ZeroHour
Cisco Talospublished ()ingested

Microsoft Update Tuesday: April 2014, two final XP and Office 2003 fixes

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2014-1761
Memory Corruption RCE in Microsoft Word

CVE-2014-1761 is a memory corruption vulnerability (CWE-119) in Microsoft Word that can be triggered by processing a maliciously crafted document, such as one delivered as an email attachment. Successful exploitation corrupts memory in a way that allows an attacker to execute arbitrary code on the victim's system with the privileges of the current user. Anyone running an affected Microsoft Word installation is exposed, which in practice spans a very large share of business and consumer desktops given Word's ubiquity. The flaw is confirmed as exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-02-15, and EPSS assigns it a 77.5% probability of exploitation in the next 30 days (100th percentile). No public proof-of-concept is known, but the KEV listing and high EPSS indicate real-world attacker activity, and Word document flaws of this kind have historically featured in targeted APT and spear-phishing campaigns.

Do: Apply Microsoft's security update for CVE-2014-1761 to every Word installation per vendor instructions, treating it as an actively exploited, high-priority patch. Until patched, be alert for unsolicited Word documents arriving by email, and consider file-blocking policies for documents from untrusted sources. Check that legacy Word editions within your estate are covered, since older builds that no longer receive routine updates are the most likely to remain exposed.

77% KEV
  • Microsoft Word
masshundreds of millions of Word installations worldwide (Word is the dominant word processor across enterprise desktops)
Full article289 words · extracted from blog.talosintelligence.com · click to collapse

Tuesday, April 8, 2014 13:06

It’s the last Microsoft Update Tuesday before the end-of-life of both Windows XP and Office 2003 and Microsoft is patching two vulnerabilities that also impact XP and two that also impact Office 2003 this month. All-in-all it’s a relatively light month this time around with only four bulletins covering eleven CVEs.

The first bulletin this month, MS14-017, deals with Word and covers three CVEs. One fix is for a 0-day vulnerability, CVE-2014-1761, that Microsoft previously addressed in advisory 2953095 and a “Fix it” that disables support for RTF completely in Word. The vulnerability results from an incorrect “listoverridecount” value in an “overridetable” structure in the RTF file.This value is not properly checked by Word and setting it to an invalid value causes a type confusion bug, which can be exploited by an attacker to gain remote code execution. The vulnerabilities addressed in this bulletin also cover Word 2003.

The requisite Internet Explorer bulletin, MS14-018, only covers six CVEs this month. As usual most of the issues are the result of use-after-free vulnerabilities. This time, none of the vulnerabilities that are being patched were publicly known. Given that IE runs on XP as well, this is one of the two bulletins that covers XP.

MS14-019 fixes a vulnerability (CVE-2014-0315) in the way that Windows handles files that can result in remote code execution. This is the second bulletin that also covers XP.

The final bulletin this month is MS14-020 and deals with Publisher, where a maliciously crafted file can result in remote code execution due to an arbitrary pointer dereference (CVE-2014-1759). As with the Word bulletin, this one also covers 2003.

Rules SID 24974-24975, 30497-30502, 30508-30509 address these vulnerabilities.

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/micorosft-update-tuesday-april-2014-two/