ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity1

July 2023 Patch Tuesday forecast: A month of instability and uncertainty

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-38023
+1 in the same advisory: …37967
Netlogon RPC Elevation of Privilege Vulnerability

Netlogon RPC Elevation of Privilege Vulnerability

NVD description · AI analysis pending
8.1
group max
2%
  • microsoft windows server 2008
  • microsoft windows server 2012
  • microsoft windows server 2016
  • +1 more
CVE-2023-32439
+2 in the same advisory: …32435 …32434
Type Confusion in Apple WebKit (Safari, iOS, iPadOS, macOS) Enables Code Execution

Apple's WebKit engine, used by Safari and shipped with iOS, iPadOS, and macOS, contains a type confusion vulnerability (CWE-843) that leads to code execution when processing maliciously crafted web content. An attacker can trigger the flaw by inducing a victim to load attacker-controlled web content, for example by visiting a crafted webpage or opening malicious HTML in any application that renders it with WebKit. Successful exploitation grants the attacker arbitrary code execution within the web-content processing context of the affected browser or application. The exposure is broad: every iPhone, iPad, and Mac running vulnerable WebKit builds is affected, and the flaw could also impact HTML parsers in non-Apple products that rely on WebKit. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2023-06-23, confirming known in-the-wild exploitation (ransomware use unknown); no public proof-of-concept is known, and CISA's required action is to apply updates per vendor instructions.

Do: Apply Apple's security updates for iOS, iPadOS, macOS, and Safari immediately, following vendor instructions as required by the CISA KEV catalog, since the flaw is confirmed exploited in the wild. Administrators should also inventory any non-Apple applications, HTML parsers, or embedded browsers that use WebKit and apply the corresponding vendor patches when available. Until patching is complete, treat unsolicited web links and HTML content as a primary attack vector and prioritize updates on internet-facing and user-facing Apple systems.

8.8
group max
24% KEV
  • Apple Safari (WebKit)
  • Apple iOS (WebKit)
  • Apple iPadOS (WebKit)
  • +2 more
masshundreds of millions to over a billion users (WebKit ships with every iPhone, iPad, and Mac)
CVE-2023-36884
Race Condition RCE in Microsoft Windows Search

CVE-2023-36884 is a race condition (TOCTOU) vulnerability in Microsoft Windows Search that permits remote code execution, rated 7.5 (high) on CVSS 3.1. It is triggered over the network with user interaction — for example, when a user opens or interacts with a specially crafted document that causes the vulnerable search code path to race, allowing arbitrary code execution in the context of the current user. An attacker gains code execution on the victim's Windows system, which the RomCom threat actor chained with Firefox flaws to deploy backdoors against political targets, and CISA notes known ransomware use. Virtually every supported Windows client and server release at the time is affected, spanning Windows 10 1507 through 22H2, Windows 11 21H2/22H2, and Windows Server 2008 through 2022. The flaw was actively exploited as a zero-day before being fixed in the July 2023 Patch Tuesday; it was added to the CISA KEV catalog on 2023-07-17 and carries a 98.9% EPSS score (100th percentile).

Do: Apply the July 2023 Patch Tuesday Windows security updates to all Windows 10, Windows 11, and Windows Server systems, prioritizing high-value and frequently attacked endpoints since the bug was exploited as a zero-day by RomCom and carries a KEV deadline (US civilian agencies were directed to remediate by August 1, 2023). Because exploitation requires user interaction, caution users against opening untrusted documents, and verify patch status via your patch management or vulnerability scanner against the KEV requirement. If patching is not possible, follow vendor mitigations per CISA's required action or discontinue use.

7.599% KEV ransomware
  • microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • microsoft Windows 11 21H2, 22H2
  • microsoft Windows Server 2008 as listed in the CPE data
  • +4 more
mass≈1 billion+ Windows devices (Windows 10/11 installed base) plus the enterprise Windows Server estate
Full article746 words · extracted from helpnetsecurity.com · click to collapse

We’re halfway through 2023 already and moving into our seventh Patch Tuesday of the year next week. There’s been a lot of activity with Microsoft this month which may impact updates we’ll see. But first taking a quick look back at June, we had a fairly standard set of releases with 32 CVEs fixed in Windows 11 and 36 fixed in Windows 10. Although I call out the desktops for simplicity, always keep in mind these updates apply to the applicable server versions as well. We revisited some older zero-day vulnerabilities with informational updates, but there were no new ones.

