical and 2 were previously known - including the one that has been exploited in the wild.

The exploited vulnerability (CVE-2019-0863) affects the way Windows Error Reporting (WER) handles files. It may allow a local attacker to elevate privileges and run arbitrary code in kernel mode. The CVSS V3 for this vulnerability is 7.8.

The other previously known (CVE-2019-0932) is an information disclosure vulnerability which affects Skype for Android. Exploiting this vulnerability, an attacker could listen to the conversation of a Skype for Android without the user’s knowledge.

Amongst critical vulnerabilities, it worth mentioning a remote code execution in Windows Remote Desktop Services (CVE-2019-0708). An unauthenticated attacker may exploit this vulnerability by sending specially crafted packets to the vulnerable service and then execute arbitrary code on the target system. It affects Windows 7 and Windows Server 2008. The CVSS V3 score for this vulnerability is 9.8.

Last but not least, we have a new critical remote execution vulnerability affecting GDI+ (Windows Graphics Device Interface). An attacker could exploit this vulnerability by convincing the user to open a specially crafted attachment in an e-mail or instant messenger, for example. The CVSS V3 for this vulnerability is 8.8.  

UPDATE: Today's Patch Tuesday also addresses the new CPU side-channel attack published today known as Zombieload[1] (ADV190013). As Meltdown, Spectre, and Foreshadow the new flaw may allow an attacker to steal sensitive data and keys being processed by the CPU. To fix the issue you must apply OS updates provided by Microsoft today (not available for all versions yet) and firmware microcode from device OEMs. The details for this advisory are available at https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV190013.

See Renato's dashboard for a more detailed breakout: https://patchtuesdaydashboard.com

