ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-8256
A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka "Microsoft PowerShell Remote Code Execution Vulnera

A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka "Microsoft PowerShell Remote Code Execution Vulnerability." This affects Windows RT 8.1, PowerShell Core 6.0, Microsoft.PowerShell.Archive 1.2.2.0, Windows Server 2016, Windows Server 2012, Windows Server 2008 R2, Windows Server 2019, Windows 7, Windows Server 2012 R2, PowerShell Core 6.1, Windows 10 Servers, Windows 10, Windows 8.1.

NVD description · AI analysis pending
8.823%
  • microsoft microsoft.powershell.archive
  • microsoft powershell core
  • microsoft windows 10
  • +1 more
CVE-2018-8544
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution V

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

NVD description · AI analysis pending
8.8
group max
48% PoC
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2018-8476
A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory, aka "Windows Deployment Services

A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory, aka "Windows Deployment Services TFTP Server Remote Code Execution Vulnerability." This affects Windows Server 2012 R2, Windows Server 2008, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows Server 2008 R2, Windows 10 Servers.

NVD description · AI analysis pending
9.865%
  • microsoft windows server 2008
  • microsoft windows server 2012
  • microsoft windows server 2016
  • +1 more
CVE-2018-8522
A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Cod

A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. This CVE ID is unique from CVE-2018-8524, CVE-2018-8576, CVE-2018-8582.

NVD description · AI analysis pending
7.8
group max
19%
  • microsoft office
  • microsoft office 365 proplus
  • microsoft outlook
  • +1 more
CVE-2018-8541
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engi

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8542, CVE-2018-8543, CVE-2018-8551, CVE-2018-8555, CVE-2018-8556, CVE-2018-8557, CVE-2018-8588.

NVD description · AI analysis pending
7.514%
  • microsoft chakracore
  • microsoft edge
CVE-2018-8567
+1 in the same advisory: …8545
An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access info

An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge.

NVD description · AI analysis pending
5.4
group max
3%
  • microsoft edge
CVE-2018-8552
An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which could provide an attacker with information t

An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Windows Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.

NVD description · AI analysis pending
7.551% PoC
  • microsoft internet explorer
CVE-2018-8563
An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Information Disclosure Vulnerability." This affec

An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2008 R2.

NVD description · AI analysis pending
5.52%
  • microsoft windows 7
  • microsoft windows 8.1
  • microsoft windows rt 8.1
  • +1 more
CVE-2018-8568
+2 in the same advisory: …8572 …8578
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected ShareP

An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8572.

NVD description · AI analysis pending
5.4
group max
2%
  • microsoft sharepoint enterprise server
  • microsoft sharepoint foundation
  • microsoft sharepoint server
CVE-2018-8575
A remote code execution vulnerability exists in Microsoft Project software when it fails to properly handle objects in memory, aka "Microsoft Project Remote Cod

A remote code execution vulnerability exists in Microsoft Project software when it fails to properly handle objects in memory, aka "Microsoft Project Remote Code Execution Vulnerability." This affects Microsoft Project, Office 365 ProPlus, Microsoft Project Server.

NVD description · AI analysis pending
7.820%
  • microsoft office 365 proplus
  • microsoft project
CVE-2018-8581
Privilege Escalation (Arbitrary User Impersonation) in Microsoft Exchange Server

CVE-2018-8581 is a privilege escalation vulnerability in Microsoft Exchange Server that, when successfully exploited, allows an attacker to impersonate any other user of the Exchange server. Impersonating an arbitrary user lets the attacker act as that user — reading their mailbox, sending messages as them, and, if the impersonated account is privileged or administrative, gaining elevated access to the messaging environment. Organizations running on-premises Microsoft Exchange Server are affected; the provided data does not specify the affected version ranges, so operators should consult Microsoft's CVE-2018-8581 advisory for the exact builds covered. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-03 with known ransomware use, confirming in-the-wild exploitation, and EPSS assigns a 27.4% probability of exploitation in the next 30 days (98th percentile). No public proof-of-concept is known, but the KEV listing and ransomware linkage make patching exposed Exchange servers urgent.

