February 2019 Patch Tuesday: PrivExchange hole plugged
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-0594 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsof A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0604. NVD description · AI analysis pending | 8.8 | 12% |
| — | ||
| CVE-2019-0604 | RCE in Microsoft SharePoint via Application Package Markup Validation Flaw Microsoft SharePoint fails to check the source markup of an application package, an improper input validation flaw (CWE-20) that allows maliciously crafted markup to be processed by the server. An attacker triggers the flaw by getting an affected SharePoint server to handle a crafted application package, without any special privileges described in the disclosure. Successful exploitation lets the attacker run remote code in the context of the SharePoint application pool and the SharePoint server farm account, providing control of the web server and access to a highly privileged farm-level identity. Any organization running an affected on-premises Microsoft SharePoint deployment is exposed, with internet-facing SharePoint servers at greatest risk. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use and EPSS puts the probability of exploitation at 99.9%, although no public proof-of-concept is catalogued. Do: Apply Microsoft's SharePoint security updates per vendor instructions immediately, prioritizing internet-exposed SharePoint servers as CISA's required action directs. Given known in-the-wild and ransomware use, hunt for signs of compromise such as unexpected .aspx or webshell files in SharePoint directories and anomalous use of the SharePoint farm account. Restrict or firewall internet exposure of SharePoint servers until patches are confirmed applied. | 9.8 | 100% | KEV ransomware |
| mass≈ hundreds of thousands of on-prem SharePoint server deployments worldwide, of which tens of thousands are directly internet-facing (estimate) | |
| CVE-2019-0626 +1 in the same advisory: …0636 | A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server, aka 'Windows DHCP A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'. NVD description · AI analysis pending | 9.8 group max | 69% |
| — | ||
| CVE-2019-0676 | Information Disclosure in Microsoft Internet Explorer via Improper Memory Handling CVE-2019-0676 is an information disclosure vulnerability in Microsoft Internet Explorer caused by improper handling of objects in memory. It is exploited remotely via attacker-crafted content, most likely a malicious web page or link, that the victim must open in Internet Explorer, as reflected by the user-interaction requirement in the CVSS vector. A successful attacker can probe the victim's system and test for the presence of specific files on disk, which is useful for reconnaissance and tailoring follow-on attacks; there is no integrity or availability impact. Affected systems are those running Microsoft Internet Explorer, per CISA and Microsoft data. The flaw is listed in the CISA KEV catalog (added 2022-05-23), confirming known exploitation in the wild, with an EPSS 30-day exploitation probability of 7.5% (94th percentile), and remediation is via Microsoft security updates. Do: Apply Microsoft security updates for Internet Explorer/Windows per vendor instructions, as required by the CISA KEV listing, and verify patch status across internet-exposed and user workstations. Because exploitation requires user interaction, caution users against opening untrusted links in IE, and consider disabling or removing Internet Explorer where it is no longer needed. Monitor for KEV-driven remediation deadlines and check environments for evidence of the file-existence probing behavior. | 6.5 | 8% | KEV |
| masshundreds of millions of Windows devices (Internet Explorer ships bundled with Windows) | |
| CVE-2019-0724 +1 in the same advisory: …0686 | An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0686. NVD description · AI analysis pending | 8.1 group max | 24% |
| — | ||
| CVE-2019-7090 | Flash Player Desktop Runtime versions 32.0.0.114 and earlier, Flash Player for Google Chrome versions 32.0.0.114 and earlier, and Flash Player for Microsoft Edg Flash Player Desktop Runtime versions 32.0.0.114 and earlier, Flash Player for Google Chrome versions 32.0.0.114 and earlier, and Flash Player for Microsoft Edge and Internet Explorer 11 versions 32.0.0.114 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. NVD description · AI analysis pending | 6.5 | 5% |
| — |
Full article458 words · extracted from helpnetsecurity.com · click to collapse
For the February 2019 Patch Tuesday, Microsoft has released fixes for over 70 CVE-numbered vulnerabilities, 20 of which are rated Critical.

Also rated Critical are the Adobe Flash security update (ADV190003, which carries a fix for CVE-2019-7090, an information disclosure flaw in Adobe Flash Player), and the latest servicing stack updates (ADV990001).
Previously disclosed and exploited vulnerabilities
“Two vulnerabilities were publicly disclosed previous to today’s releases,” notes Greg Wiseman, senior security researcher for Rapid7.
“CVE-2019-0686, an elevation of privilege vulnerability in Exchange Server that has now properly been patched. Microsoft had outlined a mitigation in their ADV190007 advisory last week, but is now encouraging administrators to apply the patch and remove the previous workaround. The other, CVE-2019-0636, is an information disclosure vulnerability in Windows that could allow a logged in user to view the contents of files on disk without authorization.”
CVE-2019-0686, the so-called PrivExchange bug, for which proof-of-concept code is available online since last month.
“If exploited, the vulnerability would give an attacker Domain Administrator privileges that would allow them to access domain user credentials. PrivExchange is also addressed by CVE-2019-0724. Given the severity and publicity of the vulnerability, organizations should patch immediately,” says Satnam Narang, senior research engineer at Tenable.
CVE-2019-0676, an Internet Explorer information disclosure vulnerability that could allow an attacker to check disks for the presence of certain files, was spotted being exploited in the wild. To exploit it an attacker would have to convince the victim to visit a malicious website.
Other flaws of prime concern
Eleven of the critical holes plugged are memory corruption vulnerabilities in the Scripting Engine.
This update, along with those for the Edge and Internet Explorer browsers and the Graphics Device Interface (GDI+) should be prioritized for workstation-type devices, says Jimmy Graham, Senior Director of Product Management at Qualys.
CVE-2019-0626, an RCE in Windows DHCP Server, and CVE-2019-0594 and CVE-2019-0604, two critical SharePoint flaws, can also lead to trouble.
The former allows attackers to take over DHCP servers by sending them a specially crafted packet.
“Code execution through a network service that executes with high privileges definitely put this in the wormable category, although it would only be wormable to other DHCP servers. While the Exploit Index (XI) rating for this is lower, there’s no reason to pass on installing this patch once you’ve tested it,” says Trend Micro Zero Day Initiative’s Dustin Childs.
The SharePoint flaws could be exploited by uploading a specially crafted SharePoint application package to execute code in the context of the SharePoint application pool and the SharePoint server farm account.
“While the malicious user would need special rights to perform this action, this patch should be treated as high priority for any SharePoint servers,” Qualys’ Jimmy Graham advises.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2019/02/13/february-2019-patch-tuesday/