ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-0952
An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations, aka "Diagnostic Hub Standard

An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations, aka "Diagnostic Hub Standard Collector Elevation Of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Microsoft Visual Studio, Windows 10 Servers.

NVD description · AI analysis pending
7.86% PoC
  • microsoft visual studio 2015
  • microsoft visual studio 2017
  • microsoft windows 10
  • +1 more
CVE-2018-8349
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows

A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

NVD description · AI analysis pending
8.8
group max
23%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2018-8384
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engi

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-8266, CVE-2018-8380, CVE-2018-8381.

NVD description · AI analysis pending
7.562%
  • microsoft chakracore
CVE-2018-8273
A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Server Remot

A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Server Remote Code Execution Vulnerability." This affects Microsoft SQL Server.

NVD description · AI analysis pending
9.829%
  • microsoft sql server
CVE-2018-8302
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchang

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server.

NVD description · AI analysis pending
9.826%
  • microsoft exchange server
CVE-2018-8357
An elevation of privilege vulnerability exists in Microsoft browsers allowing sandbox escape, aka "Microsoft Browser Elevation of Privilege Vulnerability." This

An elevation of privilege vulnerability exists in Microsoft browsers allowing sandbox escape, aka "Microsoft Browser Elevation of Privilege Vulnerability." This affects Internet Explorer 11, Microsoft Edge.

NVD description · AI analysis pending
8.3
group max
8%
  • microsoft internet explorer
  • microsoft edge
CVE-2018-8340
A security feature bypass vulnerability exists when Active Directory Federation Services (AD FS) improperly handles multi-factor authentication requests, aka "A

A security feature bypass vulnerability exists when Active Directory Federation Services (AD FS) improperly handles multi-factor authentication requests, aka "AD FS Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows Server 2012 R2, Windows 10 Servers.

NVD description · AI analysis pending
6.58%
  • microsoft windows server 2012
  • microsoft windows server 2016
CVE-2018-8397
+3 in the same advisory: …8346 …8342 …8396
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka "GDI+ Remote Code Ex

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka "GDI+ Remote Code Execution Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.

NVD description · AI analysis pending
8.8
group max
68%
  • microsoft windows 7
  • microsoft windows server 2008
CVE-2018-8377
+4 in the same advisory: …8387 …8383 …8358 …8370
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." Th

A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8387.

NVD description · AI analysis pending
7.5
group max
10%
  • microsoft edge
CVE-2018-8360
An information disclosure vulnerability exists in Microsoft .NET Framework that could allow an attacker to access information in multi-tenant environments, aka

An information disclosure vulnerability exists in Microsoft .NET Framework that could allow an attacker to access information in multi-tenant environments, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 2.0, Microsoft .NET Framework 4.6/4.6.1/4.6.2.

NVD description · AI analysis pending
7.59%
  • microsoft .net framework
CVE-2018-8373
Memory Corruption RCE in Microsoft Internet Explorer Scripting Engine

CVE-2018-8373 is an out-of-bounds write (CWE-787) in the Microsoft scripting engine's handling of objects in memory, which can corrupt memory and enable remote code execution in Internet Explorer 9, 10, and 11. It is triggered when a user is lured to an attacker-crafted web page or script in IE, with no privileges required but user interaction and relatively high attack complexity per the CVSS vector (AV:N/AC:H/UI:R). A successful attacker gains arbitrary code execution in the context of the current user, compromising that workstation's data and credentials. Any Windows system whose users browse with Internet Explorer 9, 10, or 11 was affected, and Microsoft fixed the flaw in its August 2018 Patch Tuesday release. The flaw was exploited as a zero-day in the wild at the time of patching — press coverage describes an in-the-wild VBScript zero-day blocked by endpoint protection — and it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25; EPSS places the 30-day exploitation probability at 61.9% (99th percentile).

Do: Apply Microsoft's August 2018 security updates for Internet Explorer on all supported Windows versions — the required action listed in the CISA KEV — and verify patch deployment via WSUS/SCCM/Intune across end-user workstations and RDS/browsing hosts. As interim mitigation, consider Microsoft's documented workaround of disabling VBScript execution in IE via feature-control keys and steer users away from IE for web browsing. Finally, migrate any remaining IE9/10/11 usage to Microsoft Edge (using IE mode for legacy sites), since IE11 is retired and this flaw is confirmed exploited in the wild.