Do: Apply Microsoft's Exchange security updates per vendor instructions, as required by the CISA KEV listing, and confirm the patched build for your Exchange version in Microsoft's CVE-2018-8581 advisory since affected version ranges are not enumerated in this data. Because ransomware operators are known to exploit this flaw, prioritize internet-facing Exchange servers and hunt for signs of compromise — unexpected user impersonation, anomalous mailbox access, and post-exploitation activity — before and after patching.

7.427% KEV ransomware
  • Microsoft Exchange Server
mass≈ hundreds of thousands of on-premises Exchange deployments (millions of mailbox users)
CVE-2018-8589
Local Privilege Escalation in Microsoft Windows Win32k (Windows 7 / Server 2008)

CVE-2018-8589 is an elevation of privilege vulnerability in Win32k.sys, the Windows kernel-mode component that handles system calls, affecting Windows 7, Windows Server 2008, and Windows Server 2008 R2. It is triggered when Windows improperly handles calls to Win32k.sys, allowing a local attacker who is already able to execute low-privileged code (for example, via a malicious application or as a second stage of a browser exploit) to escalate privileges. A successful exploit grants the attacker elevated (kernel/SYSTEM-level) privileges on the local machine, typically enabling full control and often chained with code-execution bugs. Windows 7 and Windows Server 2008/2008 R2 users and administrators are affected; the flaw was patched in Microsoft's November 2018 security updates. The vulnerability was known to be actively exploited in the wild at the time of the November 2018 Patch Tuesday, and it is listed in CISA's Known Exploited Vulnerabilities catalog (added May 23, 2022), with EPSS at roughly 3% (87th percentile).

Do: Apply the Microsoft November 2018 security updates (or later) to all Windows 7, Windows Server 2008, and Windows Server 2008 R2 systems, per the CISA KEV required action. Because Windows 7 and Server 2008 are past end of support, verify patch status on legacy/extended-support (ESU) systems, inventory any remaining unpatched hosts, and prioritize upgrading them; until patched, limit execution of untrusted local code and keep kernel exploit mitigations enabled.

7.83% KEV
  • microsoft Windows 7
  • microsoft Windows Server 2008
  • microsoft Windows Server 2008 R2
masshundreds of millions of Windows 7 devices worldwide at disclosure, plus widespread Windows Server 2008/2008 R2 deployments
CVE-2018-8600
A Cross-site Scripting (XSS) vulnerability exists when Azure App Services on Azure Stack does not properly sanitize user provided input, aka "Azure App Service

A Cross-site Scripting (XSS) vulnerability exists when Azure App Services on Azure Stack does not properly sanitize user provided input, aka "Azure App Service Cross-site Scripting Vulnerability." This affects Azure App.

NVD description · AI analysis pending
6.12%
  • microsoft azure app service on azure stack
CVE-2018-8602
A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka "Team Foundation Server Cross-

A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka "Team Foundation Server Cross-site Scripting Vulnerability." This affects Team.

NVD description · AI analysis pending
5.42%
  • microsoft team foundation server
CVE-2018-8609
+4 in the same advisory: …8606 …8607 …8608 …8605
A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) version 8 when the server fails to properly sanitize web requests to an aff

A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) version 8 when the server fails to properly sanitize web requests to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Remote Code Execution Vulnerability." This affects Microsoft Dynamics 365.

NVD description · AI analysis pending
8.8
group max
10%
  • microsoft dynamics 365
Full article1,231 words · extracted from thehackernews.com · click to collapse

Swati KhandelwalNov 14, 2018

It's Patch Tuesday once again…time for another round of security updates for the Windows operating system and other Microsoft products.

This month Windows users and system administrators need to immediately take care of a total of 63 security vulnerabilities, of which 12 are rated critical, 49 important and one moderate and one low in severity.

Two of the vulnerabilities patched by the tech giant this month are listed as publicly known at the time of release, and one flaw is reported as being actively exploited in the wild by multiple cybercriminal groups.

Zero-Day Vulnerability Being Exploited by Cyber Criminals

The zero-day vulnerability, tracked as CVE-2018-8589, which is being exploited in the wild by multiple advanced persistent threat groups was first spotted and reported by security researchers from Kaspersky Labs.

