ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-0222
+2 in the same advisory: …0226 …0064
Memory Corruption RCE in Microsoft Internet Explorer

CVE-2017-0222 is a remote code execution flaw in Microsoft Internet Explorer caused by improper access to objects in memory (CWE-119), which can corrupt memory in a way that allows arbitrary code execution. It is triggered remotely, typically when a user is persuaded to view attacker-controlled web content in Internet Explorer. A successful attack runs code in the context of the current user, so the attacker gains that user's privileges and potentially full control of the workstation if the user has elevated rights. Anyone running affected builds of Internet Explorer is exposed, which historically means the very large base of Windows desktops that shipped with IE. Exploitation is confirmed in the wild — CISA added the CVE to its KEV catalog on 2022-02-25 — while no public proof-of-concept is known and ransomware use is unknown; EPSS estimates a 29.6% chance of exploitation in the next 30 days (98th percentile).

Do: Apply the Microsoft cumulative security update for Internet Explorer that fixes this issue (released with the April 2017 Patch Tuesday, or any later cumulative IE update) on all Windows systems that still run IE, prioritizing legacy and internet-facing machines. Because CISA's KEV listing in February 2022 shows the flaw was still being exploited years after patching, audit Windows 7/8.1 and Windows Server estates for unpatched IE and migrate users to Microsoft Edge (with IE mode if needed). As interim mitigations, restrict or disable legacy IE, warn users about opening untrusted links, and verify current IE patch levels before patching.

8.8
group max
30% KEV
  • Microsoft Internet Explorer
masshundreds of millions of Windows endpoints (IE was bundled by default on Windows desktops of the era)
CVE-2017-0272
The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and

The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0277, CVE-2017-0278, and CVE-2017-0279.

NVD description · AI analysis pending
8.1
group max
17%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2017-0171
Windows DNS Server allows a denial of service vulnerability when Microsoft Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 Gold and R2, and Windows Serv

Windows DNS Server allows a denial of service vulnerability when Microsoft Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 Gold and R2, and Windows Server 2016 are configured to answer version queries, aka "Windows DNS Server Denial of Service Vulnerability".

NVD description · AI analysis pending
5.94%
  • microsoft windows server 2008
  • microsoft windows server 2012
  • microsoft windows server 2016
CVE-2017-0244
+4 in the same advisory: …0242 …0245 …0220 …0175
The kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows locally authenticated attackers to gain privileges via a crafted application, or in W

The kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows locally authenticated attackers to gain privileges via a crafted application, or in Windows 7 for x64-based systems, cause denial of service, aka "Windows Kernel Elevation of Privilege Vulnerability."

NVD description · AI analysis pending
6.7
group max
2%
  • microsoft windows 7
  • microsoft windows server 2008
CVE-2017-0213
Local Privilege Escalation in Microsoft Windows COM Aggregate Marshaler

CVE-2017-0213 is an elevation of privilege flaw in the Windows COM Aggregate Marshaler affecting Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 (1507/1511/1607/1703), and Windows Server 2008 SP2/R2 SP1 through Server 2016. It is triggered when a local, low-privileged user runs a specially crafted application that abuses COM aggregate marshaling; there is no remote or network attack vector, and user interaction is required. Successful exploitation lets the attacker execute code with elevated privileges (up to SYSTEM) on the local machine, typically as a step toward full host compromise, and CISA notes known ransomware use. All users of the listed Windows client and server versions are affected; the flaw was fixed in Microsoft's May 2017 Patch Tuesday. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-28, ransomware use known), a public PoC exists (Exploit-DB 42020), and EPSS assigns a top-percentile 84.1% probability of exploitation in the next 30 days.

Do: Apply Microsoft's May 2017 security update for this COM elevation-of-privilege flaw, or later monthly/cumulative rollups, on every affected Windows 7/8.1/RT 8.1/10 and Server 2008/2012/2016 system, prioritizing hosts where untrusted users can run applications (terminal/RDS servers, shared workstations, VDI). Inventory installed updates to confirm patching, and give legacy Windows 7/Server 2008/2012 estates special attention because this bug has documented ransomware-linked exploitation; if compromise is suspected, hunt for local privilege-escalation artifacts and follow the KEV required action of applying vendor updates.