7.562% KEV
  • microsoft Internet Explorer (Scripting Engine) Internet Explorer 9, Internet Explorer 10, Internet Explorer 11
masshundreds of millions of Windows devices (IE9–11 shipped with Windows; IE11 present by default on Windows 7/8.1/10)
CVE-2018-8379
+2 in the same advisory: …8375 …8382
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remo

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Excel. This CVE ID is unique from CVE-2018-8375.

NVD description · AI analysis pending
7.8
group max
17%
  • microsoft excel
  • microsoft excel 2013 rt
CVE-2018-8376
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft Power

A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft PowerPoint.

NVD description · AI analysis pending
8.818%
  • microsoft powerpoint
CVE-2018-8378
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose t

An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka "Microsoft Office Information Disclosure Vulnerability." This affects Word, Microsoft SharePoint Server, Microsoft Office Word Viewer, Microsoft Excel Viewer, Microsoft SharePoint, Microsoft Office.

NVD description · AI analysis pending
5.58%
  • microsoft excel viewer
  • microsoft office
  • microsoft office compatibility pack
  • +1 more
Full article1,199 words · extracted from blog.talosintelligence.com · click to collapse

Tuesday, August 14, 2018 14:26

Microsoft released its monthly set of security advisories today for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 62 new vulnerabilities, 20 of which are rated “critical,” 38 that are rated “important,” one that is rated moderate and one that is rated as low severity. These vulnerabilities impact Windows Operating System, Edge and Internet Explorer, along with several other products.

In addition to the 60 vulnerabilities referenced above, Microsoft has also released a critical update advisory, ADV180020 which addresses the vulnerabilities described in the Adobe Flash Security Bulletin APSB18-25.

Critical Vulnerabilities

This month, Microsoft is addressing 20 vulnerabilities that are rated "critical." Talos believes 10 of these are notable and require prompt attention.

CVE-2018-8273 is a remote code execution vulnerability in the Microsoft SQL Server that could allow an attacker who successfully exploits the vulnerability to execute code in the context of the SQL Server Database Engine Service account.

CVE-2018-8302is a remote code execution vulnerability in the Microsoft Exchange email and calendar software that could allow an attacker who successfully exploits the vulnerability to run arbitrary code in the context of the system user when the software fails to properly handle objects in memory.

CVE-2018-8344 is a remote code execution vulnerability that exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take control of the affected system. This vulnerability can be exploited in multiple ways. By leveraging a web-based attack, an attacker can convince a user to visit a web page that has been specially crafted to exploit this vulnerability. This could be in the form of an attacker-controlled webpage, or simply a page that hosts external content, such as advertisements. An attacker can also provide a specially crafted document that is designed to exploit the vulnerability, and then convince users to open the document file.

CVE-2018-8350 is a remote code execution vulnerability that exists when the Microsoft Windows PDF Library improperly handles objects in memory. An attacker who successfully exploits the vulnerability could gain the same user rights as the current user. The vulnerability can be exploited simply by viewing a website that hosts a malicious PDF file on a Windows 10 system with Microsoft Edge set as the default browser. On other affected systems, that do not render PDF content automatically, an attacker would have to convince users to open a specially crafted PDF document, such as a PDF attachment to an email message.

CVE-2018-8266, CVE-2018-8355, CVE-2018-8380,CVE-2018-8381 and CVE-2018-8384 are remote code execution vulnerabilities that exist in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge. An attacker who successfully exploits the vulnerability can potentially gain the same user rights as the current user. This vulnerability could be leveraged in web-based attacks where a user is convinced to visit a web page that has been specially crafted to exploit this vulnerability. This could be in the form of an attacker-controlled webpage, or simply a page that hosts external content, such as advertisements.

CVE-2018-8397 is a remote code execution vulnerability that exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploits this vulnerability could take control of the affected system. This vulnerability can be exploited in multiple ways. By leveraging a web-based attack, an attacker can convince a user to visit a webpage that has been specially crafted to exploit this vulnerability. This could be in the form of an attacker-controlled webpage, or simply a page that hosts external content, such as advertisements. An attacker can also provide a specially crafted document file that is designed to exploit the vulnerability, and then convince users to open the document file.

