ZeroHour
Cisco Talospublished ()ingested Tiago Pereira1

Microsoft discloses more than 130 vulnerabilities as part of July’s Patch Tuesday, four exploited in the wild

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-35312
+1 in the same advisory: …21526
Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability

Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability

NVD description · AI analysis pending
7.8
group max
<1%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2023-32049
+2 in the same advisory: …36874 …32046
Windows SmartScreen Security Feature Bypass Exploited in the Wild (CVE-2023-32049)

CVE-2023-32049 is a security feature bypass in Microsoft Windows Defender SmartScreen, the mechanism that warns users before they run downloaded or untrusted content; specially crafted content delivered over the network causes SmartScreen to skip that warning when a user opens it. The flaw requires user interaction (CVSS vector AV:N/AC:L/UI:R), so attackers must lure a victim into clicking or opening the crafted URL or file, and in exchange they gain the ability to run content without the expected SmartScreen prompt, typically as a link in a chain that delivers malware or establishes initial access. All users of Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2), and Windows Server 2016/2019/2022 are affected. The flaw was fixed in Microsoft's July 2023 Patch Tuesday batch (132 vulnerabilities, six under active attack) and was added to CISA's Known Exploited Vulnerabilities catalog on 2023-07-11, confirming in-the-wild exploitation; no public proof-of-concept is known and ransomware use is unknown.

Do: Apply Microsoft's July 2023 (or later) cumulative Windows security updates on every affected Windows 10, Windows 11, and Windows Server release, per the vendor instructions and CISA KEV required action. After patching, verify SmartScreen and Mark-of-the-Web warning behavior remain enabled and intact, and prioritize fleet-wide rollout given confirmed in-the-wild exploitation; treat unpatched users as susceptible to warning-free delivery of malicious files and links.

8.8
group max
4% KEV
  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 21H2, 22H2
  • Microsoft Windows Server 2016, 2019, 2022
masshundreds of millions of endpoints and servers (the affected Windows 10/11 and Server releases make up the large majority of the supported Windows installed…
CVE-2023-33157
+1 in the same advisory: …33134
Microsoft SharePoint Remote Code Execution Vulnerability

Microsoft SharePoint Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.838%
  • microsoft sharepoint server
CVE-2023-35311
TOCTOU Security Feature Bypass in Microsoft Outlook (Exploited in the Wild)

CVE-2023-35311 is a time-of-check to time-of-use (TOCTOU) race condition (CWE-367) in Microsoft Outlook that allows a security feature to be bypassed. It is triggered remotely over the network when a user interacts with a specially crafted email; per Microsoft's advisory, the attacker needs to know the target's mailbox email address. Successful exploitation defeats Outlook's security check (scored high for confidentiality and integrity impact), lowering the barrier for follow-on actions such as malware delivery via email content. The flaw affects Outlook as delivered with Microsoft 365 Apps, Office, and Office LTSC. It is confirmed exploited in the wild (added to CISA KEV on 2023-07-11) and was fixed in Microsoft's July 2023 Patch Tuesday; no public proof-of-concept is known.

Do: Apply the July 2023 Patch Tuesday security updates (released July 11, 2023) for Outlook, Office, Microsoft 365 Apps, and Office LTSC as soon as possible, since the flaw is being exploited in the wild and is on CISA's KEV list (U.S. civilian agency deadline August 1, 2023). After patching, verify Outlook and Office build numbers reflect the July 2023 updates, and review mailboxes for suspicious emails that users interacted with around the security prompt. Ransomware use is unknown, so treat any unpatched internet-active mail clients as priority targets in patch cycles.

8.816% KEV
  • Microsoft Outlook Builds prior to the July 11, 2023 Patch Tuesday security updates
  • Microsoft 365 Apps Builds prior to the July 11, 2023 Patch Tuesday security updates
  • Microsoft Office Builds prior to the July 11, 2023 Patch Tuesday security updates
  • +1 more
masshundreds of millions of Outlook users worldwide
CVE-2023-35352
Windows Remote Desktop Security Feature Bypass Vulnerability

Windows Remote Desktop Security Feature Bypass Vulnerability

NVD description · AI analysis pending
7.51%
  • microsoft windows server 2012
  • microsoft windows server 2016
  • microsoft windows server 2019
  • +1 more
Full article612 words · extracted from blog.talosintelligence.com · click to collapse

Tuesday, July 11, 2023 15:26

Microsoft released its monthly security update Tuesday, disclosing the most vulnerabilities as part of Patch Tuesday in more than a year.

The company released details of more than 130 vulnerabilities, the most in a month since April 2022, 10 of which are considered to be critical. The remaining vulnerabilities are “important.”

Microsoft also included an advisory in today’s Patch Tuesday that provides guidance to mitigate Microsoft-signed drivers that attackers are using maliciously in the wild. Talos recently discovered an attack that focuses on drivers certified by Microsoft’s Windows Hardware Developer Program (MWHDP) being used maliciously in post-exploitation activity. Microsoft had been previously notified of this type of activity in February 2023, and Talos researchers recently reported additional details.

Four of the disclosed vulnerabilities — albeit “important” ones — have been detected being exploited in the wild: CVE-2023-32046, CVE-2023-32049, CVE-2023-35311 and CVE-2023-36874.

CVE-2023-32046 is an elevation of privilege in the Windows MSHTML platform. Although there are not many specific details available, according to Microsoft, it would allow an attacker to gain the same access rights as the user that is running the application, if they can trick the victim into downloading and opening a specially crafted file.

CVE-2023-32049 is a security feature bypass vulnerability in the Windows SmartScreen Security Feature. An attacker could exploit this vulnerability to avoid the SmartScreen “Open File Security Warning” prompt by tricking the user into clicking on a specially crafted URL.

Another security bypass vulnerability, CVE-2023-35311, exists in Microsoft Outlook. In this case, a specially crafted URL could allow an attacker to evade the “Microsoft Outlook Security Notice” prompt that normally appears.

Lastly, CVE-2023-36874 is a local privilege escalation vulnerability that allows an attacker access to the local file system and the ability to create folders and performance traces to obtain administrative privileges.

July's security update features 10 critical vulnerabilities, up from last month’s five. Eight of these allow remote code execution, one allows elevation of privilege and one allows security feature bypass. Microsoft considers seven of them “less likely” to occur and two of them “more likely” to occur. None of the critical vulnerabilities have been detected as being exploited in the wild. The two critical vulnerabilities more likely to occur are:

  • CVE-2023-35352: An attacker could exploit this vulnerability in Windows Remote Desktop to bypass certificate or private key authentication when establishing a remote desktop protocol session.
  • CVE-2023-33157: An attacker authenticated to SharePoint with Manage List permissions could execute code remotely on the SharePoint server.

Talos would also like to highlight three important vulnerabilities that Microsoft considers to be “more likely” to be exploited:

  • CVE-2023-21526: Windows Netlogon information disclosure vulnerability
  • CVE-2023-33134: Microsoft SharePoint Server remote code execution vulnerability
  • CVE-2023-35312: Microsoft VOLSNAP.SYS elevation of privilege vulnerability

A complete list of all the vulnerabilities Microsoft disclosed this month is available on its update page.

In response to these vulnerability disclosures, Talos is releasing a new Snort rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Cisco Secure Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.

The rules included in this release that protect against the exploitation of many of these vulnerabilities are 62010 - 62012, 62022 - 62027, 62034 and 62035. This release also includes Snort 3 rules 300607, 300612, 300613 that can detect some of the vulnerabilities mentioned in this blog post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-july-2023/