ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

January 2020 Patch Tuesday: Microsoft nukes Windows crypto flaw flagged by the NSA

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-0601
ECC Certificate Spoofing in Microsoft Windows CryptoAPI (Crypt32.dll)

CVE-2020-0601 (known as 'Curveball') is a spoofing flaw in Crypt32.dll, the Windows CryptoAPI component that validates Elliptic Curve Cryptography (ECC) certificates, which mishandles ECC certificate parameters when checking signatures. An attacker can trigger it by signing malicious content, most notably an executable, with a spoofed, attacker-controlled ECC certificate that Windows accepts as if it were issued by a trusted certificate authority; the attack vector is network-based but requires user interaction (CVSS 3.1: 8.1, AV:N/AC:L/PR:N/UI:R). Successful exploitation makes attacker-supplied malware appear to come from a legitimate, trusted software vendor, defeating code-signing trust prompts and signature-based trust decisions, with high impact on confidentiality and integrity. Affected systems are the Microsoft Windows 10 builds 1507 through 1909 and Windows Server versions 1803, 1903, 1909, 2016 and 2019 in the CISA data, with Go also listed as an affected vendor via its ECC certificate validation, effectively covering the mainstream Windows install base at the time. The flaw was discovered by the NSA and patched in the January 2020 Patch Tuesday; it is now CISA KEV-listed (added 2021-11-03, ransomware use unknown) with very high predicted exploitation risk (EPSS 89.4%, 100th percentile), and no public PoC is tracked in this data.

Do: Apply Microsoft's January 2020 Patch Tuesday cumulative security updates for all affected Windows 10 and Windows Server builds, per CISA's required action (apply updates per vendor instructions). Prioritize user workstations and servers that validate signed binaries, Authenticode signatures, or TLS certificates, since exploitation hinges on a user or application trusting a spoofed ECC-signed artifact. If Go is deployed in your environment, update Go toolchains to a patched January 2020 or later release, as Go was also acknowledged as an affected vendor.

8.189% KEV
  • microsoft Windows 10 1507, 1607, 1709, 1803, 1809, 1903, 1909 (all supported editions/service configurations of these builds)
  • microsoft Windows Server 1803, 1903, 1909, 2016, 2019
  • golang Go (ECC certificate validation code)
massover 1 billion Windows devices (essentially the entire Windows 10 install base on builds 1507-1909, plus Windows Server 2016/2019 deployments)
CVE-2020-0609
+1 in the same advisory: …0610
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using

A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0610.

NVD description · AI analysis pending
9.875%
  • microsoft windows server 2012
  • microsoft windows server 2016
  • microsoft windows server 2019
CVE-2020-0620
An elevation of privilege vulnerability exists when Microsoft Cryptographic Services improperly handles files, aka 'Microsoft Cryptographic Services Elevation o

An elevation of privilege vulnerability exists when Microsoft Cryptographic Services improperly handles files, aka 'Microsoft Cryptographic Services Elevation of Privilege Vulnerability'.

NVD description · AI analysis pending
7.8<1%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
Full article771 words · extracted from helpnetsecurity.com · click to collapse

As forecasted, January 2020 Patch Tuesday releases by Microsoft and Adobe are pretty light: the “star of the show” is CVE-2020-0601, a Windows flaw flagged by the NSA that could allow attackers to successfully spoof code-signing certificates and use them to sign malicious code or intercept and modify encrypted communications.

January 2020 Patch Tuesday

Microsoft’s patches

Microsoft has released security patches for a variety of its products, including Windows, Internet Explorer, Office and Office Services and Web Apps, ASP.NET, .NET Core, .NET Framework, OneDrive for Android, and Microsoft Dynamics.

The company fixed 49 CVE-numbered vulnerabilities, eight of which are deemed critical, but none of which are currently under attack (as far as they know).

As mentioned before, CVE-2020-0601 will grab the most attention. Not only because it could have a wide-reaching impact, but also because it was reported by the NSA (as opposed to kept secret and quietly exploited).

“For the U.S. government to share its discovery of a critical vulnerability with a vendor is exceptionally rare if not unprecedented. It underscores the criticality of the vulnerability and we urge all organizations to prioritize patching their systems quickly,” said Amit Yoran, CEO of Tenable and the Founding Director of the DHS’s US-CERT program.

“The fact that Microsoft provided a fix in advance to the U.S. government and other customers that provide critical infrastructure is also highly unusual. These are clearly noteworthy shifts from regular practices and make this vulnerability worth paying attention to and also worth asking questions about. How long ago was the vulnerability discovered? How long did it take from discovery to reporting? Was it used by the NSA? Has it been observed being used by foreign intelligence services already? What triggered the vendor disclosure? None of these questions change what organizations need to do at this point to protect themselves, but their answers might tell us a lot more about the environment we operate in.”

SANS ISC’s Johannes Ullrich has described a number of scenarios for the bug’s exploitation.

The flaw only affects newer versions of Windows and Windows Server, and is found in the Windows CryptoAPI (Crypt32.dll), which validates Elliptic Curve Cryptography (ECC) certificates. The security update fixes it and creates a new entry in the Windows event logs if an attacker attempts to use a forged certificate against a patched system.

“This is significant and will help admins determine if they have been targeted,” noted Trend Micro’s Zero Day Initiative’s Dustin Childs.

It goes without saying that admins should prioritize this security update for Windows 10, Windows Server 2016 and 2019.

Other vulnerabilities of note in this batch of security updates are CVE-2020-0609 and CVE-2020-0610, two remote code execution bugs in RDP Gateway Servers that require no user interaction to be exploited. An unauthenticated remote attacker could simply send a specially-crafted request to a vulnerable RDP server and achieve the ability to execute arbitrary code with SYSTEM privileges.

Oh, and don’t forget to update your Microsoft OneDrive App for Android if you use it, to prevent attackers from bypassing the passcode or fingerprint requirements of the app by sharing a link with you.

Animesh Jain, Product Manager of Vulnerability Signatures at Qualys, also advises admins to prioritize Scripting Engine, Browser, and .NET Framework patches for workstation-type devices (including multi-user servers that are used as remote desktops for users).

Users who still use Windows 7, Windows Server 2008 R2, and Windows Server 2008 are reminded once more that support for those ends today and that the patches for them released today, covering 22 CVEs, are the last they’ll get for free.

A standout among these CVEs is CVE-2020-0620, a vulnerability that exists when Microsoft Cryptographic Services improperly handles a file, giving an attacker the opportunity to modify a protected file.

“While this exploitation would require an attacker having access and ability to execute on the machine, there are no shortage of weaponized but patchable exploits out in the wild that can provide that kind of access,” noted Richard Melick, Senior Technical Product Manager, Automox.

“And while the end of support happened today, this one simple vulnerability should be a reminder that today is the day to ensure all legacy endpoints are up to date and the security protocols and procedures surrounding these devices are centered on restricting access, securing third-party software, and minimizing the overall attack surface.”

Adobe patches

This month Adobe shipped fixes for only nine flaws.

Five, all critical, affect Adobe  Illustrator CC  for Windows and could allow attackers to achieve remote code execution on the underlying system.

The remaining four affect Adobe Experience Manager 6.5 and below. These could “only” result in sensitive information disclosure.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2020/01/14/january-2020-patch-tuesday/