ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-0788
+2 in the same advisory: …0750 …0741
The Windows Adobe Type Manager Font Driver (Atmfd.dll) in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 and

The Windows Adobe Type Manager Font Driver (Atmfd.dll) in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 and R2 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "OpenType Font Driver Elevation of Privilege Vulnerability".

NVD description · AI analysis pending
7.0
group max
1%
  • microsoft windows 7
  • microsoft windows 8.1
  • microsoft windows server 2008
  • +1 more
CVE-2018-0749
The Microsoft Server Message Block (SMB) Server in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Window

The Microsoft Server Message Block (SMB) Server in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way SMB Server handles specially crafted files, aka "Windows Elevation of Privilege Vulnerability".

NVD description · AI analysis pending
7.8
group max
3% PoC
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2018-0758
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current us

Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0762, CVE-2018-0768, CVE-2018-0769, CVE-2018-0770, CVE-2018-0772, CVE-2018-0773, CVE-2018-0774, CVE-2018-0775, CVE-2018-0776, CVE-2018-0777, CVE-2018-0778, and CVE-2018-0781.

NVD description · AI analysis pending
7.5
group max
81% PoC
  • microsoft chakracore
  • microsoft edge
CVE-2018-0764
+1 in the same advisory: …0786
Microsoft .NET Framework 1.1, 2.0, 3.0, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 5.7 and .NET Core 1.0.

Microsoft .NET Framework 1.1, 2.0, 3.0, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 5.7 and .NET Core 1.0. 1.1 and 2.0 allow a denial of service vulnerability due to the way XML documents are processed, aka ".NET and .NET Core Denial Of Service Vulnerability". This CVE is unique from CVE-2018-0765.

NVD description · AI analysis pending
7.59%
  • microsoft .net core
  • microsoft powershell core
  • microsoft .net framework
CVE-2018-0769
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current us

Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0758, CVE-2018-0762, CVE-2018-0768, CVE-2018-0770, CVE-2018-0772, CVE-2018-0773, CVE-2018-0774, CVE-2018-0775, CVE-2018-0776, CVE-2018-0777, CVE-2018-0778, and CVE-2018-0781.

NVD description · AI analysis pending
7.5
group max
79% PoC
  • microsoft edge
  • microsoft chakracore
CVE-2018-0784
ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Elevation Of Privilege

ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0808.

NVD description · AI analysis pending
8.86%
  • microsoft asp.net core
CVE-2018-0789
+2 in the same advisory: …0790 …0799
Microsoft SharePoint Foundation 2010, Microsoft SharePoint Server 2013 and Microsoft SharePoint Server 2016 allow an elevation of privilege vulnerability due to

Microsoft SharePoint Foundation 2010, Microsoft SharePoint Server 2013 and Microsoft SharePoint Server 2016 allow an elevation of privilege vulnerability due to the way web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0790.

NVD description · AI analysis pending
8.8
group max
6%
  • microsoft sharepoint enterprise server
  • microsoft sharepoint server
CVE-2018-0798
Memory Corruption RCE in Microsoft Office Equation Editor (CVE-2018-0798)

CVE-2018-0798 is a memory corruption flaw (out-of-bounds write, CWE-787) in the Microsoft Equation Editor component of Microsoft Office 2007, 2010, 2013, and 2016 that allows remote code execution when the component mishandles objects in memory. A remote attacker triggers it by persuading a user to open a specially crafted document containing a maliciously embedded equation; user interaction is required and no privileges are needed (CVSS vector AV:N/AC:L/PR:N/UI:R). Successful exploitation lets the attacker run arbitrary code in the context of the current user, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 8.8). Any organization running the affected legacy Office versions — including deployments using the Office Compatibility Pack — is exposed, with government, military, and transportation organizations named in related reporting on Office-document attack campaigns. Exploitation is confirmed: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and its EPSS score of 95.1% (100th percentile) indicates a very high probability of active exploitation, with related headlines highlighting APT activity (notably the Bitter group's campaigns against military targets in South Asia) around Office document threats.