The flaw resides in the Win32k component (win32k.sys), which if exploited successfully, could allow a malicious program to execute arbitrary code in kernel mode and elevate its privileges on an affected Windows 7, Server 2008 or Server 2008 R2 to take control of it.

"The exploit was executed by the first stage of a malware installer in order to gain the necessary privileges for persistence on the victim's system. So far, we have detected a very limited number of attacks using this vulnerability," Kaspersky said.

Two Publicly Disclosed Zero-Day Vulnerabilities

The other two publicly known zero-day vulnerabilities which were not listed as under active attack reside in Windows Advanced Local Procedure Call (ALPC) service and Microsoft's BitLocker Security Feature.

The flaw related to ALPC, tracked as CVE-2018-8584, is a privilege escalation vulnerability that could be exploited by running a specially crafted application to execute arbitrary code in the security context of the local system and take control over an affected system.

Advanced local procedure call (ALPC) facilitates high-speed and secure data transfer between one or more processes in the user mode.

The second publicly disclosed vulnerability, tracked as CVE-2018-8566, exists when Windows improperly suspends BitLocker Device Encryption, which could allow an attacker with physical access to a powered-off system to bypass security and gain access to encrypted data.

BitLocker was in headlines earlier this month for a separate issue that could expose Windows users encrypted data due to its default encryption preference and bad encryption on self-encrypting SSDs.

Microsoft did not fully address this issue; instead, the company simply provided a guide on how to manually change BitLocker default encryption choice.

November 2018 Patch Tuesday: Critical and Important Flaws

Out of 12 critical, eight are memory corruption vulnerabilities in the Chakra scripting engine that resides due to the way the scripting engine handles objects in memory in the Microsoft Edge internet browser.

All the 8 vulnerabilities could be exploited to corrupt memory, allowing an attacker to execute code in the context of the current user. To exploit these bugs, all an attacker needs to do is tricking victims into opening a specially crafted website on Microsoft Edge.

Rest three vulnerabilities are remote code execution bugs in the Windows Deployment Services TFTP server, Microsoft Graphics Components, and the VBScript engine. All these flaws reside due to the way the affected software handles objects in memory.

The last critical vulnerability is also a remote code execution flaw that lies in Microsoft Dynamics 365 (on-premises) version 8. The flaw exists when the server fails to properly sanitize web requests to an affected Dynamics server.

If exploited successfully, the vulnerability could allow an authenticated attacker to run arbitrary code in the context of the SQL service account by sending a specially crafted request to a vulnerable Dynamics server.

