Microsoft Security Updates January 2016
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2016-0034 | Remote Code Execution via Crafted Website in Microsoft Silverlight 5 CVE-2016-0034 is a memory-corruption flaw in the Microsoft Silverlight 5 runtime, which mishandles negative offsets during decoding, corrupting object headers. An attacker triggers it by convincing a user to visit a crafted website while the vulnerable Silverlight plug-in is active in their browser, requiring no privileges but user interaction. Successful exploitation allows the attacker to execute arbitrary code in the context of the logged-in user (or crash the browser/application). Anyone running Microsoft Silverlight 5 versions before 5.1.41212.0 is affected; Silverlight is now end-of-life, so remaining installations are legacy deployments. The flaw was exploited in the wild through exploit kits such as Angler and RIG to deliver ransomware like Cerber, and it was added to the CISA KEV catalog in May 2022 with known ransomware use. Do: Upgrade Silverlight to version 5.1.41212.0 (January 2016 security update) on any system where it remains installed. Because Silverlight is end-of-life, CISA's KEV required action is to disconnect or remove it and migrate any legacy Silverlight-based web applications; prioritize internet-facing endpoints and users of Internet Explorer/legacy browsers, where the plug-in can still be invoked. | 8.8 | 70% | KEV ransomware |
| masshistorically hundreds of millions of installs (Silverlight reached roughly 70% of consumer devices at peak); residual active installs today likely number in… |
Full article399 words · extracted from securelist.com · click to collapse
New Year's greetings with Silverlight and five other Critical Bulletins!
с новым годом! Microsoft rings in the New Year with a new set of ten security bulletins MS16-001 through MS16-010, patching 24 CVE detailed vulnerabilities. These bulletins effect Microsoft web browsers and plugins, Office software, Windows system software, and Exchange mail servers. Six of them maintain a critical rating. The Critical bulletins effect the following software:
-
- Silverlight Runtime
- Internet Explorer
- Microsoft Edge
- VBScript and JScript scripting engine
- Microsoft Office, Visio, and SharePoint
- Windows Win32k Kernel Components
Somewhat surprisingly with over twenty vulnerabilities, Microsoft claims to be unaware of public exploitation of any of them at the time of reporting, however they acknowledge at least three were publicly disclosed. Nonetheless, the urgency to patch remains, so please update your software.
Of these, the Silverlight vulnerability CVE-2016-0034 (note that Mitre records the CVE as assigned on 2015.12.04) appears to be the most interesting and most risky, as it enabled remote code execution across multiple platforms for this widespread software, including Apple. But more of the IE, Edge and add-on related vulnerabilities also provide opportunity for mass exploitation. Don’t forget to return to Securelist soon for concrete perspective and upcoming posts detailing past and ongoing exploitation of these issues.
It’s also assuring to see Microsoft security operations pushing the edges of improving TLS algorithms to encrypt web sessions and provide greater privacy. Even their Technet page for a summary of these Bulletins provides TLS 1.2, implementing 3DES_EDE_CBC with HMAC-SHA1 and a RSA key exchange. But, it looks like their research group hasn’t pushed forward their work on post-quantum resistant TLS key exchange (Full RWLE Paper [pdf]), as “R-LWE in TLS” into production. Tomorrow’s privacy will have to wait.
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/microsoft-security-updates-january-2016/73284/