ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Microsoft drops emergency Internet Explorer fix for actively exploited zero-day

criticalExploit / PoC exploited in the wildimportance 60CVE-2019-1367CVE-2019-1255

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-1255
A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denial of Service Vulnerability'.

A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denial of Service Vulnerability'.

NVD description · AI analysis pending
7.54%
  • microsoft windows defender
  • microsoft forefront endpoint protection 2010
  • microsoft security essentials
  • +1 more
CVE-2019-1367
Memory Corruption RCE in Microsoft Internet Explorer Scripting Engine

CVE-2019-1367 is a memory corruption flaw (CWE-787, out-of-bounds write) in the way the Internet Explorer scripting engine handles objects in memory, enabling remote code execution when the corrupted objects are processed. Attackers trigger it by convincing a user to load malicious web content in an affected Internet Explorer installation — such as visiting an attacker-controlled or compromised page, or opening a document/application that hosts IE — with user interaction required per the CVSS vector. Successful exploitation executes attacker code with the user's privileges; the flaw was exploited as an actively-attacked zero-day, with distribution observed through the Magnitude exploit kit, prompting Microsoft to release an out-of-band emergency fix. Any Windows system with an affected Internet Explorer installation is exposed, with enterprise users dependent on IE for legacy web applications at particular risk. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03, with known ransomware use), EPSS estimates a 52.4% probability of exploitation within 30 days, and no public proof-of-concept is catalogued.

Do: Apply Microsoft's out-of-band (September 2019) and subsequent cumulative Windows/Internet Explorer security updates on all endpoints, per the vendor's instructions, since this is a KEV-listed flaw with known ransomware use; Microsoft's documented mitigation, restricting access to the IE scripting engine component (jscript.dll) and reducing use of Internet Explorer in favor of a modern browser, can protect systems until patched. Verify the update applied cleanly — users reportedly experienced problems with the initial patches — and prioritize user workstations and any systems used to browse untrusted content.

7.552% KEV ransomware
  • Microsoft Internet Explorer
masstens of millions to hundreds of millions of Windows endpoints with Internet Explorer present (IE is bundled with Windows)
Full article427 words · extracted from helpnetsecurity.com · click to collapse

Microsoft has unexpectedly released out-of-band security updates to fix vulnerabilities in Internet Explorer and Microsoft Defender. The IE zero-day bug is deemed “critical”, as it’s being actively exploited to achieve partial or complete control of a vulnerable systems.

CVE-2019-1367

The Internet Explorer vulnerability (CVE-2019-1367)

CVE-2019-1367 is a memory corruption vulnerability in the scripting engine that could be exploited to achieve remote code execution.

An attacker who successfully exploited the vulnerability could gain the same user rights as the current user – if the user is logged on with administrative user rights, that means the attacker gets complete control over the system.

“In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability through Internet Explorer and then convince a user to view the website, for example, by sending an email,” Microsoft explained.

This piece of information combined with the fact that the flaw was reported by Clément Lecigne of Google’s Threat Analysis Group has given rise to speculation that the vulnerability was/is being exploited by the same threat actors who exploited various iOS bugs to compromise visitors to specific booby-trapped sites.

Whether or not that conjecture is true, Microsoft obviously assessed that issuing an unscheduled patch is important, so here we are.

The vulnerability affects Internet Explorer 9, 10 and 11. Depending on the underlying system, users are advised to (download and) implement the offered security update or cumulative security update. If updating is impossible at this moment, there’s a temporary workaround that can be implemented.

The Microsoft Defender vulnerability (CVE-2019-1255)

CVE-2019-1255 is a denial of service vulnerability that could allow an attacker “to prevent legitimate accounts from executing legitimate system binaries.”

To exploit the flaw, though, the attacker must first achieve execution rights on the target system.

The fix for the flaw, which was flagged by Charalampos Billinis of F-Secure Countercept and Wenxu Wu of Tencent Security Xuanwu Lab, is being propagated through a new version of the Microsoft Malware Protection Engine (v1.1.16400.2).

“For enterprise deployments as well as end users, the default configuration in Microsoft antimalware software helps ensure that malware definitions and the Microsoft Malware Protection Engine are kept up to date automatically,” Microsoft notes.

“For end-users, the affected software provides built-in mechanisms for the automatic detection and deployment of this update. For these customers, the update will be applied within 48 hours of its availability. The exact time frame depends on the software used, Internet connection, and infrastructure configuration. End users that do not wish to wait can manually update their antimalware software.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2019/09/24/cve-2019-1367/