Microsoft Issues Software Updates for 17 Critical Vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-8475 | A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files, aka "Windows Remote Code Execution Vulnerabili A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files, aka "Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. NVD description · AI analysis pending | 8.8 group max | 16% |
| — | ||
| CVE-2018-15967 | Adobe Flash Player versions 30.0.0.154 and earlier have a privilege escalation vulnerability. Adobe Flash Player versions 30.0.0.154 and earlier have a privilege escalation vulnerability. Successful exploitation could lead to information disclosure. NVD description · AI analysis pending | 7.5 | 7% |
| — | ||
| CVE-2018-8440 | Local Privilege Escalation in Windows ALPC Handling (Win 7–10, Server 2008–2016) An elevation-of-privilege vulnerability exists in the way Windows handles calls to the Advanced Local Procedure Call (ALPC) facility, rated 7.8 High with a local attack vector and only low privileges required. An attacker who can already run code on a machine as a low-privileged user can send crafted ALPC messages that the OS mishandles, elevating their privileges to SYSTEM/administrator without any user interaction. Successful exploitation yields full local control (high impact on confidentiality, integrity and availability) and is typically used to consolidate a foothold or escape low-privilege contexts, including in ransomware chains. Affected systems are Windows 7, 8.1, RT 8.1, Windows 10 (1607, 1703, 1709, 1803), Windows 10 Servers, and Windows Server 2008 through 2016 — essentially every Windows client and server platform in support at disclosure. The flaw was publicly demonstrated via a published proof of concept in August 2018, fixed in Microsoft's September 2018 security updates, and is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-28 with known ransomware use, and EPSS puts 30-day exploitation probability at 18.4% (97th percentile). Do: Apply the September 2018 (or later) Microsoft cumulative/monthly rollup updates across all affected Windows client and server systems, prioritizing servers and domain-joined hosts given known ransomware use and the CISA KEV listing. Legacy machines that no longer receive updates (e.g., Windows 7, Server 2008/2008 R2, 2012/2012 R2) should be upgraded to a supported OS or covered by Extended Security Updates. Verify remediation by confirming the September 2018 patch level is present on each host, since OS version alone does not indicate exposure. | 7.8 | 18% | KEV ransomware PoC |
| mass≈1 billion+ Windows installations were in affected versions at the 2018 disclosure; the residual unpatched estate today is likely in the millions of legacy… | |
| CVE-2018-8457 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corru A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 11, Microsoft Edge, Internet Explorer 10. This CVE ID is unique from CVE-2018-8354, CVE-2018-8391, CVE-2018-8456, CVE-2018-8459. NVD description · AI analysis pending | 7.5 | 13% |
| — |
Full article633 words · extracted from thehackernews.com · click to collapse
Swati KhandelwalSep 11, 2018
Times to gear up your systems and software.
Just a few minutes ago Microsoft released its latest monthly Patch Tuesday update for September 2018, patching a total of 61 security vulnerabilities, 17 of which are rated as critical, 43 are rated Important, and one Moderate in severity.
This month's security updates patch vulnerabilities in Microsoft Windows, Edge, Internet Explorer, MS Office, ChakraCore, .NET Framework, Microsoft.Data.OData, ASP.NET, and more.
Four of the security vulnerabilities patched by the tech giant this month have been listed as "publicly known" and more likely exploited in the wild at the time of release.
CVE-2018-8475: Windows Critical RCE Vulnerability
One of the four publicly disclosed vulnerabilities is a critical remote code execution flaw (CVE-2018-8475) in Microsoft Windows and affects all versions Windows operating system, including Windows 10.
The Windows RCE vulnerability resides in the way Windows handles specially crafted image files. To execute malicious code on a target system, all a remote attacker needs to do is just convince a victim to view an image.
Given its severity and easiness of exploitation, you can expect an exploit targeting Windows users in coming days.
CVE-2018-8440: Windows ALPC Elevation of Privilege Vulnerability
The latest patch update also addresses an "important" zero-day vulnerability in Windows Advanced Local Procedure Call (ALPC) that was publicly disclosed last week on Twitter.
If exploited, the flaw (CVE-2018-8440) could allow a local attacker or malicious program to gain and run code with administrative system privileges on the targeted machines.
According to Microsoft, the flaw is actively being exploited in the wild and requires immediate attention. The proof-of-concept (PoC) exploit for this privilege escalation flaw in Windows is available on Github.
CVE-2018-8457: Scripting Engine Memory Corruption Vulnerability
Another publicly disclosed flaw is a remote code execution vulnerability (CVE-2018-8457) in the scripting engine, which exists when the scripting engine fails to properly handle objects in memory in Microsoft browsers, allowing an unauthenticated, remote attacker to execute arbitrary code on a targeted system in the context of the currently logged-in user.
"If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system," Microsoft explains.
"An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights."
The vulnerability affects Microsoft Edge, Internet Explorer 11 and Internet Explorer 10.
Two Windows Hyper-V Remote Code Execution Vulnerabilities
This month patch update also includes patches for two critical remote code execution vulnerabilities in Windows Hyper-V, a native hypervisor for running virtual machines on Windows servers.
Both the flaws (CVE-2018-0965 and CVE-2018-8439) exist when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system.
Both RCE vulnerabilities can be exploited by a malicious guest user by running a specially crafted application on the virtual operating system to eventually execute arbitrary code on the host operating system.
Patch All Microsoft Software Vulnerabilities
Besides this, Microsoft has also pushed security updates to patch a critical remote code execution vulnerability in Adobe Flash Player, details of which you can get through a separate article posted today.
Adobe has labeled the same privilege escalation vulnerability (CVE-2018-15967) as important, while Microsoft marked it as a critical remote code execution flaw.
Users are strongly advised to apply all security patches as soon as possible to keep hackers and cybercriminals away from taking control of their computers.
For installing security updates, directly head on to Settings → Update & security → Windows Update → Check for updates, or you can install the updates manually.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2018/09/microsoft-software-updates.html