Microsoft Patch Tuesday updates for May 2017 fix Zero Days exploited by Russian APT groups
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-0001 | Local Privilege Escalation in Microsoft Windows GDI CVE-2017-0001 is a privilege escalation flaw in the Windows Graphics Device Interface (GDI) that affects Windows Vista through Windows 10 (1507, 1511, 1607) and Windows Server 2008 through 2016. It is triggered by a local attacker who runs a crafted application on an affected system, requiring only low local privileges and no user interaction. Successful exploitation grants the attacker elevated privileges, with high impact on confidentiality, integrity and availability, effectively giving full control of the host. Any organization running unpatched copies of these Windows client or server versions is affected. The flaw is listed in the CISA Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating known exploitation in the wild, though specific in-the-wild campaigns and ransomware use are not documented; EPSS estimates a 3.1% chance of exploitation in the next 30 days. Do: Apply the January 2017 Microsoft security update or any later cumulative update for the affected Windows version, prioritizing systems listed in CISA KEV; verify installed updates confirm the GDI privilege escalation fix is present. Systems past extended support (Windows Vista, Windows 7, Windows 8.1, Server 2008/2012 without extended security updates) should receive the applicable ESU patch or be migrated, and restrict local execution of untrusted applications as an interim mitigation. | 7.8 | 3% | KEV |
| masshundreds of millions of Windows installations worldwide (any unpatched Windows Vista through 10 1607 / Server 2008 through 2016 system) | |
| CVE-2017-0222 | Memory Corruption RCE in Microsoft Internet Explorer CVE-2017-0222 is a remote code execution flaw in Microsoft Internet Explorer caused by improper access to objects in memory (CWE-119), which can corrupt memory in a way that allows arbitrary code execution. It is triggered remotely, typically when a user is persuaded to view attacker-controlled web content in Internet Explorer. A successful attack runs code in the context of the current user, so the attacker gains that user's privileges and potentially full control of the workstation if the user has elevated rights. Anyone running affected builds of Internet Explorer is exposed, which historically means the very large base of Windows desktops that shipped with IE. Exploitation is confirmed in the wild — CISA added the CVE to its KEV catalog on 2022-02-25 — while no public proof-of-concept is known and ransomware use is unknown; EPSS estimates a 29.6% chance of exploitation in the next 30 days (98th percentile). Do: Apply the Microsoft cumulative security update for Internet Explorer that fixes this issue (released with the April 2017 Patch Tuesday, or any later cumulative IE update) on all Windows systems that still run IE, prioritizing legacy and internet-facing machines. Because CISA's KEV listing in February 2022 shows the flaw was still being exploited years after patching, audit Windows 7/8.1 and Windows Server estates for unpatched IE and migrate users to Microsoft Edge (with IE mode if needed). As interim mitigations, restrict or disable legacy IE, warn users about opening untrusted links, and verify current IE patch levels before patching. | 8.8 | 30% | KEV |
| masshundreds of millions of Windows endpoints (IE was bundled by default on Windows desktops of the era) | |
| CVE-2017-0262 +1 in the same advisory: …0261 | Memory Corruption RCE in Microsoft Office 2010, 2013, and 2016 Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 fail to properly handle objects in memory, creating a remote code execution condition when the software processes a specially crafted file. Triggering the flaw requires user interaction - the CVSS vector (AV:L, UI:R) indicates an attacker must get a user to open a malicious document, typically via a phishing email or similar file-delivery channel. Successful exploitation runs arbitrary code in the context of the current user, exposing the confidentiality, integrity, and availability of everything that account can access on the endpoint (CVSS 3.1: 7.8, High). Any organization running the affected Office versions is affected; the flaw was one of several Office zero-days fixed in Microsoft's May 2017 Patch Tuesday (distinct from CVE-2017-0261 and CVE-2017-0281) and was reportedly exploited by Russian APT actors (APT28/Sofacy) around that time. Exploitation is confirmed: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-02-10, and EPSS currently rates the 30-day exploitation probability at 81% (100th percentile), so unpatched endpoints should be treated as actively targeted. Do: Apply Microsoft's May 2017 security updates for Office 2010 SP2, Office 2013 SP1, and Office 2016, per the CISA KEV required action, and verify through asset inventory that no endpoint is running an unpatched Office build. Because exploitation requires user interaction with a crafted file, harden email and attachment handling (block or detonate Office files from untrusted sources) and brief users on unsolicited documents. Office 2010 and 2013 have since reached end of support, so migrate any remaining deployments to a currently supported Office release. | 7.8 | 81% | KEV |
