ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Microsoft Patches Windows Zero

criticalVulnerability exploited in the wildimportance 60CVE-2016-7255

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-7255
Win32k Local Privilege Escalation in Windows Vista Through Windows 10 and Server 2016

CVE-2016-7255 is an elevation-of-privilege flaw in the Windows kernel-mode drivers (win32k), affecting Windows Vista SP2 through Windows 10 1607 and the corresponding Windows Server releases. A local attacker who can run a crafted application can leverage the bug — public exploits target the win32k NtSetWindowLongPtr code path — to execute code with elevated kernel privileges. Successful exploitation yields SYSTEM-level privileges, typically used to escape a restricted context or to chain with a separate code-execution bug for full system compromise, including ransomware deployment. Anyone running the affected Windows versions is exposed; the flaw was a zero-day actively exploited at the time of its November 2016 disclosure, with reporting tying use to the Sofacy/'Pawn Storm' APT and Google warning of active exploitation. It was added to CISA KEV on 2021-11-03 with known ransomware use, and EPSS currently puts the 30-day exploitation probability at 81%, so defenders should treat it as actively targeted.

Do: Apply Microsoft's security update for CVE-2016-7255 (issued in the November 2016 Patch Tuesday cycle, bulletin MS16-135); on Windows 10 1507/1511/1607 this arrives via the corresponding monthly cumulative update. Prioritize patching internet-reachable servers and any system where unprivileged users can run code, since the flaw is used in the wild for post-exploitation privilege escalation (including ransomware chains per CISA KEV). After patching, hunt for suspicious local-to-SYSTEM activity around the disclosure window on legacy Windows Vista/2008/7/2012 estate that may still be running unpatched builds.

7.881% KEV ransomware PoC ×5
  • microsoft Windows Vista SP2
  • microsoft Windows Server 2008 SP2 and R2 SP1
  • microsoft Windows 7 SP1
  • +5 more
masshundreds of millions of Windows PCs and servers (the listed versions dominated the global installed base at disclosure)
Full article332 words · extracted from thehackernews.com · click to collapse

The Hacker NewsNov 09, 2016

Microsoft was very upset with Google last week when its Threat Analysis Group publically disclosed a critical Windows kernel vulnerability (CVE-2016-7255) that had yet to be patched.

The company criticized Google's move, claiming that the disclosure of the vulnerability, which was being exploited in the wild, put its customers "at potential risk."

The vulnerability affects all Windows versions from Windows Vista through current versions of Windows 10, and Microsoft was set to issue a fix come this month's Patch Tuesday.

So, as part of its monthly Patch Tuesday, Microsoft today patched the security flaw in Windows that was actively being exploited by hackers.

According to Microsoft's security bulletin released today, any hacker who tricked victims into running a "specially-crafted application" could successfully exploit the system bug and gain the ability to "install programs; view, change, or delete data; or create new accounts with full user rights."

Once exploited, the bug could be used to escape the sandbox protection and execute malicious code on the compromised Windows machine.

Rated as "important," the vulnerability was being exploited by Strontium group, also known as Fancy Bear, Sofacy, and APT 28, in targeted attacks.

Fancy Bear is the same group of hackers that has also been accused by the US Intelligence community of hacking the Democratic National Committee, Clinton Campaign Chair John Podesta, and former Secretary of State Colin Powell, among others.

Besides this controversial flaw exposed by Google last week, the security bulletin also fixes multiple elevation of privilege bugs.

Patch Tuesday also contains several critical security patches that affect all versions of Windows as well as other important updates and fixes for both Internet Explorer and Edge.

So, I strongly recommend home users and companies to ensure that their Windows PC is up-to-date with all of Microsoft's latest security fixes as of today.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2016/11/microsoft-windows-update.html