7.384% KEV ransomware PoC
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8.1 as listed (no service-pack detail in source data)
  • Microsoft Windows RT 8.1 as listed (no version detail in source data)
  • +4 more
masshundreds of millions of Windows systems (Windows 7/8.1/10-era desktop and server installed base)
CVE-2017-0233
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Micro

An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-0241.

NVD description · AI analysis pending
8.3
group max
3%
  • microsoft edge
CVE-2017-0248
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a cert

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability."

NVD description · AI analysis pending
7.56%
  • microsoft .net framework
CVE-2017-0262
+3 in the same advisory: …0261 …0254 …0281
Memory Corruption RCE in Microsoft Office 2010, 2013, and 2016

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 fail to properly handle objects in memory, creating a remote code execution condition when the software processes a specially crafted file. Triggering the flaw requires user interaction - the CVSS vector (AV:L, UI:R) indicates an attacker must get a user to open a malicious document, typically via a phishing email or similar file-delivery channel. Successful exploitation runs arbitrary code in the context of the current user, exposing the confidentiality, integrity, and availability of everything that account can access on the endpoint (CVSS 3.1: 7.8, High). Any organization running the affected Office versions is affected; the flaw was one of several Office zero-days fixed in Microsoft's May 2017 Patch Tuesday (distinct from CVE-2017-0261 and CVE-2017-0281) and was reportedly exploited by Russian APT actors (APT28/Sofacy) around that time. Exploitation is confirmed: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-02-10, and EPSS currently rates the 30-day exploitation probability at 81% (100th percentile), so unpatched endpoints should be treated as actively targeted.

Do: Apply Microsoft's May 2017 security updates for Office 2010 SP2, Office 2013 SP1, and Office 2016, per the CISA KEV required action, and verify through asset inventory that no endpoint is running an unpatched Office build. Because exploitation requires user interaction with a crafted file, harden email and attachment handling (block or detonate Office files from untrusted sources) and brief users on unsolicited documents. Office 2010 and 2013 have since reached end of support, so migrate any remaining deployments to a currently supported Office release.

7.881% KEV
  • Microsoft Office 2010 Service Pack 2
  • Microsoft Office 2013 Service Pack 1
  • Microsoft Office 2016
masstens to hundreds of millions of endpoints (Office 2010 SP2/2013 SP1/2016 dominated desktop deployments at disclosure; current unpatched count unknown)
CVE-2017-0255
Microsoft SharePoint Foundation 2013 SP1 allows an elevation of privilege vulnerability when it does not properly sanitize a specially crafted web request, aka

Microsoft SharePoint Foundation 2013 SP1 allows an elevation of privilege vulnerability when it does not properly sanitize a specially crafted web request, aka "Microsoft SharePoint XSS Vulnerability".

NVD description · AI analysis pending
5.42%
  • microsoft sharepoint foundation
CVE-2017-0263
Win32k Use-After-Free Local Privilege Escalation in Windows 7 through Server 2016

CVE-2017-0263 is a use-after-free flaw (CWE-416) in the Windows kernel-mode drivers (Win32k) that allows a locally authenticated user to elevate privileges. It is triggered by running a specially crafted application that mishandles kernel memory on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 1507/1511/1607/1703, and Windows Server 2008 SP2/R2 SP1, Server 2012 Gold/R2, and Server 2016. Successful exploitation yields kernel-level privileges, effectively giving an attacker full control of the host and making it a common link in chained attacks alongside other bugs; related 2017 reporting associated the flaw with Sofacy (APT28) activity. Any unpatched Windows installation of the affected releases is affected, including long-lived legacy desktops and servers. The flaw is confirmed exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities Catalog (added 2022-02-10) — with two public PoC/exploit references and a ~10% EPSS probability of exploitation in the next 30 days (95th percentile).

