Microsoft Security Updates August 2015
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2015-1769 | Local Privilege Escalation via Symlink Flaw in Microsoft Windows Mount Manager CVE-2015-1769 is an elevation-of-privilege flaw (CWE-264) in the Windows Mount Manager, the component that handles disk and mount-point management, caused by improper processing of symbolic links. A local attacker who can already run code on a target Windows machine can supply a crafted symbolic link or mount point that Mount Manager mishandles, causing operations to execute with elevated rights. Successful exploitation yields higher privileges, up to SYSTEM/administrator, which attackers typically use to harden a foothold, disable defenses, or move laterally, usually in combination with a separate initial-access or code-execution flaw. Per CISA, Microsoft Windows is affected; the flaw was addressed in Microsoft's August 2015 Mount Manager update (MS15-085), so the currently vulnerable population is largely unpatched or legacy systems. The issue is in CISA KEV (added 2022-05-25), indicating known in-the-wild exploitation, with a 4.1% EPSS probability of exploitation in the next 30 days (90th percentile); no public PoC is known and ransomware usage is undetermined. Do: Apply updates per vendor instructions: install the Mount Manager fix from Microsoft bulletin MS15-085 (August 2015) on any Windows system lacking it, prioritizing hosts referenced in CISA KEV. Audit legacy Windows builds that may have missed this 2015 update, and as interim hardening restrict interactive logon by untrusted users on those machines. Since this is a local privilege escalation, hunt on unpatched systems for signs it was chained after an initial foothold, including in intrusion-to-ransomware sequences. | — | 4% | KEV |
| masshundreds of millions of Windows devices by ubiquity, though the currently vulnerable count is limited to unpatched/legacy systems (patch available since Aug… |
Full article426 words · extracted from securelist.com · click to collapse
Microsoft releases a new batch of fourteen security updates patching over fifty vulnerabilities today, with one of them known to be abused in targeted attacks. A large number of the vulnerabilities were reported by researchers from Google and their Project Zero, and HP’s Zero Day initiative. Meanwhile, a reflective discussion about the value of these offensive teams is laid out on offsec mailing lists.
Currently being exploited in-the-wild, MS15-085 “Vulnerability in Mount Manager Could Allow Elevation of Privilege”, enables an attacker to write out an executable to disk and run it from usb disk insertion. Exploitation is in use as a part of limited targeted attacks. Update installation and maintenance seems to be a large order here, as Microsoft includes a unique recommendation with it: “If you install a language pack after you install this update, you must reinstall this update.” Not only is “Mountmgr.sys” listed a few hundred times in this related knowledge base article, but over a hundred other files are touched with this larger update. And not only is Microsoft shipping code to close up the vulnerability, they are also shipping a new event for the event log, to identify related exploit attempts, “As part of the update, we are also shipping an event log to help defenders detect attempts to use this vulnerability on their systems”. Event ID 100: MountMgr “CVE-2015-1769” will be logged by Windows for reference.
The new Edge web browser maintains three “memory corruption” vulnerabilities. Typically, when these arise in Microsoft’s web browsers, the flaws have been use-after-free problems. These memory corruption issues surprisingly enable remote code execution on Windows 10:
CVE-2015-2441
CVE-2015-2442
CVE-2015-2446
and one ASLR bypass issue. While the code base is smaller, faster, and newer than IE, these issues continue to crop up in their newest code.
More on Microsoft’s August 2015 Bulletins can be found here, please update your system asap.
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/microsoft-security-updates-august-2015/71796/