ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

September 2019 Patch Tuesday: Microsoft plugs two actively exploited zero-days

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-0787
+3 in the same advisory: …0788 …1290 …1291
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote

A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0788, CVE-2019-1290, CVE-2019-1291.

NVD description · AI analysis pending
8.812%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2019-11184
A race condition in specific microprocessors using Intel (R) DDIO cache allocation and RDMA may allow an authenticated user to potentially enable partial inform

A race condition in specific microprocessors using Intel (R) DDIO cache allocation and RDMA may allow an authenticated user to potentially enable partial information disclosure via adjacent access.

NVD description · AI analysis pending
4.8<1%
  • intel 6138 firmware
  • intel 6130t firmware
  • intel 6130 firmware
  • +1 more
CVE-2019-1181
+1 in the same advisory: …1182
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the

A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would need to send a specially crafted request to the target systems Remote Desktop Service via RDP. The update addresses the vulnerability by correcting how Remote Desktop Services handles connection requests.

NVD description · AI analysis pending
9.876%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2019-1215
+1 in the same advisory: …1214
Local Privilege Escalation in Microsoft Windows Winsock Driver (ws2ifsl.sys)

CVE-2019-1215 is an elevation-of-privilege vulnerability in ws2ifsl.sys, an auxiliary Winsock driver shipped with Windows, caused by improper handling of objects in memory (CWE-269). A local attacker with limited privileges can trigger the flaw via crafted requests to the driver, without user interaction, to execute code in kernel context. Successful exploitation grants elevated (SYSTEM-level) privileges, turning a low-privileged foothold into full control of the host and making the bug a useful link in ransomware attack chains. Affected systems include Windows 7, Windows 8.1, Windows RT 8.1, Windows 10 versions 1507 through 1903, and Windows Server versions 1803 and 1903. Microsoft patched the flaw in its October 2019 security updates; CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 with ransomware use known, and EPSS currently assigns a 19.3% probability of exploitation within 30 days (97th percentile).

Do: Apply the Microsoft security update issued October 8, 2019 across all affected Windows 7, 8.1, RT 8.1, Windows 10 (1507-1903), and Server 1803/1903 systems, prioritizing hosts where ransomware operators could chain this local privilege escalation. Systems no longer receiving updates (Windows 7 without Extended Security Updates, Windows 10 versions past end of service) should be upgraded to a supported release. Organizations subject to CISA's KEV binding requirements must patch per the vendor instructions within the required deadline, and defenders should hunt legacy endpoints for prior exploitation given the known ransomware linkage.

7.819% KEV ransomware
  • Microsoft Windows 10 1507, 1607, 1703, 1709, 1803, 1809, 1903
  • Microsoft Windows 7
  • Microsoft Windows 8.1
  • +2 more
masslikely hundreds of millions of devices at disclosure (the affected Windows 7/8.1 and Windows 10 1507-1903 releases dominated the global Windows PC installed…
CVE-2019-1257
+2 in the same advisory: …1295 …1296
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsof

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1295, CVE-2019-1296.

NVD description · AI analysis pending
8.812%
  • microsoft sharepoint enterprise server
  • microsoft sharepoint foundation
  • microsoft sharepoint server
CVE-2019-1306
A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps

A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability'.

NVD description · AI analysis pending
9.817%
  • microsoft team foundation server
  • microsoft azure devops server
Full article648 words · extracted from helpnetsecurity.com · click to collapse

For the September 2019 Patch Tuesday, Microsoft delivered fixes for 80 CVE-numbered security issues (including to actively exploited zero-days), Adobe fixed flaws in Flash Player and Application Manager, and Intel offered solutions and mitigations for two security holes, one of which could allow a side-channel attack aimed at acquiring sensitive data (e.g., keystrokes in a SSH session).

September 2019 Patch Tuesday

Microsoft’s patches

Let’s start with the zero-days exploited in the wild.

CVE-2019-1214 is an elevation of privilege vulnerability in the Windows Common Log File System (CLFS) Driver. CVE-2019-1215 is an elevation of privilege vulnerability in the Winsock IFS Driver (ws2ifsl.sys).

“Both flaws exist due to improper handling of objects in memory by the respective drivers,” says Satnam Narang, senior research engineer at Tenable, and points out that attackers must first gain access to a system before taking advantage of them.

Microsoft reports CVE-2019-1215 being used against both newer and older supported OSes, while CVE-2019-1214 is only being used against older ones.

“This is a fine time to remind you that Windows 7 is less than six months from end of support, which means you won’t be getting updates for bugs like this one next February,” says Trend Micro ZDI’s Dustin Childs, and advises: “Patch your systems, then work on your upgrade strategy.”

(Windows Server 2008 R2 will also be out of extended support and no longer receiving updates as of January 14, 2020.)

Other fixed vulnerabilities of note:

CVE-2019-1257, CVE-2019-1295, and CVE-2019-1296 – RCE flaws in Sharepoint, patches for which should be prioritized for SharePoint servers.

CVE-2019-0787, CVE-2019-0788, CVE-2019-1290, and CVE-2019-1291 – RCEs in the Remote Desktop Client (RDP). They were discovered by Microsoft as a result of internal vulnerability testing against the Remote Desktop Client, which was spurred by the attention the BlueKeep and DejaBlue (CVE-2019-1181 and CVE-2019-1182) RDP vulnerabilities got.

As Childs noted, these are all client-side and an attacker would need to convince someone to connect to their malicious RDP server or otherwise intercept the traffic. “It’s good to see these issues patched, but they don’t carry the urgency of the recent wormable bugs,” he added.

Jimmy Graham, Senior Director of Product Management at Qualys, advises prioritizing Scripting Engine, Browser, and LNK patches for workstations, and the patch for CVE-2019-1306 – a RCE in Azure DevOps Server and Team Foundations Server that can be exploited through malicious file uploads – for Azure DevOps or TFS installations.

As usual, SANS ISC handler Renato Marinho has compiled a handy dashboard covering all the fixed flaws.

Adobe’s patches

After an hefty August Patch Tuesday, Adobe has followed with an extremely light one.

The Flash Player updates (for Windows, macOS, Linux and Chrome OS) are more important, as they address two critical CVEs that could lead to to arbitrary code execution in the context of the current user.

The security update for Application Manager is only for the Windows version and fixes an insecure library loading vulnerability that could lead to arbitrary code execution.

Intel’s patches

Intel has fixed a medium severity privilege escalation flaw in the Intel Easy Streaming Wizard software and has offered recommendations for mitigating the risk of exploitation of CVE-2019-11184, “a race condition in specific microprocessors using Intel (R) DDIO cache allocation and RDMA may allow an authenticated user to potentially enable partial information disclosure via adjacent access.”

The vulnerability was discovered and flagged by VUSec researchers (VUSec is the Systems and Network Security Group at Vrije Universiteit Amsterdam) and is crucial for pulling off a set of cache attacks they dubbed NetCAT. Intel deems the vulnerability to be of low severity as it’s not easily exploited.

UPDATE: September 13, 11:25 PM PT – Microsoft reached out to say that their previous information about the CVEs being “under attack” is incorrect:

CVE-2019-1214 and CVE-2019-1215 were initially marked incorrectly as under attack. This designation has since been updated in the advisories: CVE-2019-1214, CVE-2019-1215.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2019/09/11/september-2019-patch-tuesday/