Do: Apply Microsoft security updates per vendor instructions - this Win32k bug was fixed in the April 2017 Patch Tuesday release - prioritizing hosts where untrusted or low-privileged users can execute code (terminal/VDI servers, shared workstations, jump hosts). Windows 7/8.1 and Server 2008/2012 are past end of extended support, so use Extended Security Updates or migrate where patching in place is not possible. Verify installed builds against the affected version list above and close out the CISA KEV remediation requirement promptly.

7.810% KEV PoC ×2
  • microsoft windows 10 1507 (Gold), 1511, 1607, 1703
  • microsoft windows 7 SP1
  • microsoft windows 8.1 all versions at disclosure
  • +4 more
masshundreds of millions of devices (all unpatched Windows 7/8.1/RT 8.1 and Windows 10 1507-1703 PCs, plus the dominant Windows Server releases of that era)
CVE-2017-0265
+1 in the same advisory: …0264
Microsoft PowerPoint for Mac 2011 allows a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Microsoft Offi

Microsoft PowerPoint for Mac 2011 allows a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-0254 and CVE-2017-0264.

NVD description · AI analysis pending
7.819%
  • microsoft powerpoint for mac
CVE-2017-0290
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wi

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 does not properly scan a specially crafted file leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability."

NVD description · AI analysis pending
7.881% PoC ×2
  • microsoft forefront security
  • microsoft malware protection engine
  • microsoft windows defender
Full article1,398 words · extracted from blog.talosintelligence.com · click to collapse

Tuesday, May 9, 2017 20:28

Today, Microsoft has release their monthly set of security updates designed to address vulnerabilities. This month's release addresses 56 vulnerabilities with 15 of them rated critical and 41 rated important. Impacted products include .NET, DirectX, Edge, Internet Explorer, Office, Sharepoint, and Windows.

In addition to the coverage Talos is providing for the normal monthly Microsoft security advisories, Talos is also providing coverage for CVE-2017-0290, the MsMpEng Malware Protection service vulnerability in Windows reported by Natalie Silvanovich and Tavis Ormandy of Google Project Zero. Snort rule SIDs for this specific vulnerability are 42820-42821.

Vulnerabilities Rated Critical The following vulnerabilities are rated critical by Microsoft:

  • CVE-2017-0221
  • CVE-2017-0222
  • CVE-2017-0224
  • CVE-2017-0227
  • CVE-2017-0228
  • CVE-2017-0229
  • CVE-2017-0235
  • CVE-2017-0236
  • CVE-2017-0240
  • CVE-2017-0266
  • CVE-2017-0272
  • CVE-2017-0277
  • CVE-2017-0278
  • CVE-2017-0279
  • CVE-2017-0290
    These vulnerabilities are broken out by affected software below.

Adobe Flash Adobe has released a security update for Flash Player addressing memory corruption vulnerabilities that could result in remote code execution if exploited. Windows is impacted by these vulnerabilities as Flash Player is integrated into Internet Explorer and Edge in Windows 8 and 10. For further details, please refer to Adobe's Flash Player security bulletin here.

Internet Explorer/Edge Multiple memory corruption vulnerabilities have been identified in Internet Explorer, Edge, and the Scripting Engine component utilized by both browsers. These vulnerabilities manifest due to the way Internet Explorer, Edge, and Chakra (the scripting engine) handle objects in memory. Exploitation of these vulnerabilities could yield arbitrary code execution in the context of the current user's privileges if the user navigates to a specifically crafted web page.

CVEs: CVE-2017-0221, CVE-2017-0222, CVE-2017-0224, CVE-2017-0227, CVE-2017-0228, CVE-2017-0229, CVE-2017-0235, CVE-2017-0236, CVE-2017-0240, CVE-2017-0266

Windows SMB Multiple vulnerabilities have been identified in Microsoft Server Message Block (SMB) 1.0 that could allow an attacker to execute arbitrary code on the targeted host. Per Microsoft's advisories, an unauthenticated attacker could exploit these vulnerabilities via specifically crafted packets being transmitted to a vulnerable SMBv1 server.