Description
CVEDisclosedExploitedExploitability (old versions)current versionSeverityCVSS Base (AVG)CVSS Temporal (AVG)
.NET Framework Denial of Service Vulnerability
%%cve:2019-0864%%NoNoLess LikelyLess LikelyImportant  
.NET Framework and .NET Core Denial of Service Vulnerability
%%cve:2019-0820%%NoNoLess LikelyLess LikelyImportant  
.Net Framework and .Net Core Denial of Service Vulnerability
%%cve:2019-0980%%NoNoLess LikelyLess LikelyImportant  
%%cve:2019-0981%%NoNoLess LikelyLess LikelyImportant  
ASP.NET Core Denial of Service Vulnerability
%%cve:2019-0982%%NoNoLess LikelyLess LikelyImportant  
Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability
%%cve:2019-0872%%NoNoLess LikelyLess LikelyImportant  
%%cve:2019-0979%%NoNo--Important  
Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability
%%cve:2019-0971%%NoNoLess LikelyLess LikelyImportant  
Chakra Scripting Engine Memory Corruption Vulnerability
%%cve:2019-0912%%NoNo--Critical4.23.8
%%cve:2019-0913%%NoNo--Critical4.23.8
%%cve:2019-0914%%NoNo--Critical4.23.8
%%cve:2019-0915%%NoNo--Critical4.23.8
%%cve:2019-0916%%NoNo--Critical4.23.8
%%cve:2019-0917%%NoNo--Critical4.23.8
%%cve:2019-0922%%NoNo--Critical4.23.8
%%cve:2019-0923%%NoNo--Important4.23.8
%%cve:2019-0924%%NoNo--Critical4.23.8
%%cve:2019-0925%%NoNo--Critical4.23.8
%%cve:2019-0927%%NoNo--Critical4.23.8
%%cve:2019-0933%%NoNo--Critical4.23.8
%%cve:2019-0937%%NoNo--Critical4.23.8
Diagnostic Hub Standard Collector, Visual Studio Standard Collector Elevation of Privilege Vulnerability
%%cve:2019-0727%%NoNoLess LikelyLess LikelyImportant6.76.0
GDI+ Remote Code Execution Vulnerability
%%cve:2019-0903%%NoNoMore LikelyMore LikelyCritical8.87.9
Internet Explorer Information Disclosure Vulnerability
%%cve:2019-0930%%NoNoMore LikelyMore LikelyImportant2.42.2
Internet Explorer Memory Corruption Vulnerability
%%cve:2019-0929%%NoNo--Critical7.56.7
Internet Explorer Security Feature Bypass Vulnerability
%%cve:2019-0995%%NoNo--Important7.36.6
Internet Explorer Spoofing Vulnerability
%%cve:2019-0921%%NoNoLess LikelyLess LikelyImportant2.42.2
Jet Database Engine Remote Code Execution Vulnerability
%%cve:2019-0893%%NoNoLess LikelyLess LikelyImportant7.87.0
%%cve:2019-0894%%NoNoLess LikelyLess LikelyImportant7.87.0
%%cve:2019-0895%%NoNoLess LikelyLess LikelyImportant7.87.0
%%cve:2019-0896%%NoNoLess LikelyLess LikelyImportant7.87.0
%%cve:2019-0897%%NoNoLess LikelyLess LikelyImportant7.87.0
%%cve:2019-0898%%NoNoLess LikelyLess LikelyImportant7.87.0
%%cve:2019-0899%%NoNoLess LikelyLess LikelyImportant7.87.0
%%cve:2019-0900%%NoNoLess LikelyLess LikelyImportant7.87.0
%%cve:2019-0901%%NoNoLess LikelyLess LikelyImportant7.87.0
%%cve:2019-0902%%NoNoLess LikelyLess LikelyImportant7.87.0
%%cve:2019-0889%%NoNoLess LikelyLess LikelyImportant7.87.0
%%cve:2019-0890%%NoNoLess LikelyLess LikelyImportant7.87.0
%%cve:2019-0891%%NoNoLess LikelyLess LikelyImportant7.87.0
Latest Servicing Stack Updates
ADV990001NoNo--Critical  
May 2019 Adobe Flash Security Update
ADV190012NoNo--Critical  
Microsoft Azure AD Connect Elevation of Privilege Vulnerability
%%cve:2019-1000%%NoNoLess LikelyLess LikelyImportant  
Microsoft Browser Memory Corruption Vulnerability
%%cve:2019-0940%%NoNoMore LikelyMore LikelyCritical7.56.7
Microsoft Dynamics On-Premise Security Feature Bypass
%%cve:2019-1008%%NoNoLess LikelyLess LikelyImportant  
Microsoft Edge Elevation of Privilege Vulnerability
%%cve:2019-0938%%NoNo--Important4.23.8
Microsoft Edge Memory Corruption Vulnerability
%%cve:2019-0926%%NoNo--Critical4.23.8
Microsoft Guidance to mitigate Microarchitectural Data Sampling vulnerabilities
ADV190013NoNoMore LikelyMore LikelyImportant  
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
%%cve:2019-0945%%NoNoLess LikelyLess LikelyImportant  
%%cve:2019-0946%%NoNoLess LikelyLess LikelyImportant  
%%cve:2019-0947%%NoNo--Important  
Microsoft Office SharePoint XSS Vulnerability
%%cve:2019-0963%%NoNo--Important  
Microsoft SQL Server Analysis Services Information Disclosure Vulnerability
%%cve:2019-0819%%NoNoLess LikelyLess LikelyImportant  
Microsoft SharePoint Elevation of Privilege Vulnerability
%%cve:2019-0957%%NoNoLess LikelyLess LikelyImportant  
%%cve:2019-0958%%NoNoLess LikelyLess LikelyImportant  
Microsoft SharePoint Server Information Disclosure Vulnerability
%%cve:2019-0956%%NoNo--Important  
Microsoft SharePoint Server Remote Code Execution Vulnerability
%%cve:2019-0952%%NoNo--Important  
Microsoft SharePoint Spoofing Vulnerability
%%cve:2019-0949%%NoNo--Important  
%%cve:2019-0950%%NoNo--Important  
%%cve:2019-0951%%NoNo--Important  
Microsoft Word Remote Code Execution Vulnerability
%%cve:2019-0953%%NoNoLess LikelyLess LikelyCritical  
NuGet Package Manager Tampering Vulnerability
%%cve:2019-0976%%NoNoLess LikelyLess LikelyImportant  
Remote Desktop Services Remote Code Execution Vulnerability
%%cve:2019-0708%%NoNo--Critical9.88.8
Scripting Engine Memory Corruption Vulnerability
%%cve:2019-0884%%NoNoMore LikelyMore LikelyCritical6.45.8
%%cve:2019-0911%%NoNoMore LikelyMore LikelyCritical7.56.7
%%cve:2019-0918%%NoNoMore LikelyMore LikelyCritical7.56.7
Skype for Android Information Disclosure Vulnerability
%%cve:2019-0932%%YesNoLess LikelyLess LikelyImportant  
Unified Write Filter Elevation of Privilege Vulnerability
%%cve:2019-0942%%NoNoLess LikelyLess LikelyImportant4.44.0
Win32k Elevation of Privilege Vulnerability
%%cve:2019-0892%%NoNoMore LikelyMore LikelyImportant7.87.0
Windows DHCP Server Remote Code Execution Vulnerability
%%cve:2019-0725%%NoNoLess LikelyLess LikelyCritical8.17.3
Windows Defender Application Control Security Feature Bypass Vulnerability
%%cve:2019-0733%%NoNoLess LikelyLess LikelyImportant5.34.8
Windows Elevation of Privilege Vulnerability
%%cve:2019-0734%%NoNoLess LikelyLess LikelyImportant7.87.0
%%cve:2019-0936%%NoNoMore LikelyMore LikelyImportant7.87.0
Windows Error Reporting Elevation of Privilege Vulnerability
%%cve:2019-0863%%YesYesDetectedDetectedImportant7.87.0
Windows GDI Information Disclosure Vulnerability
%%cve:2019-0882%%NoNoMore LikelyMore LikelyImportant4.74.2
%%cve:2019-0961%%NoNoMore LikelyMore LikelyImportant4.74.2
%%cve:2019-0758%%NoNoMore LikelyMore LikelyImportant4.74.2
Windows Hyper-V Information Disclosure Vulnerability
%%cve:2019-0886%%NoNoLess LikelyLess LikelyImportant5.55.0
Windows Kernel Elevation of Privilege Vulnerability
%%cve:2019-0881%%NoNoMore LikelyMore LikelyImportant8.87.9
Windows NDIS Elevation of Privilege Vulnerability
%%cve:2019-0707%%NoNoMore LikelyMore LikelyImportant7.06.3
Windows OLE Remote Code Execution Vulnerability
%%cve:2019-0885%%NoNoMore LikelyMore LikelyImportant7.87.0
Windows Storage Service Elevation of Privilege Vulnerability
%%cve:2019-0931%%NoNoMore LikelyMore LikelyImportant7.06.3

 

References

[1] https://zombieloadattack.com/

--
Renato Marinho
Morphus Labs| LinkedInTwitter

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Viewing all articles
Browse latest Browse all 12054

Trending Articles