Do: Apply Microsoft's security updates for this vulnerability across Office 2007, 2010, 2013, 2016 and the Office Compatibility Pack, per vendor instructions as required by CISA KEV, and upgrade off legacy Office 2007/2010 to a still-supported release since those versions no longer receive regular fixes. Enforce caution with untrusted Office documents (don't open unsolicited attachments or embedded equations from unknown sources) and consider stripping or blocking embedded OLE equation objects from external files. Prioritize patching for government, military, and transportation-sector environments given active APT targeting of those sectors via Office documents.

8.8
group max
95% KEV
  • Microsoft Office (Equation Editor) Office 2007, Office 2010, Office 2013, Office 2016
  • Microsoft Office Compatibility Pack
  • Microsoft Word
masshundreds of millions of Office users/endpoints worldwide
CVE-2018-0796
Microsoft Excel in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability d

Microsoft Excel in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Excel Remote Code Execution Vulnerability".

NVD description · AI analysis pending
8.823%
  • microsoft excel
  • microsoft excel viewer
  • microsoft office
  • +1 more
CVE-2018-0818
Microsoft ChakraCore allows an attacker to bypass Control Flow Guard (CFG) in conjunction with another vulnerability to run arbitrary code on a target system, d

Microsoft ChakraCore allows an attacker to bypass Control Flow Guard (CFG) in conjunction with another vulnerability to run arbitrary code on a target system, due to how the Chakra scripting engine handles accessing memory, aka "Scripting Engine Security Feature Bypass".

NVD description · AI analysis pending
7.54%
  • microsoft chakracore
Full article2,670 words · extracted from blog.talosintelligence.com · click to collapse

Today Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 56 new vulnerabilities with 16 of them rated critical, 39 of them rated important and 1 of them rated Moderate. These vulnerabilities impact ASP.NET, Edge, Internet Explorer, Office, Windows, and more.

In addition to the 56 vulnerabilities addressed, Microsoft has also released an update that addresses Meltdown and Spectre. Mitigations for these two vulnerabilities were published for Windows in ADV180002. Note that due to incompatibilities with anti-virus products, users and organizations may not have received this update yet. For more information, users should refer to Microsoft's knowledge base article which covers this issue.

Vulnerabilities Rated Critical
Microsoft has assigned the following vulnerabilities a Critical severity rating:

  • CVE-2018-0758 - Scripting Engine Memory Corruption Vulnerability
  • CVE-2018-0762 - Scripting Engine Memory Corruption Vulnerability
  • CVE-2018-0767 - Scripting Engine Information Disclosure Vulnerability
  • CVE-2018-0769 - Scripting Engine Memory Corruption Vulnerability
  • CVE-2018-0770 - Scripting Engine Memory Corruption Vulnerability
  • CVE-2018-0772 - Scripting Engine Memory Corruption Vulnerability
  • CVE-2018-0773 - Scripting Engine Memory Corruption Vulnerability
  • CVE-2018-0774 - Scripting Engine Memory Corruption Vulnerability
  • CVE-2018-0775 - Scripting Engine Memory Corruption Vulnerability
  • CVE-2018-0776 - Scripting Engine Memory Corruption Vulnerability
  • CVE-2018-0777 - Scripting Engine Memory Corruption Vulnerability
  • CVE-2018-0778 - Scripting Engine Memory Corruption Vulnerability
  • CVE-2018-0780 - Scripting Engine Information Disclosure Vulnerability
  • CVE-2018-0781 - Scripting Engine Memory Corruption Vulnerability
  • CVE-2018-0797 - Microsoft Word Memory Corruption Vulnerability
  • CVE-2018-0800 - Scripting Engine Information Disclosure Vulnerability The following is a brief description of each vulnerability.

Multiple CVEs - Scripting Engine Memory Corruption Vulnerability
Multiple remote code execution vulnerabilities have been discovered that affect Microsoft Edge and Internet Explorer. These vulnerabilities manifest due to Internet Explorer and Edge not properly handling objects in memory. Successful exploitation of these vulnerabilities could result in an attacker obtaining the ability to execute code within the context of the current user. Scenarios where these vulnerabilities would likely be exploited include web-based attacks where the user navigates to a malicious web page designed to exploit this vulnerability or, in some cases, opens a Microsoft Office document that utilizes the browser rendering engine.

The following is a list of CVEs related to these vulnerabilities.