Other vulnerabilities deemed "critical" are listed below:

CVE-2018-8345    LNK Remote Code Execution Vulnerability

CVE-2018-8359    Scripting Engine Memory Corruption Vulnerability

CVE-2018-8371    Scripting Engine Memory Corruption Vulnerability

CVE-2018-8372    Scripting Engine Memory Corruption Vulnerability

CVE-2018-8373    Scripting Engine Memory Corruption Vulnerability

CVE-2018-8377    Microsoft Edge Memory Corruption Vulnerability

CVE-2018-8385    Scripting Engine Memory Corruption Vulnerability

CVE-2018-8387    Microsoft Edge Memory Corruption Vulnerability

CVE-2018-8390    Scripting Engine Memory Corruption Vulnerability

CVE-2018-8403    Microsoft Browser Memory Corruption Vulnerability

Important Vulnerabilities

This month, Microsoft is addressing 38 vulnerabilities that are rated "important." Talos believes two of these are notable and require prompt attention.

CVE-2018-8200 is a vulnerability that exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session. An attacker who successfully exploits this vulnerability can potentially inject code into a trusted PowerShell process to bypass the Device Guard code integrity policy on the local machine. To exploit the vulnerability, an attacker would first have to access the local machine and then inject malicious code into a script that is trusted by the policy. The injected code would then run with the same trust level as the script and bypass the policy.

CVE-2018-8340 is a vulnerability in the Windows Authentication Methods, and enables an Active Directory Federation Services (AD FS)Security Bypass vulnerability. An attacker who successfully exploits this vulnerability could bypass some, but not all, of the authentication factors.

Other vulnerabilities deemed "important" are listed below:

CVE-2018-0952    Diagnostic Hub Standard Collector Elevation Of Privilege Vulnerability

CVE-2018-8204    Device Guard Code Integrity Policy Security Feature Bypass Vulnerability

CVE-2018-8253    Cortana Elevation of Privilege Vulnerability

CVE-2018-8316    Internet Explorer Remote Code Execution Vulnerability

CVE-2018-8339    Windows Installer Elevation of Privilege Vulnerability

CVE-2018-8341    Windows Kernel Information Disclosure Vulnerability

CVE-2018-8342    Windows NDIS Elevation of Privilege Vulnerability

CVE-2018-8343    Windows NDIS Elevation of Privilege Vulnerability

CVE-2018-8346    LNK Remote Code Execution Vulnerability

CVE-2018-8347    Windows Kernel Elevation of Privilege Vulnerability

CVE-2018-8348    Windows Kernel Information Disclosure Vulnerability

CVE-2018-8349    Microsoft COM for Windows Remote Code Execution Vulnerability

CVE-2018-8351    Microsoft Edge Information Disclosure Vulnerability

CVE-2018-8353    Scripting Engine Memory Corruption Vulnerability

CVE-2018-8357    Microsoft Browser Elevation of Privilege Vulnerability

CVE-2018-8358    Microsoft Browser Security Feature Bypass Vulnerability

CVE-2018-8360    .NET Framework Information Disclosure Vulnerability

CVE-2018-8370    Microsoft Edge Information Disclosure Vulnerability

CVE-2018-8375    Microsoft Excel Remote Code Execution Vulnerability

CVE-2018-8376    Microsoft PowerPoint Remote Code Execution Vulnerability

CVE-2018-8378    Microsoft Office Information Disclosure Vulnerability

CVE-2018-8379    Microsoft Excel Remote Code Execution Vulnerability

CVE-2018-8382    Microsoft Excel Information Disclosure Vulnerability

CVE-2018-8383    Microsoft Edge Spoofing Vulnerability

CVE-2018-8389    Scripting Engine Memory Corruption Vulnerability

CVE-2018-8394    Windows GDI Information Disclosure Vulnerability

CVE-2018-8396    Windows GDI Information Disclosure Vulnerability

CVE-2018-8398    Windows GDI Information Disclosure Vulnerability

CVE-2018-8399    Win32k Elevation of Privilege Vulnerability

CVE-2018-8400    DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2018-8401    DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2018-8404    Win32k Elevation of Privilege Vulnerability

CVE-2018-8405    DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2018-8406    DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2018-8412    Microsoft (MAU) Office Elevation of Privilege Vulnerability

CVE-2018-8414    Windows Shell Remote Code Execution Vulnerability

Coverage

In response to these vulnerability disclosures, Talos is releasing the following Snort rules that detect attempts to exploit them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Firepower customers should use the latest update to their ruleset by updating their SRU. Open Source Snort Subscriber Rule Set customers can stay up-to-date by downloading the latest rule pack available for purchase on Snort.org.

Snort Rules:

45877-45878, 46548-46549, 46999-47002, 47474-47493, 47495-47496, 47503-47504, 47512-47513, 47515-47520

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/ms-tuesday-63063210e63ef5e7e1ec3139/