ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Microsoft Fixes Fewer Than 100 Bugs for First Time Since February

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-16898
A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets.

A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could gain the ability to execute code on the target server or client. To exploit this vulnerability, an attacker would have to send specially crafted ICMPv6 Router Advertisement packets to a remote Windows computer. The update addresses the vulnerability by correcting how the Windows TCP/IP stack handles ICMPv6 Router Advertisement packets.

NVD description · AI analysis pending
8.8
group max
11%
  • microsoft windows 10
  • microsoft windows server 2016
  • microsoft windows server 2019
CVE-2020-16937
An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory.

An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attacker who successfully exploited the vulnerability could disclose contents of an affected system's memory. To exploit the vulnerability, an authenticated attacker would need to run a specially crafted application. The update addresses the vulnerability by correcting how the .NET Framework handles objects in memory.

NVD description · AI analysis pending
4.73%
  • microsoft .net framework
CVE-2020-16947
A remote code execution vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory.

A remote code execution vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the targeted user. If the targeted user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Outlook software. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file designed to exploit the vulnerability. An attacker would have no way to force users to visit the website. Instead, an attacker would have to convince users to click a link, typically by way of an enticement in an email or instant message, and then convince them to open the specially crafted file. Note that where severity is indicated as Critical in the Affected Products table, the Preview Pane is an attack vector. The security update addresses the vulnerability by correcting how Outlook handles objects in memory.

NVD description · AI analysis pending
7.534%
  • microsoft 365 apps
  • microsoft office
  • microsoft outlook
Full article330 words · extracted from infosecurity-magazine.com · click to collapse

Microsoft has issued its first patch update for eight months fixing fewer than 100 CVEs, although six are related to publicly disclosed bugs and will need prioritizing.

October’s Patch Tuesday yesterday addressed 87 vulnerabilities including 11 rated critical.

Many experts pointed to CVE-2020-16898, which has a CVSS score of 9.8, as a priority.

“This is a remote code execution vulnerability in Microsoft’s TCP/IP stack. The vulnerability is in the way the Windows TCP/IP stack handles ICMPv6 Router Advertisement packets,” explained Recorded Future senior security architect, Allan Liska.

“For successful exploitation of this vulnerability, all an attacker has to do is send a specially crafted ICMPv6 Router Advertisement packet to a remote Windows computer. This vulnerability impacts Windows 10 and Windows Server 2019 and should be patched immediately.”

Elsewhere, five of the six bugs affect Windows 10 and related server editions: CVE-2020-16908CVE-2020-16909CVE-2020-16901CVE-2020-16885 and CVE-2020-16938. The sixth affects the .Net Framework (CVE-2020-16937).

Todd Schell, senior product manager at Ivanti, also pointed to CVE-2020-16947, a vulnerability in Microsoft Outlook which could allow remote code execution just by viewing a specially crafted email.

“The Preview Pane is an attack vector here, so you don’t even need to open the mail to be impacted,” he added. “The flaw exists within the parsing of HTML content in an email. Patch this one quickly. It will be an attractive target for threat actors.”

Another RCE flaw, this time in Windows Hyper-V, is CVE-2020-16891.

“This patch corrects a bug that allows an attacker to run a specially crafted program on an affected guest OS to execute arbitrary code on the host OS. A guest OS escape like this would also be very attractive to threat actors,” said Schell.

Microsoft also released a preview of its new update guide this month. It’s designed to provide a more intuitive layout so sysadmins can get to the risk-based information they need quicker, including exploited and publicly disclosed vulnerabilities.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-fixes-fewer-than-100-bugs/