  • CVE-2018-0758
  • CVE-2018-0762
  • CVE-2018-0769
  • CVE-2018-0770
  • CVE-2018-0772
  • CVE-2018-0773
  • CVE-2018-0774
  • CVE-2018-0775
  • CVE-2018-0776
  • CVE-2018-0777
  • CVE-2018-0778
  • CVE-2018-0781

Multiple CVEs - Scripting Engine Information Disclosure Vulnerability
Two information disclosure vulnerabilities have been discovered that affect Microsoft Edge. These vulnerabilities manifests due to Microsoft Edge not properly handling objects in memory. These vulnerabilities could be leveraged by an attacker to obtain sensitive information from an affected system. This information could then be utilized to launch additional attacks against the system. Scenarios where these vulnerabilities would like be exploited include web-based attacks where the user navigates to a malicious web page designed to exploit this vulnerability.

The following is a list of CVEs related to these vulnerabilities.

  • CVE-2018-0767
  • CVE-2018-0780
  • CVE-2018-0800

CVE-2018-0797 - Microsoft Word Memory Corruption Vulnerability
A remote code execution vulnerability has been discovered that affects Microsoft Office. This vulnerability manifests due to Microsoft Office failing to properly handle RTF files. Successful exploitation of this vulnerability could result in an attacker gaining the ability to execute code within the context of the current user. Scenarios where this vulnerability would likely be exploited include web-based attacks where the user navigates to a malicious web page containing a specially crafted RTF file or in email-based attacks where the user opens a specially crafted file that has been received as an email attachment.

Vulnerabilities Rated Important
Microsoft has assigned the following vulnerabilities an Important severity rating:

  • CVE-2018-0741 - Microsoft Color Management Information Disclosure Vulnerability
  • CVE-2018-0743 - Windows Subsystem for Linux Elevation of Privilege Vulnerability
  • CVE-2018-0744 - Windows Elevation of Privilege Vulnerability
  • CVE-2018-0745 - Windows Information Disclosure Vulnerability
  • CVE-2018-0746 - Windows Information Disclosure Vulnerability
  • CVE-2018-0747 - Windows Information Disclosure Vulnerability
  • CVE-2018-0748 - Windows Elevation of Privilege Vulnerability
  • CVE-2018-0749 - SMB Server Elevation of Privilege Vulnerability
  • CVE-2018-0750 - Windows GDI Information Disclosure Vulnerability
  • CVE-2018-0751 - Windows Elevation of Privilege Vulnerability
  • CVE-2018-0752 - Windows Elevation of Privilege Vulnerability
  • CVE-2018-0753 - Windows IPSec Denial of Service Vulnerability
  • CVE-2018-0754 - ATMFD.dll Information Disclosure Vulnerability
  • CVE-2018-0764 - .NET and .NET Core Denial Of Service Vulnerability
  • CVE-2018-0766 - Microsoft Edge Information Disclosure Vulnerability
  • CVE-2018-0768 - Scripting Engine Memory Corruption Vulnerability
  • CVE-2018-0784 - ASP.NET Core Elevation Of Privilege Vulnerability
  • CVE-2018-0786 - .NET Security Feature Bypass Vulnerability
  • CVE-2018-0788 - ATMFD.dll Information Disclosure Vulnerability
  • CVE-2018-0789 - Microsoft Office Spoofing Vulnerability
  • CVE-2018-0790 - Microsoft Office Information Disclosure Vulnerability
  • CVE-2018-0791 - Microsoft Outlook Remote Code Execution Vulnerability
  • CVE-2018-0792 - Microsoft Word Remote Code Execution
  • CVE-2018-0793 - Microsoft Outlook Remote Code Execution
  • CVE-2018-0794 - Microsoft Word Remote Code Execution
  • CVE-2018-0795 - Microsoft Office Remote Code Execution
  • CVE-2018-0796 - Microsoft Excel Remote Code Execution
  • CVE-2018-0798 - Microsoft Word Memory Corruption Vulnerability
  • CVE-2018-0799 - Microsoft Access Tampering Vulnerability
  • CVE-2018-0801 - Microsoft Office Remote Code Execution Vulnerability
  • CVE-2018-0802 - Microsoft Office Memory Corruption Vulnerability
  • CVE-2018-0803 - Microsoft Edge Elevation of Privilege Vulnerability
  • CVE-2018-0805 - Microsoft Word Remote Code Execution Vulnerability
  • CVE-2018-0806 - Microsoft Word Remote Code Execution Vulnerability
  • CVE-2018-0807 - Microsoft Word Remote Code Execution Vulnerability
  • CVE-2018-0812 - Microsoft Word Memory Corruption Vulnerability
  • CVE-2018-0818 - Scripting Engine Security Feature Bypass
  • CVE-2018-0819 - Spoofing Vulnerability in Microsoft Office for MAC The following is a brief description of each vulnerability:

