ZeroHour
The Recordpublished ()ingested

CISA gives US civilian agencies until August 1 to resolve four Microsoft vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-32049
+3 in the same advisory: …36884 …36874 …32046
Windows SmartScreen Security Feature Bypass Exploited in the Wild (CVE-2023-32049)

CVE-2023-32049 is a security feature bypass in Microsoft Windows Defender SmartScreen, the mechanism that warns users before they run downloaded or untrusted content; specially crafted content delivered over the network causes SmartScreen to skip that warning when a user opens it. The flaw requires user interaction (CVSS vector AV:N/AC:L/UI:R), so attackers must lure a victim into clicking or opening the crafted URL or file, and in exchange they gain the ability to run content without the expected SmartScreen prompt, typically as a link in a chain that delivers malware or establishes initial access. All users of Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2), and Windows Server 2016/2019/2022 are affected. The flaw was fixed in Microsoft's July 2023 Patch Tuesday batch (132 vulnerabilities, six under active attack) and was added to CISA's Known Exploited Vulnerabilities catalog on 2023-07-11, confirming in-the-wild exploitation; no public proof-of-concept is known and ransomware use is unknown.

Do: Apply Microsoft's July 2023 (or later) cumulative Windows security updates on every affected Windows 10, Windows 11, and Windows Server release, per the vendor instructions and CISA KEV required action. After patching, verify SmartScreen and Mark-of-the-Web warning behavior remain enabled and intact, and prioritize fleet-wide rollout given confirmed in-the-wild exploitation; treat unpatched users as susceptible to warning-free delivery of malicious files and links.

8.8
group max
4% KEV
  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 21H2, 22H2
  • Microsoft Windows Server 2016, 2019, 2022
masshundreds of millions of endpoints and servers (the affected Windows 10/11 and Server releases make up the large majority of the supported Windows installed…
CVE-2023-35311
TOCTOU Security Feature Bypass in Microsoft Outlook (Exploited in the Wild)

CVE-2023-35311 is a time-of-check to time-of-use (TOCTOU) race condition (CWE-367) in Microsoft Outlook that allows a security feature to be bypassed. It is triggered remotely over the network when a user interacts with a specially crafted email; per Microsoft's advisory, the attacker needs to know the target's mailbox email address. Successful exploitation defeats Outlook's security check (scored high for confidentiality and integrity impact), lowering the barrier for follow-on actions such as malware delivery via email content. The flaw affects Outlook as delivered with Microsoft 365 Apps, Office, and Office LTSC. It is confirmed exploited in the wild (added to CISA KEV on 2023-07-11) and was fixed in Microsoft's July 2023 Patch Tuesday; no public proof-of-concept is known.

Do: Apply the July 2023 Patch Tuesday security updates (released July 11, 2023) for Outlook, Office, Microsoft 365 Apps, and Office LTSC as soon as possible, since the flaw is being exploited in the wild and is on CISA's KEV list (U.S. civilian agency deadline August 1, 2023). After patching, verify Outlook and Office build numbers reflect the July 2023 updates, and review mailboxes for suspicious emails that users interacted with around the security prompt. Ransomware use is unknown, so treat any unpatched internet-active mail clients as priority targets in patch cycles.

8.816% KEV
  • Microsoft Outlook Builds prior to the July 11, 2023 Patch Tuesday security updates
  • Microsoft 365 Apps Builds prior to the July 11, 2023 Patch Tuesday security updates
  • Microsoft Office Builds prior to the July 11, 2023 Patch Tuesday security updates
  • +1 more
masshundreds of millions of Outlook users worldwide
Full article690 words · extracted from therecord.media · click to collapse

The Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal civilian agencies until August 1 to resolve four serious zero-day vulnerabilities announced as part of Microsoft’s monthly Patch Tuesday release.

The inclusion of the four vulnerabilities — CVE-2023-32046, CVE-2023-32049, CVE-2023-35311, CVE-2023-36874 — into CISA’s catalog means the bugs are already being exploited by hackers.

The four cited Microsoft vulnerabilities are among more than 130 announced by the tech giant on Tuesday.

A Microsoft spokesperson told Recorded Future News on Thursday that none of the releases are connected to revelations that a Chinese hacking group exploited a bug in the company’s cloud email service to spy on 25 organizations, including some government agencies, members of Congress and even Commerce Secretary Gina Raimondo.

In its blog post on that situation, Microsoft said the hackers — part of a group they refer to as Storm-0558 — “exploited a token validation issue” during the attack, but the company did not elaborate on what specific vulnerability was used.

“The security updates released this month are separate from the mitigations regarding Storm-0558 activity,” the spokesperson said.

The spokesperson declined to say what vulnerability was exploited by the China-based group and whether advisories will be released covering those issues.

Outlook and browser bugs

CVE-2023-35311 caused significant alarm among experts because it affects Microsoft Outlook. Experts from Trend Micro’s Zero Day Initiative said the bug “allows attackers to bypass an Outlook Security Notice prompt after clicking a link.”

“This is likely being paired with some other exploit designed to execute code when opening a file. Outlook should pop a warning dialog, but this vulnerability evades that user prompt. Considering how broadly Outlook is used, this should be your first priority for test and deployment,” they said.

Microsoft confirmed that it was being exploited but provided no information on what groups are using the bug, only writing that it carries a CVSS score of 8.8 out of 10 and affects all versions of Microsoft Outlook from 2013 onwards.

“Because Outlook is a popular email client, the potential impact for organizations if this vulnerability is left unpatched could be severe,” said Automox CISO Jason Kikta. “This vulnerability is perfect fuel for phishing and will be especially popular with criminal actors to potentially enable a ransomware or fraud event. We recommend patching within 24 hours to mitigate.”

Immersive Labs’ Kev Breen added that the vulnerability would be “especially dangerous” if paired with other vulnerabilities like CVE-2023-36884, which affects Microsoft Office and was reported earlier this week, or CVE-2023-32046 — a bug affecting the Microsoft software component used to render web pages on Windows.

Mike Walters, co-founder of cybersecurity firm Action1, said CVE-2023-32046 on its own was concerning because of how it will be used by hackers. In order to exploit the bug, hackers need to get a victim to open a specially crafted file.

In one scenario, Walters said an attacker could send the manipulated file through email and find some way to get them to open it.

“Similarly, in a web-based attack scenario, the attacker may host a website containing the specially crafted file intended to exploit the vulnerability. It is important to note that the attacker would only acquire the rights of the user running the affected application,” he said.

“Therefore, if a user does not possess administrative rights on the computer, neither does the attacker. Considering that this vulnerability is actively being exploited and has the potential to be combined with other exploits, it is strongly advised to promptly apply the available update.”

In addition to browsers, the component affected by the bug is used by applications like Office, Outlook, and Skype.

In addition to the Microsoft announcements, several other companies, including Apple, Google, SAP, Fortinet, Adobe, and Cisco, published advisories about their own vulnerabilities.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/four-microsoft-vulnerabilities-cisa-civilian-agencies