ZeroHour
Krebs on Securitypublished ()ingested

Patch Tuesday, September 2018 Edition

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-15967
Adobe Flash Player versions 30.0.0.154 and earlier have a privilege escalation vulnerability.

Adobe Flash Player versions 30.0.0.154 and earlier have a privilege escalation vulnerability. Successful exploitation could lead to information disclosure.

NVD description · AI analysis pending
7.57%
  • adobe flash player desktop runtime
  • adobe flash player
  • adobe enterprise linux desktop
  • +1 more
CVE-2018-8409
A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Co

A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1.

NVD description · AI analysis pending
7.57%
  • microsoft .net core
  • microsoft asp.net core
  • microsoft system.io.pipelines
CVE-2018-8440
Local Privilege Escalation in Windows ALPC Handling (Win 7–10, Server 2008–2016)

An elevation-of-privilege vulnerability exists in the way Windows handles calls to the Advanced Local Procedure Call (ALPC) facility, rated 7.8 High with a local attack vector and only low privileges required. An attacker who can already run code on a machine as a low-privileged user can send crafted ALPC messages that the OS mishandles, elevating their privileges to SYSTEM/administrator without any user interaction. Successful exploitation yields full local control (high impact on confidentiality, integrity and availability) and is typically used to consolidate a foothold or escape low-privilege contexts, including in ransomware chains. Affected systems are Windows 7, 8.1, RT 8.1, Windows 10 (1607, 1703, 1709, 1803), Windows 10 Servers, and Windows Server 2008 through 2016 — essentially every Windows client and server platform in support at disclosure. The flaw was publicly demonstrated via a published proof of concept in August 2018, fixed in Microsoft's September 2018 security updates, and is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-28 with known ransomware use, and EPSS puts 30-day exploitation probability at 18.4% (97th percentile).

Do: Apply the September 2018 (or later) Microsoft cumulative/monthly rollup updates across all affected Windows client and server systems, prioritizing servers and domain-joined hosts given known ransomware use and the CISA KEV listing. Legacy machines that no longer receive updates (e.g., Windows 7, Server 2008/2008 R2, 2012/2012 R2) should be upgraded to a supported OS or covered by Extended Security Updates. Verify remediation by confirming the September 2018 patch level is present on each host, since OS version alone does not indicate exposure.

7.818% KEV ransomware PoC
  • Microsoft Windows 10 1607, 1703, 1709, 1803 (CPE-listed; CISA description lists Windows 10 broadly)
  • Microsoft Windows 10 Servers all editions per CISA listing (server editions of Windows 10)
  • Microsoft Windows 7 all supported editions (no service pack pinned in source data)
  • +5 more
mass≈1 billion+ Windows installations were in affected versions at the 2018 disclosure; the residual unpatched estate today is likely in the millions of legacy…
CVE-2018-8457
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corru

A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 11, Microsoft Edge, Internet Explorer 10. This CVE ID is unique from CVE-2018-8354, CVE-2018-8391, CVE-2018-8456, CVE-2018-8459.

NVD description · AI analysis pending
7.513%
  • microsoft internet explorer
  • microsoft edge
CVE-2018-8475
A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files, aka "Windows Remote Code Execution Vulnerabili

A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files, aka "Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

NVD description · AI analysis pending
8.816%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
Full article784 words · extracted from krebsonsecurity.com · click to collapse

Adobe and Microsoft today each released patches to fix serious security holes in their software. Adobe pushed out a new version of its beleaguered Flash Player browser plugin. Redmond issued updates to address at least 61 distinct vulnerabilities in Microsoft Windows and related programs, including several flaws that were publicly detailed prior to today and one “zero-day” bug in Windows that is already being actively exploited by attackers.

As per usual, the bulk of the fixes from Microsoft tackle security weaknesses in the company’s Web browsers, Internet Explorer and Edge. Patches also are available for Windows, Office, Sharepoint, and the .NET Framework, among other components.

Of the 61 bugs fixed in this patch batch, 17 earned Microsoft’s “critical” rating, meaning malware or miscreants could use them to break into Windows computers with little or no help from users.

The zero-day flaw, CVE-2018-8440, affects Microsoft operating systems from Windows 7 through Windows 10 and allows a program launched by a restricted Windows user to gain more powerful administrative access on the system. It was first publicized August 27 in a (now deleted) Twitter post that linked users to proof-of-concept code hosted on Github. Since then, security experts have spotted versions of the code being used in active attacks.

According to security firm Ivanti, prior to today bad guys got advance notice about three vulnerabilities in Windows targeted by these patches. The first, CVE-2018-8457, is a critical memory corruption issue that could be exploited through a malicious Web site or Office file. CVE-2018-8475 is a critical bug in most supported versions of Windows that can be used for nasty purposes by getting a user to view a specially crafted image file. The third previously disclosed flaw, CVE-2018-8409, is a somewhat less severe “denial-of-service” vulnerability.

Standard advice about Windows patches: Not infrequently, Redmond ships updates that end up causing stability issues for some users, and it doesn’t hurt to wait a day or two before seeing if any major problems are reported with new updates before installing them. Windows 10 likes to install patches and reboot your computer on its own schedule, and Microsoft doesn’t make it easy for Windows 10 users to change this setting, but it is possible. For all other Windows OS users, if you’d rather be alerted to new updates when they’re available so you can choose when to install them, there’s a setting for that in Windows Update.

It’s a good idea to get in the habit of backing up your computer before applying monthly updates from Microsoft. Windows has some built-in tools that can help recover from bad patches, but restoring the system to a backup image taken just before installing updates is often much less hassle and an added peace of mind while you’re sitting there praying for the machine to reboot successfully after patching.

The sole non-Microsoft update pushed by Redmond today fixes a single vulnerability in Adobe Flash Player, CVE-2018-15967. Curiously, Adobe lists the severity of this information disclosure bug as “important,” while Microsoft considers it a more dangerous “critical” flaw.

Regardless, if you have Adobe Flash Player installed, it’s time to either update your browser and/or operating system, or else disable this problematic and insecure plugin. Windows Update should install the Flash Patch for IE/Edge users; the newest version of Google Chrome, which bundles Flash but prompts users to run Flash elements on a Web page by default, also includes the fix (although a complete Chrome shutdown and restart may be necessary before the fix is in).

Loyal readers here know full well where I stand on Flash: This is a dangerous, oft-exploited program that needs to be relegated to the dustbin of Internet history (for its part, Adobe has said it plans to retire Flash Player in 2020). Fortunately, disabling Flash in Chrome is simple enough. Paste “chrome://settings/content” into a Chrome browser bar and then select “Flash” from the list of items.

By default, Mozilla Firefox on Windows computers with Flash installed runs Flash in a “protected mode,” which prompts the user to decide if they want to enable the plugin before Flash content runs on a Web site.

Administrators have the ability to change Flash Player’s behavior when running Internet Explorer on Windows 7 by prompting the user before playing Flash content. A guide on how to do that is here (PDF). Administrators may also consider implementing Protected View for Office. Protected View opens a file marked as potentially unsafe in Read-only mode.

As always, please feel free to leave a note in the comments below if you experience any issues installing these fixes. Happy patching!

Text extracted automatically; images, tables and formatting may be missing. Original: https://krebsonsecurity.com/2018/09/patch-tuesday-september-2018-edition/