CVE-2018-0741 - Microsoft Color Management Information Disclosure Vulnerability
An information disclosure vulnerability has been discovered affecting Microsoft Graphics Component. This vulnerability manifests due to the Color Management Module (ICM32.dll) not properly handling objects in memory. Successful exploitation of this vulnerability could provide an attacker with the information required to bypass Address Space Layout Randomization (ASLR). While this vulnerability does not provide code execution, it could make it easier to successfully exploit remote code execution vulnerabilities due to the ability of the attacker to bypass ASLR.

CVE-2018-0743 - Windows Subsystem for Linux Elevation of Privilege Vulnerability
A privilege escalation vulnerability has been discovered affecting Windows Subsystem for Linux. This vulnerability manifests due to an integer overflow present in Windows Subsystem for Linux. Successful exploitation of this vulnerability requires an authenticated local attacker to run a specially crafted program and could allow them to execute code with elevated privileges on affected systems.

CVE-2018-0744 - Windows Elevation of Privilege Vulnerability
A privilege escalation vulnerability has been discovered affecting the Windows Kernel. This vulnerability manifests due to the Windows kernel failing to properly handle objects in memory. Successful exploitation of this vulnerability requires an authenticated local attacker to run a specially crafted program and could allow them to execute code with elevated privileges on affected systems.

Multiple CVEs - Windows Information Disclosure Vulnerability
Multiple information disclosure vulnerabilities have been discovered affecting Windows kernel. Successful exploitation of these vulnerability could provide an attacker information required to bypass ASLR as they allows the retrieval of the memory address of kernel objects. Exploitation of these vulnerability would require an authenticated local attacker to run a specially crafted program.

The following is a list of CVEs related to these vulnerabilities.

  • CVE-2018-0745
  • CVE-2018-0746
  • CVE-2018-0747

Multiple CVEs - Windows Elevation of Privilege Vulnerability
Multiple privilege escalation vulnerabilities have been discovered affecting the Windows kernel. These vulnerabilities manifests due to the Windows Kernel API failing to properly enforce permissions. Successful exploitation of these vulnerability would require an authenticated local attacker to execute a specially crafted program and could result in the attacker having the ability to impersonate processes, inject cross-process communications, or interrupt system functionality.

The following is a list of CVEs related to these vulnerabilities.

  • CVE-2018-0748
  • CVE-2018-0751
  • CVE-2018-0752

CVE-2018-0749 - SMB Server Elevation of Privilege Vulnerability
A privilege escalation vulnerability has been discovered affecting Windows SMB Server. This vulnerability manifests when an attacker with valid credentials to authenticate to an affected system opens a specially crafted file locally using the SMB protocol. Successful exploitation of this vulnerability could allow an attacker to bypass certain security checks. An attacker must have valid credentials and be authenticated to the affected system.

CVE-2018-0750 - Windows GDI Information Disclosure Vulnerability
An information disclosure vulnerability has been discovered affecting Microsoft Graphics Component. This vulnerability manifests due to the Windows GDI component improperly disclosing kernel memory addresses. Successful exploitation of this vulnerability could result in an attacker obtaining sensitive information that could be used to further attack the system. In order to exploit this vulnerability an attacker need to log on to the affected system and execute a specially crafted program.

CVE-2018-0753 - Windows IPSec Denial of Service Vulnerability
A denial of service vulnerability has been discovered that affects IPSec. This vulnerability manifests due to Windows improperly handling objects in memory. Successful exploitation of this vulnerability could allow an attacker to cause a system to stop responding, preventing the system from being used by authorized users.

