ZeroHour
Security Affairspublished ()ingested @securityaffairs

Microsoft patch Tuesday security updates fix PrintNightmare flaws

criticalVulnerability exploited in the wildimportance 60CVE-2021-36948CVE-2020-1380CVE-2020-1585

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-1380
Memory Corruption RCE in Microsoft Internet Explorer Scripting Engine

CVE-2020-1380 is a memory corruption vulnerability (an out-of-bounds write, CWE-787) in the Microsoft Internet Explorer scripting engine that can corrupt memory when the engine processes maliciously crafted script content. It is triggered by luring a user to visit an attacker-controlled or compromised web page in Internet Explorer or in an application that invokes the IE engine, with no authentication required. Successful exploitation allows the attacker to execute arbitrary code in the context of the current user, gaining that user's privileges on the system. All installations of the affected Microsoft Internet Explorer versions are potentially exposed, with the greatest risk to legacy and enterprise Windows systems that still browse or render content with IE. The flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating exploitation in the wild, while no public proof-of-concept is known and ransomware use is unconfirmed.

Do: Apply Microsoft's June 2020 (or later) Windows cumulative security updates on every system running Internet Explorer, per the vendor instructions cited by CISA. Given the KEV listing (added 2021-11-03) and high EPSS (~24% 30-day exploitation probability, 98th percentile), treat this as a priority patch. Reduce attack surface by steering users to Microsoft Edge instead of IE for web browsing and auditing internal apps or legacy sites that still invoke the IE engine to render external content.

7.824% KEV
  • Microsoft Internet Explorer Microsoft Internet Explorer (source data does not enumerate version ranges; Microsoft addressed this flaw in its June 2020 Windows security updates)
masshundreds of millions of Windows devices historically able to run Internet Explorer; exact currently-vulnerable count unknown
CVE-2020-1585
A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory.

A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Exploitation of the vulnerability requires that a program process a specially crafted image file. The update addresses the vulnerability by correcting how Microsoft Windows Codecs Library handles objects in memory.

NVD description · AI analysis pending
8.85%
  • microsoft windows 10
CVE-2021-36948
Privilege Escalation in Microsoft Windows Update Medic Service

CVE-2021-36948 is an elevation-of-privilege flaw in the Microsoft Windows Update Medic Service (WaaSMedicSvc), the built-in service that keeps Windows Update functioning; Microsoft has not publicly detailed the underlying bug. A local attacker who can execute code on a target machine can abuse the service to elevate their privileges to higher integrity levels, typically SYSTEM, enabling full control of the host such as installing software, modifying accounts, and disabling defenses. Any Windows system running the Windows Update Medic Service is affected; CISA lists the impacted product simply as 'Microsoft Windows' without version detail, and the service ships with Windows 10 and later. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, indicating confirmed exploitation in the wild, with no public proof-of-concept code known and ransomware use undetermined. Microsoft's EPSS model assigns a 26.7% probability of exploitation within 30 days (98th percentile), so patching urgency is high.

Do: Apply Microsoft's November 2021 Patch Tuesday cumulative updates (per the vendor's advisory) via Windows Update or your patch management platform, prioritizing servers, workstations, and multi-user hosts where local privilege escalation is most damaging. Since CISA lists this in KEV, federal and regulated environments must patch by the catalog deadline; as an interim mitigation, restrict untrusted local code execution and review whether any local accounts show unexpected SYSTEM-level activity.

7.823% KEV
  • Microsoft Windows (systems running the Windows Update Medic Service; Windows 10 and later) CISA lists affected product as 'Microsoft Windows' without version detail; remediated in Microsoft's November 2021 security updates
mass≈1 billion+ Windows devices (the Medic Service ships on effectively every Windows 10/11 machine)
Full article459 words · extracted from securityaffairs.com · click to collapse

Microsoft released patch Tuesday security updates for August that address 120 CVEs in Microsoft products including a zero-day actively exploited in the wild.

Microsoft released patch Tuesday security updates for August that address 120 CVEs in multiple products, including Microsoft Windows, Edge (EdgeHTML-based and Chromium-based), ChakraCore, Internet Explorer (IE), Microsoft Scripting Engine, SQL Server, .NET Framework, ASP.NET Core, Office and Office Services and Web Apps, Windows Codecs Library, and Microsoft Dynamics.

17 vulnerabilityìies fixed by the IT giant have been rated Critical, the remaining as Important in severity.

The actively exploited issue is a local privilege flaw tracked as  CVE-2021-36948, the vulnerability affects the Windows Update Medic Service and has been rated “important” with a CVSS base score of 7.8.

Microsoft described the vulnerability as a local privilege escalation bug, a suggestion that it is part of a larger software exploit chain.

One of the most severe flaws addressed by the company, tracked as CVE-2020-1380, is a scripting Engine Memory corruption vulnerability.

“A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.” reads the advisory published by Microsoft.

“In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability through Internet Explorer and then convince a user to view the website. An attacker could also embed an ActiveX control marked “safe for initialization” in an application or Microsoft Office document that hosts the IE rendering engine. The attacker could also take advantage of compromised websites and websites that accept or host user-provided content or advertisements. These websites could contain specially crafted content that could exploit the vulnerability.”

Another flaw fixed by Microsoft, tracked as  CVE-2020-1585, is a Microsoft Windows Codecs Library Remote Code Execution Vulnerability
An attacker could trigger the flaw to gain code execution on the target system, the attacker can trick a user into viewing a specially crafted image file.

Microsoft also announced that Windows will now require admin rights to change the default Point and Print driver installation and update behavior, the decision will fix PrintNightmare flaws.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Microsoft patch Tuesday)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/121014/security/microsoft-patch-tuesday-august-2021.html