Windows Deployment Services TFTP Server Remote Code Execution VulnerabilityCVE-2018-8476Critical
Microsoft Graphics Components Remote Code Execution VulnerabilityCVE-2018-8553Critical
Chakra Scripting Engine Memory Corruption VulnerabilityCVE-2018-8588Critical
Chakra Scripting Engine Memory Corruption VulnerabilityCVE-2018-8541Critical
Chakra Scripting Engine Memory Corruption VulnerabilityCVE-2018-8542Critical
Chakra Scripting Engine Memory Corruption VulnerabilityCVE-2018-8543Critical
Windows VBScript Engine Remote Code Execution VulnerabilityCVE-2018-8544Critical
Chakra Scripting Engine Memory Corruption VulnerabilityCVE-2018-8555Critical
Chakra Scripting Engine Memory Corruption VulnerabilityCVE-2018-8556Critical
Chakra Scripting Engine Memory Corruption VulnerabilityCVE-2018-8557Critical
Chakra Scripting Engine Memory Corruption VulnerabilityCVE-2018-8551Critical
Microsoft Dynamics 365 (on-premises) version 8 Remote Code Execution VulnerabilityCVE-2018-8609Critical
Azure App Service Cross-site Scripting VulnerabilityCVE-2018-8600Important
Windows Win32k Elevation of Privilege VulnerabilityCVE-2018-8589Important
BitLocker Security Feature Bypass VulnerabilityCVE-2018-8566Important
Windows ALPC Elevation of Privilege VulnerabilityCVE-2018-8584Important
Team Foundation Server Cross-site Scripting VulnerabilityCVE-2018-8602Important
Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting VulnerabilityCVE-2018-8605Important
Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting VulnerabilityCVE-2018-8606Important
Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting VulnerabilityCVE-2018-8607Important
Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting VulnerabilityCVE-2018-8608Important
Microsoft RemoteFX Virtual GPU miniport driver Elevation of Privilege VulnerabilityCVE-2018-8471Important
DirectX Elevation of Privilege VulnerabilityCVE-2018-8485Important
DirectX Elevation of Privilege VulnerabilityCVE-2018-8554Important
DirectX Elevation of Privilege VulnerabilityCVE-2018-8561Important
Win32k Elevation of Privilege VulnerabilityCVE-2018-8562Important
Microsoft SharePoint Elevation of Privilege VulnerabilityCVE-2018-8572Important
Microsoft Exchange Server Elevation of Privilege VulnerabilityCVE-2018-8581Important
Windows COM Elevation of Privilege VulnerabilityCVE-2018-8550Important
Windows VBScript Engine Remote Code Execution VulnerabilityCVE-2018-8552Important
Microsoft SharePoint Elevation of Privilege VulnerabilityCVE-2018-8568Important
Windows Elevation Of Privilege VulnerabilityCVE-2018-8592Important
Microsoft Edge Elevation of Privilege VulnerabilityCVE-2018-8567Important
DirectX Information Disclosure VulnerabilityCVE-2018-8563Important
MSRPC Information Disclosure VulnerabilityCVE-2018-8407Important
Windows Audio Service Information Disclosure VulnerabilityCVE-2018-8454Important
Win32k Information Disclosure VulnerabilityCVE-2018-8565Important
Microsoft Outlook Information Disclosure VulnerabilityCVE-2018-8558Important
Windows Kernel Information Disclosure VulnerabilityCVE-2018-8408Important
Microsoft Edge Information Disclosure VulnerabilityCVE-2018-8545Important
Microsoft SharePoint Information Disclosure VulnerabilityCVE-2018-8578Important
Microsoft Outlook Information Disclosure VulnerabilityCVE-2018-8579Important
PowerShell Remote Code Execution VulnerabilityCVE-2018-8256Important
Microsoft Outlook Remote Code Execution VulnerabilityCVE-2018-8522Important
Microsoft Outlook Remote Code Execution VulnerabilityCVE-2018-8576Important
Microsoft Outlook Remote Code Execution VulnerabilityCVE-2018-8524Important
Microsoft Word Remote Code Execution VulnerabilityCVE-2018-8539Important
Microsoft Word Remote Code Execution VulnerabilityCVE-2018-8573Important
Microsoft Excel Remote Code Execution VulnerabilityCVE-2018-8574Important
Microsoft Project Remote Code Execution VulnerabilityCVE-2018-8575Important
Microsoft Outlook Remote Code Execution VulnerabilityCVE-2018-8582Important
Windows Search Remote Code Execution VulnerabilityCVE-2018-8450Important
Microsoft Excel Remote Code Execution VulnerabilityCVE-2018-8577Important
Internet Explorer Memory Corruption VulnerabilityCVE-2018-8570Important
Microsoft JScript Security Feature Bypass VulnerabilityCVE-2018-8417Important
Windows Security Feature Bypass VulnerabilityCVE-2018-8549Important
Microsoft Edge Spoofing VulnerabilityCVE-2018-8564Important
Active Directory Federation Services XSS VulnerabilityCVE-2018-8547Important
Team Foundation Server Remote Code Execution VulnerabilityCVE-2018-8529Important
Yammer Desktop Application Remote Code Execution VulnerabilityCVE-2018-8569Important
Microsoft Powershell Tampering VulnerabilityCVE-2018-8415Important
.NET Core Tampering VulnerabilityCVE-2018-8416Moderate
Microsoft Skype for Business Denial of Service VulnerabilityCVE-2018-8546Low

This month's security update also covers 46 important vulnerabilities in Windows, PowerShell, MS Excel, Outlook, SharePoint, VBScript Engine, Edge, Windows Search service, Internet Explorer, Azure App Service, Team Foundation Server, and Microsoft Dynamics 365.

Users and system administrators are strongly advised to apply the above security patches as soon as possible in order to keep hackers and cyber criminals away from taking control of their systems.

For installing security patch updates, head on to Settings → Update & security → Windows Update → Check for updates, or you can install the updates manually.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2018/11/microsoft-patch-tuesday-updates.html