CVE-2018-0754 - ATMFD.dll Information Disclosure Vulnerability
An information disclosure vulnerability exists affecting Graphics Fonts. This vulnerability manifests due to the Adobe Type Manager Font Driver (ATMFD.dll) improperly handling objects in memory. Successful exploitation of this vulnerability could allow an attacker to obtain sensitive information that could be used to further attack affected systems. Scenarios where this vulnerability would likely be exploited include an attacker opening a document containing specially crafted fonts on an affected system.

CVE-2018-0764 - .NET and .NET Core Denial Of Service Vulnerability
A denial of service vulnerability has been discovered affecting the .NET Framework. This vulnerability manifests due to .NET and .NET core improperly processing XML documents. Successful exploitation of this vulnerability could cause a denial of service in an affected .NET application. This vulnerability could be exploited by an attacker by sending specially crafted requests to a vulnerable .NET or .NET core application.

CVE-2018-0766 - Microsoft Edge Information Disclosure Vulnerability
An information disclosure vulnerability have been identified that affects Microsoft Edge. This vulnerability manifests due to Microsoft Edge PDF reader improperly handling objects in memory. This vulnerability could be leveraged by an attacker to obtain information that could be used for subsequent attacks against an affected system. Scenarios where this vulnerability would likely be exploited include web-based attacks where the user navigates to a malicious PDF hosted on an attacker controlled website.

CVE-2018-0768 - Scripting Engine Memory Corruption Vulnerability
A remote code execution vulnerability have been discovered that affects Microsoft Edge and Internet Explorer. This vulnerability manifests due to Internet Explorer and Edge not properly handling objects in memory. Successful exploitation of this vulnerability could result in an attacker obtaining the ability to execute code within the context of the current user. Scenarios where this vulnerability would likely be exploited include web-based attacks where the user navigates to a malicious web page designed to exploit this vulnerability.

CVE-2018-0784 - ASP.NET Core Elevation Of Privilege Vulnerability
A vulnerability have been discovered in the ASP.NET Core that could allow a privilege escalation attack to occur. This vulnerability manifests when an ASP.NET Core web application, based on a vulnerable project template, incorrectly utilizes input without first sanitizing it. An attacker who exploits this vulnerability could perform content injection attacks and run scripts in the context of the current user. Exploitation of this vulnerability could be achieved in email-based attack scenarios or via other social engineering means where the user clicks on a specially crafted link.

CVE-2018-0786 - .NET Security Feature Bypass Vulnerability
A security feature bypass vulnerability in the Microsoft .NET Framework and .NET Core have been identified that could allow attackers to bypass certificate validation. This vulnerability manifests in the way certificates are handled where certificates marked invalid for specific use may still be used for that purpose.

CVE-2018-0788 - OpenType Font Driver Elevation of Privilege Vulnerability
A privilege escalation vulnerability has been discovered in the Windows Adobe OpenType Font Driver. This vulnerability manifests as a result of the library incorrectly handling objects in memory. Exploitation of this vulnerability could be achieved by running a specially crafted application that exploits this flaw.

Multiple CVEs - Microsoft SharePoint Cross Site Scripting Elevation of Privilege Vulnerability
Two cross-site scripting vulnerabilities have been identified in Microsoft Sharepoint that could allow an attacker to perform a privilege escalation attack. These vulnerabilities manifest as a result of improper input sanitization for specially crafted web requests. An attacker who exploits these vulnerabilities would be able to run scripts in the context of the affected user, allowing the attacker to read content or perform actions based on that user's permission.

The following is a list of CVEs related to these vulnerabilities.

  • CVE-2018-0789
  • CVE-2018-0790

Multiple CVEs - Microsoft Outlook Remote Code Execution Vulnerability
Two remote code execution vulnerabilities have been identified in Microsoft Outlook that could allow an attacker to execute arbitrary code of their choice on targeted hosts. These vulnerabilities manifest as a result of Microsoft Outlook incorrectly parsing specially crafted emails. An attacker who sends a user a specially crafted email and socially engineers them to open a specially crafted attachment in Outlook could exploit this vulnerability.

The following is a list of CVEs related to these vulnerabilities.