July 2023 Patch Tuesday forecast

Microsoft continued their phased enablement of security enforcement with new Kerberos and NetLogon default settings. If you haven’t been following this closely, check out How to manage the Kerberos and Netlogon Protocol changes related to CVE-2022-37967 and KB5021130: How to manage the Netlogon protocol changes related to CVE-2022-38023 from Microsoft. There were also critical updates all for the .NET framework releases addressing six vulnerabilities which need attention. The weather is getting hotter now that July is here, will the upcoming releases be as well?

M365 apps failing to launch

There have been many reports in the news throughout June regarding issues caused by the Microsoft June releases as well as issues within Microsoft software and services that have resulted in instability. These issues may portend a hot July Patch Tuesday release.

Starting on Patch Tuesday, the application of Windows 11 22H2 KB5027231 cumulative update broke Google Chrome for users running Malwarebytes, Cisco Secure Endpoint, and WatchGuard Endpoint Security – they were not able to launch Google Chrome. There was no easy way to remove the Microsoft update and these companies were forced to provide temporary workarounds until fixes were provided within their software.

Later in the month, Microsoft ran into some problems of their own. Starting the week of June 19th, there were many reports of Microsoft 365 Applications, Microsoft Outlook, and Microsoft Teams either failing to launch, running slowly, starting and stopping randomly, and even licensing failure. And finally, researchers reported this month that Microsoft Teams can be exploited to distribute malware. The reported vulnerability allows external tenants to bypass restrictions on incoming files which could be malicious. Microsoft has been relatively quiet on all these issues, but we may hear more as Patch Tuesday approaches.

Apple vulnerabilities

Apple was in the news again this month addressing three new zero-day vulnerabilities. CVE-2023-32434 and CVE-2023-32435 exist in iOS and are associated with the Triangulation spyware. CVE-2023-32439 is a WebKit zero-day vulnerability that can let attackers gain arbitrary code execution on unpatched devices. For a complete list of the latest application, iOS, and macOS security updates check out the Apple Security Updates page.

July 2023 Patch Tuesday forecast

  • Microsoft will provide their regular operating system and application updates this month. I don’t expect another .NET framework release after the critical one from June. There were Microsoft Exchange Server updates last month so we may get a pass this month. Based on the online issues with Microsoft 365 Applications we should see application updates as well as some Azure updates if there are communications or hosting related issues.
  • I was really surprised we didn’t get an Adobe Acrobat and Reader update last month – the last one was in April. Expect one soon.
  • Apple provided the zero-day updates on June 21st so we shouldn’t see another set of updates for a while. Don’t forget the beta of Sonoma is now available with an anticipated release of this new OS near year-end.
  • The Stable channel for Chrome OS was updated to 114.0.5735.205 last week. The Beta channel for Desktop was also updated to 115.0.5790.56 for Windows, Linux and Mac last week, so I would expect a Stable channel announcement next week.
  • Mozilla released Firefox 115, Firefox ESR 102.13, and Thunderbird 102.13 on July 4th. Don’t expect another update next week.
  • Oracle Critical Patch Updates are scheduled for July 18th. You can get all your Oracle product updates, including Java, the week after Patch Tuesday.

If you haven’t done so already, deploy the Apple and Mozilla updates to lighten you load next week. There was a lot of unanswered activity surrounding Microsoft this month, so keep a close eye on the KBs next week to see if any of your application disruptions or operating system issues were addressed.

The July 2023 Patch Tuesday is now live: Microsoft patches four exploited zero-days, but lags with fixes for a fifth (CVE-2023-36884)

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/07/07/july-2023-patch-tuesday-forecast/