ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Microsoft Fixes Five Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-36025
+2 in the same advisory: …36036 …36033
Windows SmartScreen Bypass (CVE-2023-36025) Exploited via Crafted Shortcut Files

CVE-2023-36025 is a security feature bypass in Windows SmartScreen in which a specially crafted file — exploited in the wild using Internet Shortcut (.url) files — evades the Mark-of-the-Web warning SmartScreen normally displays for content downloaded from the internet. The flaw is network-reachable and requires no authentication, but user interaction is required: it triggers when a user clicks the crafted file delivered via phishing email, chat, or a web download. By bypassing the SmartScreen prompt, the attacker removes a key user-facing defense that would otherwise flag or warn about the file, which facilitated delivery of malware in the observed DarkGate and Mispadu campaigns. Any unpatched Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), or Windows Server 2008/2012/2016/2019 system is affected, which at the time of disclosure effectively meant the entire supported Windows installed base. It is confirmed exploited in the wild: CISA added it to the KEV catalog on 2023-11-14, EPSS scores 30-day exploitation probability at 88.1% (100th percentile), though no public PoC is known.

Do: Apply Microsoft's November 2023 cumulative Windows security updates (the release containing the fix) on all affected Windows 10/11 and Windows Server systems; no configuration-based workaround is widely documented, so patching is the primary mitigation. Until patched, treat unexpected Internet Shortcut (.url) files arriving via email or chat with extra suspicion, since they can execute without the usual SmartScreen warning, and hunt for DarkGate/Mispadu indicators. Given the KEV listing and 88.1% EPSS, prioritize this fix in the current patch cycle; ransomware-associated use is reported as unknown.

8.8
group max
88% KEV
  • microsoft Windows 10 1507 (builds prior to the November 2023 security updates)
  • microsoft Windows 10 1607 (builds prior to the November 2023 security updates)
  • microsoft Windows 10 1809 (builds prior to the November 2023 security updates)
  • +9 more
mass>1 billion endpoints (effectively the entire supported Windows 10/11/Server installed base at the time of disclosure)
CVE-2023-36038
ASP.NET Core Denial of Service Vulnerability

ASP.NET Core Denial of Service Vulnerability

NVD description · AI analysis pending
7.53%
  • microsoft visual studio 2022
  • microsoft asp.net core
CVE-2023-36413
Microsoft Office Security Feature Bypass Vulnerability

Microsoft Office Security Feature Bypass Vulnerability

NVD description · AI analysis pending
6.530%
  • microsoft 365 apps
  • microsoft office
  • microsoft office long term servicing channel
Full article300 words · extracted from infosecurity-magazine.com · click to collapse

Microsoft has released fixes for five zero-day vulnerabilities in its monthly update round, three of which are being actively exploited in the wild.

The software flaws currently being targeted by threat actors include CVE-2023-36036: a critical elevation of privilege issue affecting Microsoft Windows 10 and later, and Microsoft Windows Server 2008 and later.

“The vulnerability, which requires local access, is of low complexity and can be exploited without high-level privileges or user interaction,” explained Action1 co-founder, Mike Walters.

“Successful exploitation allows attackers to gain system-level privileges, making it an ideal tool for escalating privileges after initial access, such as through phishing.”

Read more on zero-days: Microsoft Fixes Six Zero-Days This Patch Tuesday

The second exploited zero-day is CVE-2023-36033, another elevation of privilege vulnerability but this time in the Windows DWM Core Library. It can also be exploited locally, with low complexity and without the need for high-level privileges or user interaction.

The final zero-day of the trio is CVE-2023-36025, a security feature bypass bug in Windows SmartScreen, enabling attackers to circumvent Windows Defender SmartScreen checks and prompts, said Walters.

“Unlike the other vulnerabilities mentioned, this one has a network attack vector and requires user interaction, though it still maintains low attack complexity and doesn’t require high privileges,” he continued.

“To exploit this flaw, a user must interact with a malicious Internet shortcut (.URL) or a hyperlink directing to such a shortcut. This exploitation allows attackers to prevent Windows Smart Screen from blocking malware.”

The two zero-days which have been publicly disclosed but are not being exploited are a security feature bypass flaw in Microsoft Office (CVE-2023-36413) and a denial of service bug in ASP.NET (CVE-2023-36038).

Microsoft fixed a total of 58 software vulnerabilities in November’s Patch Tuesday, although only three were rated critical.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-fixes-five-zeroday/