Microsoft Patch Tuesday
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-11899 | Device Guard in Windows 10 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a security feature bypass vulnerability due to Device Guard in Windows 10 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a security feature bypass vulnerability due to the way untrusted files are handled, aka "Microsoft Windows Security Feature Bypass Vulnerability". NVD description · AI analysis pending | 9.8 group max | 6% |
| — | ||
| CVE-2017-11907 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how Internet Explorer handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11886, CVE-2017-11889, CVE-2017-11890, CVE-2017-11893, CVE-2017-11894, CVE-2017-11895, CVE-2017-11901, CVE-2017-11903, CVE-2017-11905, CVE-2017-11905, CVE-2017-11908, CVE-2017-11909, CVE-2017-11910, CVE-2017-11911, CVE-2017-11912, CVE-2017-11913, CVE-2017-11914, CVE-2017-11916, CVE-2017-11918, and CVE-2017-11930. NVD description · AI analysis pending | 7.5 group max | 65% | PoC |
| — | |
| CVE-2017-11893 | ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the c ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11886, CVE-2017-11889, CVE-2017-11890, CVE-2017-11894, CVE-2017-11895, CVE-2017-11901, CVE-2017-11903, CVE-2017-11905, CVE-2017-11907, CVE-2017-11908, CVE-2017-11909, CVE-2017-11910, CVE-2017-11911, CVE-2017-11912, CVE-2017-11913, CVE-2017-11914, CVE-2017-11916, CVE-2017-11918, and CVE-2017-11930. NVD description · AI analysis pending | 7.5 | 68% | PoC |
| — | |
| CVE-2017-11889 | ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11886, CVE-2017-11890, CVE-2017-11893, CVE-2017-11894, CVE-2017-11895, CVE-2017-11901, CVE-2017-11903, CVE-2017-11905, CVE-2017-11907, CVE-2017-11908, CVE-2017-11909, CVE-2017-11910, CVE-2017-11911, CVE-2017-11912, CVE-2017-11913, CVE-2017-11914, CVE-2017-11916, CVE-2017-11918, and CVE-2017-11930. NVD description · AI analysis pending | 7.5 group max | 9% |
| — | ||
| CVE-2017-11932 | Microsoft Exchange Server 2016 CU5 and Microsoft Exchange Server 2016 CU5 allow a spoofing vulnerability due to the way Outlook Web Access (OWA) validates web r Microsoft Exchange Server 2016 CU5 and Microsoft Exchange Server 2016 CU5 allow a spoofing vulnerability due to the way Outlook Web Access (OWA) validates web requests, aka "Microsoft Exchange Spoofing Vulnerability". NVD description · AI analysis pending | 8.1 | 6% |
| — | ||
| CVE-2017-11935 | Microsoft Office 2016 Click-to-Run (C2R) allows a remote code execution vulnerability due to the way files are handled in memory, aka "Microsoft Excel Remote Co Microsoft Office 2016 Click-to-Run (C2R) allows a remote code execution vulnerability due to the way files are handled in memory, aka "Microsoft Excel Remote Code Execution Vulnerability". NVD description · AI analysis pending | 7.8 group max | 19% |
| — | ||
| CVE-2017-11936 | Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability due to the way web requests are handled, aka "Microsoft SharePoint El Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability due to the way web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". NVD description · AI analysis pending | 8.8 | 4% |
| — | ||
| CVE-2017-11937 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 15 The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to remote code execution. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability". NVD description · AI analysis pending | 7.8 | 28% |
| — | ||
| CVE-2017-11940 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 15 The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to remote code execution. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability". This is different than CVE-2017-11937. NVD description · AI analysis pending | 7.8 | 20% |
| — |
Full article1,650 words · extracted from blog.talosintelligence.com · click to collapse
Tuesday, December 12, 2017 18:32
Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 34 new vulnerabilities with 21 of them rated critical and 13 of them rated important. These vulnerabilities impact Edge, Exchange, Internet Explorer, Office, Scripting Engine, Windows, and more.
In addition to the 33 vulnerabilities addressed, Microsoft has also released an update for Microsoft Office which improves security by disabling the Dynamic Data Exchange (DDE) protocol. This update is detailed in ADV170021 and impacts all supported versions of Office. Organizations who are unable to install this update should consult the advisory for workaround that help mitigate DDE exploitation attempts.