  • CVE-2018-0791
  • CVE-2018-0793

Multiple CVEs - Microsoft Word Remote Code Execution Vulnerability
Multiple arbitrary code execution vulnerabilities have been identified in Microsoft Word. These vulnerabilities manifest as a result of Microsoft Word incorrectly handing objects in memory. An attacker who exploits one of these vulnerabilities could execute arbitrary code of their choosing on targeted hosts. Scenarios where this could occur include email-based attacks or other scenarios involving social engineering where the attackers convince the user to open a specially crafted Word document.

The following is a list of CVEs related to these vulnerabilities.

  • CVE-2018-0792
  • CVE-2018-0794
  • CVE-2018-0805
  • CVE-2018-0806
  • CVE-2018-0807
  • CVE-2018-0812

CVE-2018-0796 - Microsoft Excel Remote Code Execution Vulnerability
An arbitrary code execution vulnerabilty have been identified in Microsoft Excel. This vulnerability manifests as a result of Microsoft Excel incorrectly handing objects in memory. An attacker who exploits this vulnerability could execute arbitrary code of their choosing on targeted hosts. Scenarios where this could occur include email-based attacks or other scenarios involving social engineering where the attackers convince the user to open a specially crafted Excel spreadsheet.

Multiple CVEs - Microsoft Office Memory Corruption Vulnerability
Multiple arbitrary code execution vulnerabilities have been identified in Microsoft Office. These vulnerabilities manifest as a result of Microsoft Office incorrectly handing objects in memory. An attacker who exploits one of these vulnerabilities could execute arbitrary code of their choosing on targeted hosts. Scenarios where this could occur include email-based attacks or other scenarios involving social engineering where the attackers convince the user to open a specially crafted Office file.

The following is a list of CVEs related to these vulnerabilities.

  • CVE-2018-0795
  • CVE-2018-0798
  • CVE-2018-0801
  • CVE-2018-0802

CVE-2018-0799 - Microsoft Access Tampering Vulnerability
A cross-site scripting vulnerability has been identified in Microsoft Access. This vulnerability manifests as a result of Microsoft Access incorrectly handling and sanitizing inputs to image fields editing within Design view. An attacker who exploits this vulnerability could execute arbitrary JavaScript in the context of the current user. An attacker could then read content or perform actions on behalf on the user on a remote site. Exploitation of this vulnerability could be achieved by opening a specially crafted Access file.

CVE-2018-0803 - Microsoft Edge Elevation of Privilege Vulnerability
A vulnerability in Microsoft Edge has been identified that could result in privilege escalation if exploited. This vulnerability manifests as a result of Edge incorrectly enforcing cross-domain policies. Successful exploitation could result in a user obtaining elevated privileges.

CVE-2018-0818 - Scripting Engine Security Feature Bypass
A security feature bypass vulnerability has been identified in Microsoft Chakra that could allow an attacker to bypass Control Flow Guard. An attacker could exploit this vulnerability by creating a specially crafted web page designed to exploit this vulnerability and convincing a user to visit the web page.

CVE-2018-0819 - Spoofing Vulnerability in Microsoft Office for Mac
A spoofing vulnerability in Microsoft Outlook for Mac has been discovered and manifests as a result of Outlook for Mac incorrectly handling the encoding and display of email addresses. As a result, antivirus and anti-spam scanning may not work as intended.

Vulnerabilities Rated Moderate
Microsoft has assigned the following vulnerabilities an Moderate severity rating:

  • CVE-2018-0785 - ASP.NET Core Cross Site Request Forgery Vulnerability The following is a brief description of this vulnerability:

CVE-2018-0785 - ASP.NET Core Cross Site Request Forgery Vulnerability
A Cross Site Request Forgery (CSRF) vulnerability has been discovered affecting ASP.NET Core web applications that were created using vulnerable project templates. Successful exploitation of this vulnerability could allow an attacker to modify recovery codes associated with accounts to which the attacker should not have access to, resulting in the user being locked out of their account in situations where the user attempts to access their account after losing their 2FA device.

Coverage
In response to these vulnerability disclosures, Talos is releasing the following Snort rules that detect attempts to exploit them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Firepower customers should use the latest update to their ruleset by updating their SRU. Open Source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.

Snort Rules:

  • 45374-45379
  • 45383-45384
  • 45387-45392
  • 45395-45396
  • 45402-45403

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/ms-tuesday-63063210e63ef5e7e1ec3140/