Microsoft Patch Tuesday fixes three flaws actively exploited in attacks in the wild
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-0093 | A remote code execution vulnerability in Microsoft Edge exists in the way that the Scripting Engine renders when handling objects in memory in Microsoft browser A remote code execution vulnerability in Microsoft Edge exists in the way that the Scripting Engine renders when handling objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0201. NVD description · AI analysis pending | 7.5 | 14% |
| — | ||
| CVE-2017-0180 | A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an authenticated A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is unique from CVE-2017-0162, CVE-2017-0163, and CVE-2017-0181. NVD description · AI analysis pending | 7.6 | 3% |
| — | ||
| CVE-2017-0199 | Remote Code Execution in Microsoft Office and WordPad via crafted document files CVE-2017-0199 is a remote code execution vulnerability in Microsoft Office and WordPad that stems from improper parsing of specially crafted files. Attackers trigger it by getting a user to open a malicious document, after which attacker-controlled code executes with the privileges of the logged-in user. Anyone running the affected Microsoft Office or WordPad software is exposed, and CISA notes the flaw has been leveraged in ransomware campaigns; no CVSS score is available in the source data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and EPSS assigns a 99.9% probability of exploitation within 30 days (100th percentile), indicating active, ongoing exploitation. Do: Apply Microsoft's security updates for Office and Windows per vendor instructions, as required by CISA's KEV catalog; the flaw was publicly reported as fixed in Microsoft's April 2017 security updates. Until patched, treat unsolicited Office documents and email attachments as high-risk, since exploitation requires a user to open a crafted file. Verify that all Office and WordPad installations across the estate—especially endpoints that handle untrusted documents—have received the update. | 7.8 | 100% | KEV ransomware PoC ×6 |
| masshundreds of millions of Office installations worldwide (exact count unknown) | |
| CVE-2017-0210 +1 in the same advisory: …0201 | Cross-Domain Privilege Escalation in Microsoft Internet Explorer CVE-2017-0210 is a privilege elevation flaw caused by Internet Explorer failing to properly enforce cross-domain policies, breaking the isolation between security zones/domains in the browser. It is triggered when a user views malicious or attacker-controlled web content in Internet Explorer, allowing content from one domain to reach resources that should be restricted to another domain or zone. Successful exploitation lets an attacker access information across those boundaries and gain elevated privileges within the browser context, which is commonly chained with other flaws for fuller compromise. Any user running affected versions of Internet Explorer on Windows is affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-24), indicating known exploitation in the wild, with a 22.3% EPSS probability of exploitation in the next 30 days (98th percentile). Do: Apply Microsoft security updates per vendor instructions (the latest cumulative Internet Explorer security updates on all supported Windows versions still in use), since CISA's required action is to apply updates. Audit your environment for systems still launching IE or embedded WebBrowser/IE-based content, restrict or retire IE usage, and migrate users to a supported modern browser (e.g., Edge, using IE mode only for legacy intranet apps) to reduce exposure. | 8.8 group max | 22% | KEV |
| masstens of millions of Windows endpoints (IE shipped with all Windows versions in use during the affected period and remains present on large numbers of… | |
| CVE-2017-2605 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-1000362. Reason: This candidate is a duplicate of CVE-2017-1000362. A vendor reference identifier was mistakenly treated as a CVE ID. Notes: All CVE users should reference CVE-2017-1000362 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage NVD description · AI analysis pending | — | — | — | — |
Full article517 words · extracted from securityaffairs.com · click to collapse

Today Microsoft Patch Tuesday fixed the zero-day Word vulnerability that has been actively exploited in attacks in the wild.
Microsoft today patched the zero-day Word vulnerability that has been exploited in attacks in the wild. Just yesterday I wrote about a phishing campaign leveraging the flaw to deliver the Dridex banking Trojan.
Microsoft published security patches that addressed a total of 45 CVEs in nine products, including Internet Explorer, Microsoft Edge and Windows 10. Most of the updates address problems in Microsoft IE and Edge browsers.
The company confirmed that three of the vulnerabilities among this Tuesday updates are under active attack in the wild.
The first vulnerability actively exploited by attackers is tracked as CVE-2017-0199, it allowed attackers to use a specially-crafted document embedding an OLE2link object to spread malware such as the Dridex banking Trojan.
“While labelled as an Outlook issue, this is actually bug actually stems from an issue within RTF files. According to published reports, the exploit uses an embedded OLE2link object in a specially-crafted document. It should also be noted that these attacks can be thwarted by enabling Office’s Protective View feature. There are updates for both Office and Windows to be applied, and both should be considered necessary for complete protection.” reads the Patch Tuesday analysis by the Zero Day Initiative.
The second flaw exploited in the wild is an Internet Explorer elevation of privilege vulnerability tracked as CVE-2017-0210. The flaw could be exploited by attackers to access information from one domain and inject it into another domain.
“The exploit allows an attacker to access sensitive information from one domain and inject it into another domain, which could allow the attacker to gain elevated privileges. However, direct code execution is not possible through this bug alone. Instead, it would likely be used with a bug that executes code at a low integrity level to elevate the code execution to medium level integrity.” continues ZDI.
Microsoft published an the 2017-2605*: “Defense-in-Depth Update for Microsoft Office”, to address a flaw tracked as CVE-2017-2605. It is a Microsoft Office bug in the Encapsulated PostScript (EPS) filter in Office.
“According to Microsoft, they are aware of “limited targeted attacks” that take advantage of an unpatched vulnerability in the EPS filter. This temporary measure is being pushed out until a true fix is released. Issues like this used to be covered by Security Advisories, so perhaps this indicates Microsoft has chosen to do away with these as well.” states the analysis.
Microsoft did not issue an update to address this flaw, it opted to update Microsoft Office turning off, by default, the EPS filter in Office as a defense-in-depth measure.

Microsoft also issued a fix for Windows 10 (Creators Update) that addresses several remote code execution and elevation of privilege flaws.
Giving a look at the list of the vulnerabilities fixed by this last Microsoft Patch Tuesday we can find:
- CVE-2017-0201 IE RCE vulnerability ;
- CVE-2017-0093 Edge scripting engine memory corruption vulnerability;
- CVE-2017-0162, CVE-2017-0163, CVE-2017-0180 Hyper-V vulnerabilities;
[adrotate banner=”9″]
(Security Affairs – Mirai Botnet, Bitcoin)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/57947/hacking/microsoft-patch-tuesday.html