CVEs: CVE-2017-0272, CVE-2017-0277, CVE-2017-0278, CVE-2017-0279

Microsoft Malware Protection Engine A vulnerability has been identified in the Microsoft Malware Protection Engine that could lead to arbitrary code execution in the context of the kernel. This vulnerability, CVE-2017-0290, manifests due to the Malware Protection engine improperly scanning specifically crafted files. Exploitation of this flaw is achievable by opening an email containing a malicious file, visiting a malicious website that exploits this vulnerability, or by downloading a maliciously crafted file.

Microsoft has released an engine update separate from a bulletin that addresses this issue. Users and administrators should note that no action is typically required for updates for the Malware Protection Engine as updates are normally applied within 48 hours of the release. For further details, please see Microsoft's security advisory.

Vulnerabilities Rated ImportantThe following vulnerabilities are rated important by Microsoft:

  • CVE-2017-0064
  • CVE-2017-0077
  • CVE-2017-0171
  • CVE-2017-0175
  • CVE-2017-0190
  • CVE-2017-0212
  • CVE-2017-0213
  • CVE-2017-0214
  • CVE-2017-0220
  • CVE-2017-0226
  • CVE-2017-0230
  • CVE-2017-0231
  • CVE-2017-0233
  • CVE-2017-0234
  • CVE-2017-0238
  • CVE-2017-0241
  • CVE-2017-0242
  • CVE-2017-0244
  • CVE-2017-0245
  • CVE-2017-0246
  • CVE-2017-0248
  • CVE-2017-0254
  • CVE-2017-0255
  • CVE-2017-0258
  • CVE-2017-0259
  • CVE-2017-0261
  • CVE-2017-0262
  • CVE-2017-0263
  • CVE-2017-0264
  • CVE-2017-0265
  • CVE-2017-0267
  • CVE-2017-0268
  • CVE-2017-0269
  • CVE-2017-0270
  • CVE-2017-0271
  • CVE-2017-0273
  • CVE-2017-0274
  • CVE-2017-0275
  • CVE-2017-0276
  • CVE-2017-0280
  • CVE-2017-0281
    These vulnerabilities are broken out by affected software below.

.NET A security feature bypass vulnerability has been identified and patched in the .NET Core and .NET Framework. CVE-2017-0248 manifests due to .NET core and .NET component failing to completely validate certificates. Exploitation of this flaw could occur where an attacker presents a certificate which is not valid for a specific use, but is still utilized for that purpose.

DirectX A privilege escalation vulnerability in the DirectX graphics kernel subsystem (dxgkrnl.sys) has been identified and patched. CVE-2017-0077 manifests due to the way objects in memory are incorrectly handled. Exploitation of the flaw is achievable if a user runs a specifically written application that exploits this flaw.

Microsoft Browser Multiple vulnerabilities have been identified and patched in Microsoft Internet Explorer and Edge. Two of the vulnerabilities (CVE-2017-0233, CVE-2017-0241) are privilege escalation vulnerabilities in Edge, one is a memory corruption flaw in IE (CVE-2017-0226), one is a security feature bypass in IE (CVE-2017-0064), one is a browser spoofing vulnerability (CVE-2017-0231), and one is a ActiveX information disclosure flaw (CVE-2017-0242).

Office Multiple arbitrary code execution vulnerabilities have been identified and patched in Microsoft Office for Mac and PC. These vulnerabilities manifest due to incorrectly handling objects in memory, resulting in memory corruption and arbitrary code execution in the context of the current privilege level. Exploitation of the these flaws achievable if a victim opens a specifically crafted Office document with a vulnerable version of Office on the host system. Attack vectors where this could be exploited included email-based attack where the user opens a malicious attachment from an attacker.

