ZeroHour
Security Affairspublished ()ingested @securityaffairs

Microsoft April 2019 Patch Tuesday fixes Windows 0days under attack

criticalVulnerability exploited in the wildimportance 60CVE-2019-0803CVE-2019-0859

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-0803
+1 in the same advisory: …0859
Local Privilege Escalation in Microsoft Win32k Kernel Component

CVE-2019-0803 is a privilege escalation flaw in Microsoft's Win32k kernel component caused by improper handling of objects in memory. It is triggered locally when code already running on a Windows system reaches the vulnerable Win32k object-handling path, allowing memory corruption that the attacker can leverage. Successful exploitation lets the attacker run arbitrary code in kernel mode, elevating from a low-privileged account to full system-level control. Per the available data, the affected component is Microsoft Win32k across Windows installations, though specific affected Windows versions and builds are not enumerated in the source data and should be confirmed against Microsoft's advisory. Exploitation is confirmed in the wild: CISA added it to the KEV catalog on 2021-11-03 with known ransomware use, and EPSS assigns a 45.2% probability of exploitation within 30 days (99th percentile).

Do: Apply Microsoft Windows security updates per vendor instructions — this flaw was fixed in Microsoft's April 2019 security updates, so ensure systems are running those or later cumulative updates and verify by checking OS build numbers. Prioritize patching endpoints and servers where untrusted or low-privileged users can execute code, given documented ransomware chaining. Treat KEV status as a deadline: systems unpatched for this Win32k flaw should be considered actively targeted.

7.845% KEV ransomware
  • Microsoft Win32k
masshundreds of millions of Windows desktops and servers (Win32k is a core component shipped with essentially all Windows installations)
Full article317 words · extracted from securityaffairs.com · click to collapse

Microsoft Patches Windows Privilege Escalation Flaws Exploited in Attacks

Microsoft has released its April 2019 Patch Tuesday updates that address over 70 vulnerabilities, including two Windows zero-day flaws.

Microsoft has released the April 2019 Patch Tuesday updates that address 74 vulnerabilities, including two Windows zero-days under active attack.

April 2019 Patch Tuesday security updates resolve over a dozen critical remote code execution and privilege escalation vulnerabilities affecting Windows and Microsoft browsers.

The vulnerabilities exploited in the wild tracked as CVE-2019-0803 and CVE-2019-0859 could allow an attacker to escalate privileges on the target system.

Both vulnerabilities tied the way the Win32k component in Windows handles objects in memory, an authenticated attacker could exploit them authenticated to execute arbitrary code in kernel mode.

“An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.” reads the security advisor for the CVE-2019-0803 that is equal to the one for the CVE-2019-0859 flaw.

“To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.

The update addresses this vulnerability by correcting how Win32k handles objects in memory.”

The flaws were respectively discovered by researchers at Kaspersky Lab and Donghai Zhu of the Alibaba Cloud Intelligence Security Team.

Microsoft did not reveal details about the vulnerabilities and the way threat actors have exploited them.

Adobe also released its Patch Tuesday updates for April 2019 that address a total of 43 vulnerabilities affecting the eight products of the company.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – Microsoft Patch Tuesday, zero-days)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/83598/breaking-news/microsoft-april-2019-patch-tuesday.html