ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Microsoft Patches Three Zero

criticalVulnerability exploited in the wildimportance 60CVE-2023-29336CVE-2023-24932CVE-2023-29325

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-29325
+1 in the same advisory: …24932
Windows OLE Remote Code Execution Vulnerability

Windows OLE Remote Code Execution Vulnerability

NVD description · AI analysis pending
7.5
group max
84%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2023-29336
Use-after-free privilege escalation to SYSTEM in Microsoft Win32k

CVE-2023-29336 is a use-after-free flaw (CWE-416) in Microsoft's Win32k kernel component that allows privilege escalation to SYSTEM. It is triggered by code running on a Windows host that causes the Win32k driver to reference freed kernel memory; the exact trigger path is not detailed in the available data, but as a kernel elevation-of-privilege issue it requires local code execution or an attacker already holding a foothold on the machine. A successful exploit grants SYSTEM privileges, giving the attacker full control of the compromised host. Because Win32k ships in every supported Windows client and server, effectively the entire Windows installed base is exposed to the flaw. The vulnerability is confirmed exploited in the wild — CISA added it to the KEV catalog on 2023-05-09 — and EPSS places its 30-day exploitation probability at 40.9% (99th percentile), though no public proof-of-concept is known and ransomware use is unconfirmed.

Do: Apply Microsoft's current cumulative Windows security updates (issued May 2023, per the CISA KEV required action) across all Windows clients and servers, prioritizing servers and systems exposed to untrusted users since the flaw is being actively exploited. Until patched, limit untrusted local code execution and restrict remote entry points such as RDP, because local privilege escalation flaws are commonly chained into full compromises. Verify update installation after deployment; specific affected build numbers and any ransomware involvement are not stated in the available data.

7.841% KEV PoC
  • Microsoft Win32k
mass≈1 billion+ Windows devices (Win32k ships in every supported Windows client and server)
Full article430 words · extracted from infosecurity-magazine.com · click to collapse

Microsoft issued fixes for just 38 CVEs this month, including three zero-day vulnerabilities.

Although this month’s Patch Tuesday update round is one of the smallest this year, experts warned that sysadmins should move quickly to patch the zero-days, two of which are being actively exploited in the wild.

The first is CVE-2023-29336, an elevation of privilege vulnerability in Win32k that grants the attacker system privileges, allowing them to escalate access rights. Although an attacker first has to possess basic privileges on a system, this is fairly easily done via a phishing attack or credential harvesting.

“It has a local attack vector, meaning the attacker needs access to the targeted system. The attack complexity is low, requiring minimal privileges and no user interaction,” explained Mike Walters, VP of vulnerability and threat research at Action1.

“As of now, no workarounds or alternative solutions are available, making the installation of the updates the most effective way to mitigate the risk and ensure the security of your systems.”

Read more on Microsoft zero-day vulnerabilities: Microsoft Fixes Three Zero-Days in May Patch Tuesday.

The second CVE being actively exploited in the wild is CVE-2023-24932: a low-complexity secure boot security feature bypass bug which also requires no user interaction.

An attacker would need physical or administrator access to a target system to exploit the CVSS 6.7-rated vulnerability, said Walters.

“Successful exploitation of this vulnerability allows an attacker to bypass secure boot, thereby enabling the loading of malicious drivers or malware without Microsoft-trusted signatures during Windows startup,” he explained.

“To address this vulnerability, a security update has been released that updates the Windows Boot Manager. However, it is important to note that this update is not enabled by default. To mitigate the vulnerability, you must follow three essential steps detailed in the Microsoft article KB5025885.”

The final zero-day patched this month is CVE-2023-29325: a critical remote code execution bug in Windows OLE. A proof-of-concept is available for the bug, meaning that attacks in the wild will not be far away.

“With this vulnerability, the simple act of glancing at a carefully crafted malicious email in Outlook’s preview pane is enough to enable remote code execution and potentially compromise the recipient’s computer,” explained Yoav Iellin, senior researcher at Silverfort.

“At this stage, we believe Outlook users will be the main attack vector, although it has the potential to be used in other Office programs as well. We recommend ensuring client’s Windows machines and Office software are fully up to date and consider following the workaround given by Microsoft while deploying the patch.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-patches-three-zeroday-1/