CVEs: CVE-2017-0254, CVE-2017-0261, CVE-2017-0262, CVE-2017-0264, CVE-2017-0265, CVE-2017-0281

Sharepoint A cross-site scripting (XSS) vulnerability has been identified and patched in Sharepoint Foundation 2013. CVE-2017-0255 manifests due to improperly sanitizing web requests to an affected server, potentially allowing an attacker to run scripts in the context of the current user. Exploiting the vulnerability could allow an attacker to read sensitive information or perform actions on behalf of the targeted user.

Win32k Three vulnerabilities have been identified and patched in the Win32k subsystem that could allow an attacker to gain elevated privileges or gain sensitive information regarding the system. Two of the vulnerabilities (CVE-2017-0246, CVE-2017-0263) are privilege escalation flaws while the third vulnerability (CVE-2017-0245) is an information disclosure vulnerability that could expose sensitive information about the system. All three vulnerabilities manifest due the kernel-mode driver failing to properly handle object in memory and could be exploited by executing a specifically written application.

Windows COM Two privilege escalation vulnerabilities (CVE-2017-0213 and CVE-2017-0214) in Windows Component Object Model (COM) have been identified and patched. CVE-2017-0213 manifests in the Windows COM Aggregate Marshaller due to how the COM Marshaller processes interface requests. CVE-2017-0214 manifests as a failure to properly validate input before loading libraries and could be exploited when loading type libraries.

Windows DNS A denial of service vulnerability (CVE-2017-0171) in Windows DNS Server has been identified and patched. CVE-2017-0171 manifests due to incorrectly handling DNS queries "if the server is configured to answer version queries." As a result, a remote attacker could exploit this vulnerability and cause the host to become unresponsive.

Windows GDI A information disclosure vulnerability in the Windows Graphics Device Interface (GDI) has been identified and patched that could allow an attacker to gain information about the targeted system. The vulnerability (CVE-2017-0190) itself does not permit an attacker to execute arbitrary code on the targeted system. However, exploiting this vulnerability in conjunction with another flaw could allow an attacker to execute arbitrary code.

Windows Hyper-V A privilege escalation vulnerability has been identified and patched in Windows Hyper-V. The vulnerability in question, CVE-2017-0212, is a flaw where the host server fails to properly handle vSMB packets.

Windows Kernel Five vulnerabilities have been identified and fixed in the Windows Kernel with four of them being information disclosure flaws and one of them being a privilege escalation vulnerability. All five vulnerabilities manifest due to the way object are incorrectly handled in memory.

A user who executes a specifically written application could exploit these vulnerabilities and gain information to further compromise the host (in the case of the information disclosure vulnerabilities), or gain elevated privileges that could be used to gain full control of the affected system. Note that for the privilege escalation vulnerability (CVE-2017-0244), x86-64 based systems will suffer from a denial of service instead of a privilege escalation.

CVEs: CVE-2017-0175, CVE-2017-0220, CVE-2017-0244, CVE-2017-0258, CVE-2017-0259

Windows SMB Multiple vulnerabilities have been identified in Microsoft Server Message Block (SMB) 1.0 that could result a denial of service or information leakage on affected hosts. These vulnerabilities manifest as a result of an affected host incorrectly processing SMBv1 requests.

CVEs: CVE-2017-0267, CVE-2017-0268, CVE-2017-0269, CVE-2017-0270, CVE-2017-0271, CVE-2017-0273, CVE-2017-0274, CVE-2017-0275, CVE-2017-0276, CVE-2017-0280

Coverage In response to these bulletin disclosures, Talos is releasing the following rules to address these vulnerabilities. Please note that additional rules may be released at a future date and current rules are subject to change pending additional vulnerability information. For the most current rule information, please refer to your Management Center or Snort.org.

Snort Rules:

  • 42749-42785
  • 42798-42799
  • 42811-42812
  • 42820-42821 (for CVE-2017-0290)

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/ms-tuesday-63063210e63ef5e7e1ec314c/