ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Microsoft, Adobe February 2018 security updates: An overview

criticalVulnerability exploited in the wildimportance 60CVE-2018-4878

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-4878
Use-After-Free RCE in Adobe Flash Player before 28.0.0.161

CVE-2018-4878 is a use-after-free (CWE-416) in Adobe Flash Player before 28.0.0.161, caused by a dangling pointer in the Primetime SDK's media-player handling of listener objects. An attacker triggers it by persuading a user to open attacker-controlled Flash content — typically a malicious SWF delivered via email, Office documents, or malvertising/exploit kits — because the CVSS vector (AV:L, UI:R) requires local user interaction. Successful exploitation yields arbitrary code execution with the privileges of the user running Flash. Anyone running a vulnerable Flash Player was exposed, including Red Hat Enterprise Linux Desktop/Server/Workstation users running Red Hat's packaged Flash plugin. The flaw was exploited as a zero-day in January–February 2018 (documented by McAfee and distributed alongside the Fallout exploit kit), and it remains in CISA's KEV with known ransomware use.

Do: Upgrade Adobe Flash Player to 28.0.0.161 or later, including Red Hat's flash-plugin package on RHEL Desktop/Server/Workstation. Because Flash is now end-of-life, CISA's required KEV action is to remove or disconnect Flash entirely where still in use — audit browsers, Office configurations, and legacy RHEL hosts for residual Flash installs, and block SWF content delivered via email and the web. Given confirmed in-the-wild exploitation, known ransomware use, and 89.5% EPSS, prioritize this in remediation tracking.

7.890% KEV ransomware PoC ×2
  • adobe Flash Player all versions before 28.0.0.161
  • redhat Enterprise Linux Desktop (flash-plugin) Flash Player component before 28.0.0.161
  • redhat Enterprise Linux Server (flash-plugin) Flash Player component before 28.0.0.161
  • +1 more
mass≈ hundreds of millions of desktop installs at time of disclosure; residual unmigrated installs now unknown (Flash is end-of-life)
Full article416 words · extracted from helpnetsecurity.com · click to collapse

The Microsoft February 2018 security updates are for Internet Explorer, Edge, Windows, Office, Office Services and Web Apps, Adobe Flash, and ChakraCore (the core part of the Chakra Javascript engine that powers Microsoft Edge).

Microsoft February 2018 security updates

Jimmy Graham, director of product management at Qualys, considers the Adobe Flash update and that for StructuredQuery in Windows servers and workstations to be the most critical and best implemented as soon as possible.

The former plugs the Flash zero-day bug that is being actively exploited in the wild (CVE-2018-4878), and the latter a critical remote code execution vulnerability (CVE 2018-0825) that can be triggered by a user opening a specially crafted file (delivered via email or compromised website).

“Once again the Microsoft Scripting Engine takes up the wide majority of Critical vulnerabilities,” noted Karl Sigler, a threat intelligence manager at Trustwave.

“These vulnerabilities are bugs in how the Scripting Engine executes scripting languages like Javascript or VBscript. This would affect Microsoft browsers like Edge and IE but also Office documents with macro scripts.” These patches should be prioritized on workstations.

Another critical bug squashed is a memory corruption vulnerability in Outlook (CVE 2018-0852), which can be exploited to achieve remote code execution. Exploitation can be triggered by opening a malicious attachment or viewing the email in Outlook’s Preview Pane.

“If this bug turns into active exploits – and with [the Preview Pane] vector, exploit writers will certainly try – unpatched systems will definitely suffer,” noted Trend Micro Zero Day Initiative’s Dustin Childs pointed out.

Finally, it’s good to note that Microsoft has updated the SPECTRE advisory to say that they’ve released security updates to provide additional protections for the 32-bit (x86) versions of Windows 10 and that customers running these systems should install the applicable update as soon as possible.

“Microsoft continues to work to provide 32-bit (x86) protections for other supported Windows versions but does not have a release schedule at this time,” they added.

Adobe updates

After the Flash update released last week that fixed the aforementioned zero-day bug actively exploited in the wild, Adobe has pushed out security updates to address vulnerabilities in Adobe Experience Manager, Acrobat, and Acrobat Reader.

But while the Adobe Experience Manager update fixes only two vulnerabilities that could lead to disclosure of sensitive information, the Adobe Acrobat and Acrobat Reader updates are more critical: they plug a considerable number of flaws that can lead to arbitrary code execution, remote code execution, or can be exploited for privilege escalation.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2018/02/14/microsoft-adobe-push-out-february-2018-security-updates/