Vulnerabilities Rated Critical
Microsoft has assigned the following vulnerabilities a Critical severity rating:
- CVE-2017-11886 - Scripting Engine Memory Corruption Vulnerability
- CVE-2017-11888 - Microsoft Edge Memory Corruption Vulnerability
- CVE-2017-11889 - Scripting Engine Memory Corruption Vulnerability
- CVE-2017-11890 - Scripting Engine Memory Corruption Vulnerability
- CVE-2017-11893 - Scripting Engine Memory Corruption Vulnerability
- CVE-2017-11894 - Scripting Engine Memory Corruption Vulnerability
- CVE-2017-11895 - Scripting Engine Memory Corruption Vulnerability
- CVE-2017-11901 - Scripting Engine Memory Corruption Vulnerability
- CVE-2017-11903 - Scripting Engine Memory Corruption Vulnerability
- CVE-2017-11905 - Scripting Engine Memory Corruption Vulnerability
- CVE-2017-11907 - Scripting Engine Memory Corruption Vulnerability
- CVE-2017-11908 - Scripting Engine Memory Corruption Vulnerability
- CVE-2017-11909 - Scripting Engine Memory Corruption Vulnerability
- CVE-2017-11910 - Scripting Engine Memory Corruption Vulnerability
- CVE-2017-11911 - Scripting Engine Memory Corruption Vulnerability
- CVE-2017-11912 - Scripting Engine Memory Corruption Vulnerability
- CVE-2017-11914 - Scripting Engine Memory Corruption Vulnerability
- CVE-2017-11918 - Scripting Engine Memory Corruption Vulnerability
- CVE-2017-11930 - Scripting Engine Memory Corruption Vulnerability
- CVE-2017-11937 - Microsoft Malware Protection Engine Remote Code Execution Vulnerability
- CVE-2017-11940 - Microsoft Malware Protection Engine Remote Code Execution Vulnerability
The following is a brief description of each vulnerability.
Multiple CVEs - Scripting Engine Memory Corruption Vulnerability
Multiple vulnerabilities have been identified in the scripting engines of Edge and Internet Explorer that could allow an attacker to remotely execute arbitrary code. These vulnerabilities all manifest due to the scripting engines in Edge and Internet Explorer improperly handling objects in memory. As a result, successful exploitation could lead to arbitrary code execution in the context of the current user. Scenarios where these vulnerabilities would likely be exploited include web-based attacks where the user navigates to a malicious web page designed to exploit of these vulnerabilities or, in some cases, opens a Microsoft Office document containing an embedded ActiveX control marked "safe for initialization."
The following is a list of CVEs related to these vulnerabilities:
- CVE-2017-11886
- CVE-2017-11889
- CVE-2017-11890
- CVE-2017-11893
- CVE-2017-11894
- CVE-2017-11895
- CVE-2017-11901
- CVE-2017-11903
- CVE-2017-11905
- CVE-2017-11907
- CVE-2017-11908
- CVE-2017-11909
- CVE-2017-11910
- CVE-2017-11911
- CVE-2017-11912
- CVE-2017-11914
- CVE-2017-11918
- CVE-2017-11930
CVE-2017-11888 - Microsoft Edge Memory Corruption Vulnerability
A vulnerability have been identified in the scripting engines of Edge and Internet Explorer that could allow an attacker to remotely execute arbitrary code. This vulnerability manifests due to the scripting engines in Edge and Internet Explorer improperly handling objects in memory. As a result, successful exploitation could lead to arbitrary code execution in the context of the current user. Users could be exploited if they navigate to a malicious web page designed to exploit of these vulnerabilities.
Multiple CVEs - Microsoft Malware Protection Engine Remote Code Execution Vulnerability
Two arbitrary code execution vulnerabilities have been identified within the Microsoft Malware Protection Engine that could allow an attacker to execute code in the context of the LocalSystem account. These vulnerabilities manifest as a result of the engine improperly scanning files. Exploitation of these vulnerabilities is achievable if the system scans a specially crafted file with an affected version of the Microsoft Malware Protection Engine. Note that these update typically will not require action by users or administrators as the the built-in mechanism for automatic deployment of these updates will account within 48 hours of release.
- CVE-2017-11937
- CVE-2017-11940
Vulnerabilities Rated Important
Microsoft has assigned the following vulnerabilities an Important severity rating:
- CVE-2017-11885 - Windows RRAS Service Remote Code Execution Vulnerability
- CVE-2017-11887 - Scripting Engine Information Disclosure Vulnerability
- CVE-2017-11899 - Microsoft Windows Security Feature Bypass Vulnerability
- CVE-2017-11906 - Scripting Engine Information Disclosure Vulnerability
- CVE-2017-11913 - Scripting Engine Memory Corruption Vulnerability
- CVE-2017-11916 - Scripting Engine Memory Corruption Vulnerability
- CVE-2017-11919 - Scripting Engine Information Disclosure Vulnerability
- CVE-2017-11927 - Microsoft Windows Information Disclosure Vulnerability
- CVE-2017-11932 - Microsoft Exchange Spoofing Vulnerability
- CVE-2017-11934 - Microsoft PowerPoint Information Disclosure Vulnerability
- CVE-2017-11935 - Microsoft Excel Remote Code Execution Vulnerability
- CVE-2017-11936 - Microsoft SharePoint Elevation of Privilege Vulnerability
- CVE-2017-11939 - Microsoft Office Information Disclosure Vulnerability
The following is a brief description of each vulnerability.
