Microsoft Releases Patch Updates for 53 Vulnerabilities In Its Software
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-8288 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corru A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CVE-2018-8287, CVE-2018-8291, CVE-2018-8296, CVE-2018-8298. NVD description · AI analysis pending | 7.5 | 69% | PoC |
| — | |
| CVE-2018-8279 | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." Th A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8125, CVE-2018-8262, CVE-2018-8274, CVE-2018-8275, CVE-2018-8301. NVD description · AI analysis pending | 7.5 group max | 71% | PoC |
| — | |
| CVE-2018-8283 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-8242, CVE-2018-8287, CVE-2018-8288, CVE-2018-8291, CVE-2018-8296, CVE-2018-8298. NVD description · AI analysis pending | 7.5 | 14% |
| — | ||
| CVE-2018-8298 | Type Confusion RCE in Microsoft ChakraCore Scripting Engine CVE-2018-8298 is a type-confusion (CWE-843) remote code execution flaw in Microsoft's ChakraCore JavaScript engine, which mishandles objects in memory. An attacker triggers it by getting a user or an embedding application to execute attacker-crafted JavaScript, causing the engine to misinterpret object types and corrupt memory (CVSS shows a network attack vector with high complexity and required user interaction). Successful exploitation yields code execution in the context of the hosting process, with high confidentiality, integrity, and availability impact. Anyone running ChakraCore is affected — most prominently the legacy Microsoft Edge browser shipped with Windows 10, plus standalone or embedded ChakraCore builds such as Node.js-ChakraCore; Microsoft is the assigning vendor. Exploitation is confirmed: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), carries an EPSS of 74.8% (99th percentile), and a public proof-of-concept is referenced (Exploit-DB 45217). Do: Apply Microsoft's Patch Tuesday security updates and update ChakraCore to the vendor's current patched release per the CISA KEV required action (see Microsoft's advisory for the exact fixed version). Audit for anything still embedding ChakraCore — legacy Edge on Windows 10, node-chakracore builds, and IoT/embedded integrations — and update or retire it, since modern Chromium-based Edge no longer uses ChakraCore. Until patched, limit rendering of untrusted JavaScript in ChakraCore-hosted applications. | 7.5 | 75% | KEV PoC |
| mass≈100 million+ users (legacy Edge on Windows 10 devices; direct standalone/embedded ChakraCore deployments are far fewer) | |
| CVE-2018-8327 | A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code Execution Vulnerability." This affects P A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code Execution Vulnerability." This affects PowerShell Editor, PowerShell Extension. NVD description · AI analysis pending | 9.8 | 21% |
| — |
Full article580 words · extracted from thehackernews.com · click to collapse
Swati KhandelwalJul 10, 2018
It's time to gear up your systems and software for the latest July 2018 Microsoft security patch updates.
Microsoft today released security patch updates for 53 vulnerabilities, affecting Windows, Internet Explorer (IE), Edge, ChakraCore, .NET Framework, ASP.NET, PowerShell, Visual Studio, and Microsoft Office and Office Services, and Adobe Flash Player.
Out of 53 vulnerabilities, 17 are rated critical, 34 important, one moderate and one as low in severity.
This month there is no critical vulnerability patched in Microsoft Windows operating system and surprisingly, none of the flaw patched by the tech giant this month is listed as publicly known or under active attack.
Critical Flaws Patched In Microsoft Products
Most of the critical issues are memory corruption flaws in IE, Edge browser and Chakra scripting engine, which if successfully exploited, could allow an unauthenticated, remote attacker to execute arbitrary code on a targeted system in the context of the current user.
"If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights," Microsoft explains.
One of these critical flaws (CVE-2018-8327), reported by researchers at Casaba Security, also affects PowerShell Editor Services that could allow a remote attacker to execute malicious code on a vulnerable system.
Here's below you can find a brief list of all critical vulnerabilities Microsoft has patched this month in its various products:
- Scripting Engine Memory Corruption Vulnerability (CVE-2018-8242)
- Edge Memory Corruption Vulnerability (CVE-2018-8262)
- Edge Memory Corruption Vulnerability (CVE-2018-8274)
- Scripting Engine Memory Corruption Vulnerability (CVE-2018-8275)
- Scripting Engine Memory Corruption Vulnerability (CVE-2018-8279)
- Chakra Scripting Engine Memory Corruption Vulnerability (CVE-2018-8280)
- Scripting Engine Memory Corruption Vulnerability (CVE-2018-8283)
- Chakra Scripting Engine Memory Corruption Vulnerability (CVE-2018-8286)
- Scripting Engine Memory Corruption Vulnerability (CVE-2018-8288)
- Chakra Scripting Engine Memory Corruption Vulnerability (CVE-2018-8290)
- Scripting Engine Memory Corruption Vulnerability (CVE-2018-8291)
- Chakra Scripting Engine Memory Corruption Vulnerability (CVE-2018-8294)
- Scripting Engine Memory Corruption Vulnerability (CVE-2018-8296)
- Chakra Scripting Engine Memory Corruption Vulnerability (CVE-2018-8298)
- Microsoft Edge Memory Corruption Vulnerability (CVE-2018-8301)
- Microsoft Edge Information Disclosure Vulnerability (CVE-2018-8324)
- PowerShell Editor Services Remote Code Execution Vulnerability (CVE-2018-8327)
Important Patch Updates for Microsoft Products
Besides this, Microsoft has also addressed 34 important flaws categorized as below:
- Microsoft Edge—Remote code execution (RCE), Information disclosure, spoofing, and security feature bypass flaws
- Microsoft Internet Explorer (IE)— RCE and security feature bypass flaws
- MS Office (Powerpoint, Word, Excel, Access, Lync, Skype)—security feature bypass, RCE, and elevation of privilege flaws
- Windows 10, 8.1, 7 and Server 2008, 2012, 2016—Denial of Service, security feature bypass, elevation of privilege flaws
- Microsoft .NET Framework—Elevation of privilege and RCE flaws
- Microsoft SharePoint—Elevation of Privilege, and RCE flaws
- ChakraCore—RCE, and security feature bypass vulnerabilities
- Microsoft Visual Studio—RCE flaw
- Expression Blend 4—RCE flaw
- ASP .NET—security feature bypass flaws
- Mail, Calendar, and People in Windows 8.1 App Store—information disclosure flaw
Besides this, Microsoft has also pushed security updates to patch vulnerabilities in Adobe products, details of which you can get through a separate article posted today.
Users are strongly advised to apply security patches as soon as possible to keep hackers and cybercriminals away from taking control of their computers.
For installing security updates, simply head on to Settings → Update & security → Windows Update → Check for updates, or you can install the updates manually.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2018/07/microsoft-security-patch-update.html