ZeroHour
Krebs on Securitypublished ()ingested

Microsoft’s October Patch Batch Fixes 62 Flaws

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-11776
Microsoft Outlook 2016 allows an attacker to obtain the email content of a user, due to how Outlook 2016 discloses user email content, aka "Microsoft Outlook In

Microsoft Outlook 2016 allows an attacker to obtain the email content of a user, due to how Outlook 2016 discloses user email content, aka "Microsoft Outlook Information Disclosure Vulnerability."

NVD description · AI analysis pending
7.59%
  • microsoft outlook
CVE-2017-11779
+1 in the same advisory: …8703
The Microsoft Windows Domain Name System (DNS) DNSAPI.dll on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 170

The Microsoft Windows Domain Name System (DNS) DNSAPI.dll on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly handle DNS responses, aka "Windows DNSAPI Remote Code Execution Vulnerability".

NVD description · AI analysis pending
8.1
group max
33%
  • microsoft windows 10
  • microsoft windows 8.1
  • microsoft windows rt 8.1
  • +1 more
CVE-2017-11826
Memory Corruption RCE in Microsoft Office, Word, SharePoint and Office Web Apps

Affected versions of Microsoft Office and related server products fail to properly handle objects in memory (CWE-119 memory corruption), allowing remote code execution. The flaw is triggered when a user opens a specially crafted document, for example a malicious Word file delivered by email, with an affected version of Word, Word Viewer, the Office Compatibility Pack, Office 2010, or an affected SharePoint / Office Web Apps / Office Online Server component; the CVSS vector (AV:L, UI:R) reflects this user-interaction requirement. A successful attacker runs arbitrary code in the context of the logged-in user, with high impact on confidentiality, integrity and availability (CVSS 3.1 base 7.8, high). Anyone running Word 2007/2010/2013/2016, Office 2010, Word Viewer, the Office Compatibility Pack, SharePoint Enterprise Server 2010 or SharePoint Server 2010 (including Word Automation Services), Office Web Apps Server 2010 and 2013, Office Web Applications, or Office Online Server is affected. The bug was addressed as an Office zero-day in Microsoft's October 2017 Patch Tuesday release, is listed in the CISA KEV catalog (added 2022-03-03, indicating exploitation in the wild; ransomware use unknown), and EPSS assigns an 81.3% probability of exploitation within 30 days (100th percentile).

Do: Apply Microsoft's October 2017 Patch Tuesday security updates to all affected components, including the frequently missed Word Viewer and Office Compatibility Pack, across endpoints, SharePoint 2010 servers, and Office Web Apps/Office Online Server deployments (KEV required action: apply updates per vendor instructions). Until patched, treat unsolicited Word documents and attachments as untrusted and verify users' installed Office builds. Prioritize remediation given confirmed in-the-wild exploitation.

7.881% KEV PoC ×2
  • Microsoft Office 2010 2010
  • Microsoft Word 2007, 2010, 2013, 2016
  • Microsoft Word Viewer
  • +7 more
masshundreds of millions of desktop Office/Word installations (Microsoft's Office installed base exceeded 1 billion users when the flaw was disclosed), plus tens…
Full article404 words · extracted from krebsonsecurity.com · click to collapse

Microsoft on Tuesday released software updates to fix at least 62 security vulnerabilities in Windows, Office and other software. Two of those flaws were detailed publicly before yesterday’s patches were released, and one of them is already being exploited in active attacks, so attackers already have a head start.

brokenwindowsRoughly half of the flaws Microsoft addressed this week are in the code that makes up various versions of Windows, and 28 of them were labeled “critical” — meaning malware or malicious attackers could use the weaknesses to break into Windows computers remotely with no help from users.

One of the publicly disclosed Windows flaws (CVE-2017-8703) fixed in this batch is a problem with a feature only present in Windows 10 known as the Windows Subsystem for Linux, which allows Windows 10 users to run unmodified Linux binary files. Researchers at CheckPoint recently released some interesting research worth reading about how attackers might soon use this capability to bypass antivirus and other security solutions on Windows.

The bug quashed this week that’s being actively exploited resides in Microsoft Office (CVE-2017-11826), and Redmond says attackers could seize control over a vulnerable system just by convincing someone to open a booby-trapped Word file. Another Office vulnerability, (CVE-2017-11776), involves a flaw in Outlook’s ability to encrypt messages; SEC-Consult has more details on this bug.

Another critical flaw (CVE-2017-11779) addresses a scary vulnerability in the domain name system (DNS) component of Windows 8 and Windows Server 2012. According to research from Bishop Fox, the security firm credited with finding and reporting the bug, this flaw could be exploited quite easily to gain complete control over vulnerable systems if the attacker controls or compromises a local network (think Wi-Fi hotspot).

Normally, Adobe uses Microsoft’s Patch Tuesday (the second Tuesday of each month) to release its own fixes for Flash Player, Reader and other products. However, this time around the company has no security updates available. Adobe did release a new version of Flash that includes bug fixes (v. 27.0.0.159), but generally speaking only even-numbered Flash releases include security fixes.

For additional commentary on October’s bundle of updates from Microsoft, see these blogs from security vendors Ivanti and Qualys. For those looking for a straight-up list of which patches deserve priority, check out the always useful roundup from the SANS Internet Storm Center.

Text extracted automatically; images, tables and formatting may be missing. Original: https://krebsonsecurity.com/2017/10/microsofts-october-patch-batch-fixes-62-flaws/