ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

Microsoft Security Updates June 2015

criticalVulnerabilityimportance 60CVE-2015-2360

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2015-2360
Win32k Local Privilege Escalation in Microsoft Windows Kernel Drivers

CVE-2015-2360 is a memory-handling flaw (CWE-119) in Win32k.sys, the Windows kernel-mode driver, that allows a local user to elevate privileges or cause a denial-of-service crash. It is triggered by local code that drives Win32k into improperly handling objects in memory, letting the attacker run code with kernel/SYSTEM-level rights — typically chained with a separate remote code execution bug to go from network access to full system compromise. Any Microsoft Windows system that has not received the vendor fix is affected, and because the fix shipped in mid-2015, the remaining exposed population is largely legacy Windows deployments that missed regular patching. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-25, indicating exploitation in the wild, and EPSS assigns a 15% probability of exploitation within 30 days (96th percentile); no public proof-of-concept is known.

Do: Apply the Microsoft update from security Bulletin MS15-078 (July 2015) to any Windows system lacking it, prioritizing internet-facing hosts running legacy Windows/Server releases and POS, embedded or air-gapped systems that miss routine patch cycles. Verify via patch inventory that the affected Win32k.sys builds are current, and treat the CISA KEV listing as mandatory remediation per the required action (apply updates per vendor instructions).

15% KEV
  • Microsoft Win32k.sys / Windows kernel-mode drivers (Microsoft Windows) All supported Windows releases of the era — Windows Vista SP2, Windows 7 SP1, Windows 8, Windows 8.1, Windows RT 8.1, Windows Server 2008 SP2, Server 2008 R2 SP
massplausibly millions of legacy Windows systems remain unpatched, out of a multi-hundred-million to >1 billion Windows install base
Full article322 words · extracted from securelist.com · click to collapse

Software

Software

09 Jun 2015

minute read

MS15-061 patches eight different software flaws in the kernel, including cve-2015-2360

Microsoft releases eight security bulletins today, updating a set of forty five software vulnerabilities. This month’s updates touch a smaller set of Microsoft software, but two of the Bulletins address kernel-level vulnerabilities and require a restart. Some are being exploited as a part of serious targeted attack activity:

  • Windows Kernel, win32k.sys (MS15-061)
  • Internet Explorer – critical
  • Windows Media Player – critical
  • Microsoft Common Controls
  • Microsoft Office
  • Active Directory Federation Services
  • Exchange Server

Two are rated Critical (MS15-056 for Internet Explorer and MS15-057 for Windows Media Player) because of their remote code execution severity. The Internet Explorer bulletin alone fixes over 20 memory corruption vulnerabilities in the IE codebase.

Most interesting of all the bulletins this month turns out to be MS15-061, patching eight different software flaws in the kernel. In particular, cve-2015-2360 was a difficult find, and this 0day was reported by our own talented colleague Maxim Golovkin. This issue presented itself within win32k.sys, which fails to properly free memory after use. It might be rated “Important” as an escalation of privilege vulnerability, but defending against its deployment as a part of targeted attack activity is most certainly critical.

Please update your Windows systems asap.

Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/microsoft-security-updates-june-2015/70531/