November 2018 Patch Tuesday: Microsoft fixes 63 flaws, one actively exploited zero-day
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-8450 | A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability." This affec A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. NVD description · AI analysis pending | 8.8 | 16% |
| — | ||
| CVE-2018-8476 | A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory, aka "Windows Deployment Services A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory, aka "Windows Deployment Services TFTP Server Remote Code Execution Vulnerability." This affects Windows Server 2012 R2, Windows Server 2008, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows Server 2008 R2, Windows 10 Servers. NVD description · AI analysis pending | 9.8 | 65% |
| — | ||
| CVE-2018-8589 | Local Privilege Escalation in Microsoft Windows Win32k (Windows 7 / Server 2008) CVE-2018-8589 is an elevation of privilege vulnerability in Win32k.sys, the Windows kernel-mode component that handles system calls, affecting Windows 7, Windows Server 2008, and Windows Server 2008 R2. It is triggered when Windows improperly handles calls to Win32k.sys, allowing a local attacker who is already able to execute low-privileged code (for example, via a malicious application or as a second stage of a browser exploit) to escalate privileges. A successful exploit grants the attacker elevated (kernel/SYSTEM-level) privileges on the local machine, typically enabling full control and often chained with code-execution bugs. Windows 7 and Windows Server 2008/2008 R2 users and administrators are affected; the flaw was patched in Microsoft's November 2018 security updates. The vulnerability was known to be actively exploited in the wild at the time of the November 2018 Patch Tuesday, and it is listed in CISA's Known Exploited Vulnerabilities catalog (added May 23, 2022), with EPSS at roughly 3% (87th percentile). Do: Apply the Microsoft November 2018 security updates (or later) to all Windows 7, Windows Server 2008, and Windows Server 2008 R2 systems, per the CISA KEV required action. Because Windows 7 and Server 2008 are past end of support, verify patch status on legacy/extended-support (ESU) systems, inventory any remaining unpatched hosts, and prioritize upgrading them; until patched, limit execution of untrusted local code and keep kernel exploit mitigations enabled. | 7.8 | 3% | KEV |
| masshundreds of millions of Windows 7 devices worldwide at disclosure, plus widespread Windows Server 2008/2008 R2 deployments | |
| CVE-2018-8609 | A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) version 8 when the server fails to properly sanitize web requests to an aff A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) version 8 when the server fails to properly sanitize web requests to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Remote Code Execution Vulnerability." This affects Microsoft Dynamics 365. NVD description · AI analysis pending | 8.8 | 10% |
| — |
Full article480 words · extracted from helpnetsecurity.com · click to collapse
As part of the November 2018 Patch Tuesday, Microsoft has released 62 security patches and several advisories.
There are 12 critical vulnerabilities among those patched this month, but CVE-2018-8589, a Windows Win32k elevation of privilege flaw that’s being actively exploited by attackers, is not one of them.

The attacks exploiting the flaw were flagged by Kaspersky Lab. “The exploit was executed by the first stage of a malware installer in order to gain the necessary privileges for persistence on the victim’s system. So far, we have detected a very limited number of attacks using this vulnerability. The victims are located in the Middle East,” the company’s researchers noted.
A similar vulnerability was reported by Kaspersky in August, and patched by Microsoft last month. As with that one, attackers using CVE-2018-8589 must first gain access to the system and then exploit this flaw to elevate their privileges to gain full control of a target system.
Other vulnerabilities and prioritizing patches
Trend Micro Zero Day Initiative’s Dustin Childs flagged CVE-2018-8450, a Window Search RCE flaw, as critical (although Microsoft does not).
“This patch corrects a problem in Windows Search that could allow a remote attacker to execute privileged code and take over a target system,” he explains. “There is a local component here, but Microsoft also states this could be done by an unauthenticated user via an SMB connection. Remotely triggering elevated code execution without authentication generally means wormable.”
The patch for CVE-2018-8476, a remote code execution flaw affecting Windows Deployment Services’ TFTP Server, should be prioritized if the service is used in the organization’s environment.
“This patch corrects a bug that could allow an attacker to execute code with elevated permissions through a specially crafted TFTP message. Getting elevated code execution over a network without authentication generally means wormable, but for this vulnerability, it would only be wormable to other affected TFTP servers,” Childs noted.
“However, chances are your TFTP server also has other roles. Since this bug allows an attacker to take over a system, any other service – DNS, Active Directory, DHCP, etc. – could also be manipulated. If you’re running deployment services, don’t miss this patch.”
Jimmy Graham, Director of Product Management at Qualys, advises administrators to prioritize:
- browser and Scripting Engine patches for workstation-type devices (and multi-user servers that are used as remote desktops for users), as out of the twelve critical vulnerabilities fixed, ten can be exploited through browsers or opening malicious files, and
- the CVE-2018-8609 patch if they use on-premises deployments of Microsoft Dynamics 365. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SQL service account, and alter the information contained in a database.
As a side note: Adobe has also released security updates on Tuesday, to address information disclosure vulnerabilities in Flash Player, Adobe Acrobat and Reader, and Adobe Photoshop CC.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2018/11/14/november-2018-patch-tuesday/