| masstens to hundreds of millions of endpoints (Office 2010 SP2/2013 SP1/2016 dominated desktop deployments at disclosure; current unpatched count unknown) | |
| CVE-2017-0263 | Win32k Use-After-Free Local Privilege Escalation in Windows 7 through Server 2016 CVE-2017-0263 is a use-after-free flaw (CWE-416) in the Windows kernel-mode drivers (Win32k) that allows a locally authenticated user to elevate privileges. It is triggered by running a specially crafted application that mishandles kernel memory on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 1507/1511/1607/1703, and Windows Server 2008 SP2/R2 SP1, Server 2012 Gold/R2, and Server 2016. Successful exploitation yields kernel-level privileges, effectively giving an attacker full control of the host and making it a common link in chained attacks alongside other bugs; related 2017 reporting associated the flaw with Sofacy (APT28) activity. Any unpatched Windows installation of the affected releases is affected, including long-lived legacy desktops and servers. The flaw is confirmed exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities Catalog (added 2022-02-10) — with two public PoC/exploit references and a ~10% EPSS probability of exploitation in the next 30 days (95th percentile). Do: Apply Microsoft security updates per vendor instructions - this Win32k bug was fixed in the April 2017 Patch Tuesday release - prioritizing hosts where untrusted or low-privileged users can execute code (terminal/VDI servers, shared workstations, jump hosts). Windows 7/8.1 and Server 2008/2012 are past end of extended support, so use Extended Security Updates or migrate where patching in place is not possible. Verify installed builds against the affected version list above and close out the CISA KEV remediation requirement promptly. | 7.8 | 10% | KEV PoC ×2 |
| masshundreds of millions of devices (all unpatched Windows 7/8.1/RT 8.1 and Windows 10 1507-1703 PCs, plus the dominant Windows Server releases of that era) |
Full article442 words · extracted from securityaffairs.com · click to collapse

Microsoft Patch Tuesday for May 2017 address tens security vulnerabilities, including a number of zero-day flaws exploited by Russian APT groups.
Microsoft Patch Tuesday updates for May 2017 fix more than 50 security flaws, including a number of zero-day vulnerabilities exploited by Russian APT groups.
Microsoft released security updates for Windows, Internet Explorer, Edge, Office, the .NET framework, and Flash Player on Tuesday.
Security experts at Microsoft worked with peers at ESET and FireEye to address the vulnerabilities affecting Encapsulated PostScript (EPS) filter in Office.

Researchers at FireEye investigated some attacks attributed to the Russian APT groups and also an unknown financially-motivated threat actor.
“At the end of March 2017, we detected another malicious document leveraging an unknown vulnerability in EPS and a recently patched vulnerability in Windows Graphics Device Interface (GDI) to drop malware. Following the April 2017 Patch Tuesday, in which Microsoft disabled EPS, FireEye detected a second unknown vulnerability in EPS.” reads the analysis shared by FireEye.
“FireEye believes that two actors – Turla and an unknown financially motivated actor – were using the first EPS zero-day (CVE-2017-0261), and APT28 was using the second EPS zero-day (CVE-2017-0262) along with a new Escalation of Privilege (EOP) zero-day (CVE-2017-0263). Turla and APT28 are Russian cyber espionage groups that have used these zero-days against European diplomatic and military entities. The unidentified financial group targeted regional and global banks with offices in the Middle East.”
The Turla group (aka Waterbug, KRYPTON, and Venomous Bear) has been exploiting an Office remote code execution (RCE) vulnerability (CVE-2017-0261) to spread the SHIRIME custom JavaScript malware.
A second group of financially motivated threat actors has been exploiting the same vulnerability to deliver a new variant of the NETWIRE malware.
The experts observed that The Turla APT also leveraged CVE-2017-0001 for privilege escalation, while the cyber crime gang the CVE-216-7255 for privilege escalation.
The experts from the two firms confirmed that the notorious APT28 group exploited a number of zero-day vulnerabilities in targeted attacks, including the CVE-2017-0262 Office RCE vulnerabilities and a Windows privilege escalation tracked as CVE-2017-0263.
The hackers leveraged the above exploits to deliver the GAMEFISH malware (Seduploader).
Microsoft announced that the security updates released this month have fixed vulnerabilities in Office (CVE-2017-0261 and CVE-2017-0262) exploited the Russian APT groups.
The list of flaws fixed by Microsoft on Tuesday includes also a memory corruption issue in Internet Explorer tracked as CVE-2017-0222, this memory corruption zero-day can be exploited by a remote attacker for code execution.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(Security Affairs – Russian APT groups, APT28)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/58937/apt/russian-apt-groups.html