CVE-2017-11885 - Windows RRAS Service Remote Code Execution Vulnerability
A vulnerability has been identified that exists in RPC on systems where Routing and Remote Access is enabled. Successful exploitation of this vulnerability could result in code execution. In order to exploit this vulnerability, an attacker would need to run an application specifically designed to exploit this vulnerability. Routing and Remote access is not enabled in default configurations of Windows. On systems where Routing and Remote Access is disabled, the system is not vulnerable.
Multiple CVEs - Scripting Engine Information Disclosure Vulnerability
Multiple vulnerabilities have been identified in the scripting engines of Edge and Internet Explorer that could allow an attacker to obtain information to further compromise a user's system. These vulnerabilities all manifest due to the scripting engine improperly handling objects in memory. Successful exploitation would give an attacker sensitive information that could then be used in other exploits. A scenario where users could be exploited include web-based attacks, where a user navigates to a malicious web page designed to exploit of one of these vulnerabilities.
The following is a list of CVEs related to these vulnerabilities:
- CVE-2017-11887
- CVE-2017-11906
- CVE-2017-11919
CVE-2017-11899 - Microsoft Windows Security Feature Bypass Vulnerability
A vulnerability has been identified that affects Device Guard. Successful exploitation of this vulnerability could result in Device Guard incorrectly validating untrusted files. As Device Guard uses signatures to determine whether a file is benign or malicious, this could cause Device Guard to allow a malicious file to execute on vulnerable systems. An attacker could leverage this vulnerability to cause an untrusted file to appear as if it is trusted.
Multiple CVEs - Scripting Engine Memory Corruption Vulnerability
Multiple vulnerabilities have been identified in the scripting engines of Edge and Internet Explorer that could allow an attacker to remotely execute arbitrary code. These vulnerabilities all manifest due to the scripting engines in Edge and Internet Explorer improperly handling objects in memory. As a result, successful exploitation could lead to arbitrary code execution in the context of the current user. Scenarios where these vulnerabilities would likely be exploited include web-based attacks where the user navigates to a malicious web page designed to exploit of these vulnerabilities or, in some cases, opens a Microsoft Office document containing an embedded ActiveX control marked "safe for initialization."
The following is a list of CVEs related to these vulnerabilities:
- CVE-2017-11913
- CVE-2017-11916
CVE-2017-11927 - Microsoft Windows Information Disclosure Vulnerability
An information disclosure vulnerability has been identified that affects the Windows its:// protocol handler. This vulnerability manifests due to the protocol handler sending network traffic to a remote site when determining the zone associated with a URL that is provided to the protocol handler. An attacker could attempt to leverage this vulnerability to obtain sensitive information. This vulnerability could be leveraged to obtain NTLM hash values associated with a victim's account.
CVE-2017-11932 - Microsoft Exchange Spoofing Vulnerability
A spoofing vulnerability has been identified that affects Microsoft Exchange. This vulnerability manifests due to Outlook Web Access (OWA) failing to properly handle certain web requests. This vulnerability could be leveraged by attackers to inject scripts and content. This vulnerability could also be leveraged to redirect clients to a malicious web site. Successful exploitation of this vulnerability would require an attacker to send victims a specially crafted email containing a malicious link.
CVE-2017-11934 - Microsoft PowerPoint Information Disclosure Vulnerability
An information disclosure vulnerability has been identified that affects Microsoft Office. This vulnerability manifests due to Microsoft Office improperly disclosing contents in memory. This vulnerability could be leveraged by an attacker to obtain sensitive information that could be used to launch additional attacks against a target system. Successful exploitation of this vulnerability would require an attacker to send a specially crafted file to a victim and convince them to open the file.
CVE-2017-11935 - Microsoft Excel Remote Code Execution Vulnerability
An arbitrary code execution vulnerability has been identified in Microsoft Excel which manifests as a result of improperly handling objects in memory. An attacker could exploit this vulnerability by creating a specially crafted Excel document which triggers the vulnerability. Successful exploitation would allow an attacker to execute arbitrary code in the context of the current user. Scenarios where this could occur include email-based attacks or attacks where users download malicious files off of a site hosting user-created content (DropBox, OneDrive, Google Drive).
CVE-2017-11936 - Microsoft SharePoint Elevation of Privilege Vulnerability
A privilege escalation vulnerability has been identified in Microsoft SharePoint Server that could potentially allow an attacker to impersonate a user and perform restricted actions. This vulnerability manifests due to SharePoint improperly sanitizing specially crafted web requests. An authenticated user who exploits this vulnerability could proceed to perform a cross-site scripting attack to cause other users to execute arbitrary JavaScript in the context of that user. This could then allow an attacker to read content, change permissions, or inject other malicious content on behalf of that user if permitted.
Coverage
In response to these vulnerability disclosures, Talos is releasing the following Snort rules that detect attempts to exploit them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Firepower customers should use the latest update to their ruleset by updating their SRU. Open Source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.
Snort Rules:
- 37283-37284, 45121-45124, 45128-40133, 45138-45153, 45155-45156, 45160-45163,45167-45170.
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/ms-tuesday-63063210e63ef5e7e1ec3142/