Microsoft Patch Tuesday — Oct. 2019: Vulnerability disclosures and Snort coverage
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-1239 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1238. NVD description · AI analysis pending | 7.5 group max | 8% |
| — | ||
| CVE-2019-1365 | An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attacker who suc An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to execute code in the context of NT AUTHORITY\system escaping the Sandbox.The security update addresses the vulnerability by correcting how Microsoft IIS Server sanitizes web requests., aka 'Microsoft IIS Server Elevation of Privilege Vulnerability'. NVD description · AI analysis pending | 9.9 group max | 4% |
| — | ||
| CVE-2019-1330 | An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1329. NVD description · AI analysis pending | 6.5 group max | 3% |
| — | ||
| CVE-2019-1307 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engi A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1308, CVE-2019-1335, CVE-2019-1366. NVD description · AI analysis pending | 7.5 | 10% |
| — | ||
| CVE-2019-1376 +1 in the same advisory: …1313 | An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enforces permissions, aka 'SQL Server Managem An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enforces permissions, aka 'SQL Server Management Studio Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1313. NVD description · AI analysis pending | 6.5 | 5% |
| — | ||
| CVE-2019-1314 | A security feature bypass vulnerability exists in Windows 10 Mobile when Cortana allows a user to access files and folders through the locked screen, aka 'Windo A security feature bypass vulnerability exists in Windows 10 Mobile when Cortana allows a user to access files and folders through the locked screen, aka 'Windows 10 Mobile Security Feature Bypass Vulnerability'. NVD description · AI analysis pending | 6.8 | <1% |
| — | ||
| CVE-2019-1322 +1 in the same advisory: …1315 | Local Privilege Escalation in Microsoft Windows 10 and Windows Server CVE-2019-1322 is an elevation of privilege vulnerability in Microsoft Windows caused by improper handling of authentication requests. A local attacker with low privileges can trigger the flaw via crafted authentication requests with no user interaction required, gaining elevated (SYSTEM-level) rights and full confidentiality, integrity, and availability impact on the host. Affected products are Windows 10 versions 1803, 1809, and 1903, and Windows Server 1803, 1903, and 2019. The flaw is known to be exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-15 with ransomware use explicitly noted, and a public proof-of-concept exists. Because it is a local escalation, it is typically used as a post-compromise step to deepen an attacker's foothold, commonly as part of ransomware chains. Do: Apply Microsoft's current cumulative security updates to Windows 10 1803/1809/1903 and Windows Server 1803/1903/2019 per CISA's required action, and prioritize these systems given their KEV listing and known ransomware use. Because exploitation requires a low-privileged local foothold, also limit unprivileged local logon and RDP access on servers while patching. Verify hosts no longer run the affected builds before considering them remediated. | 7.8 | 19% | KEV ransomware PoC |
| masstens of millions of Windows 10/Server endpoints on unpatched 1803–1903-era builds (Windows 10 installed base was hundreds of millions of devices at disclosure;… | |
| CVE-2019-1331 +1 in the same advisory: …1327 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remo A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1327. NVD description · AI analysis pending | 8.8 | 20% |
| — | ||
| CVE-2019-1364 | An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1362. NVD description · AI analysis pending | 7.8 group max | 3% |
| — | ||
| CVE-2019-1356 | An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory, aka 'Microsoft Edge based on Edge HT An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory, aka 'Microsoft Edge based on Edge HTML Information Disclosure Vulnerability'. NVD description · AI analysis pending | 6.5 | 6% |
| — | ||
| CVE-2019-1369 | An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Di An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'. NVD description · AI analysis pending | 5.5 | 2% |
| — | ||
| CVE-2019-1372 | An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length of a buffer prior to copying memory to it An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability could allow an unprivileged function run by the user to execute code in the context of NT AUTHORITY\system thereby escaping the Sandbox.The security update addresses the vulnerability by ensuring that Azure App Service sanitizes user inputs., aka 'Azure App Service Remote Code Execution Vulnerability'. NVD description · AI analysis pending | 10.0 | 19% |
| — | ||
| CVE-2019-1375 | A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. NVD description · AI analysis pending | 5.4 | 2% |
| — | ||
| CVE-2019-1378 | An elevation of privilege vulnerability exists in Windows 10 Update Assistant in the way it handles permissions.A locally authenticated attacker could run arbit An elevation of privilege vulnerability exists in Windows 10 Update Assistant in the way it handles permissions.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows 10 Update Assistant Elevation of Privilege Vulnerability'. NVD description · AI analysis pending | 7.8 | 1% |
| — |
Full article588 words · extracted from blog.talosintelligence.com · click to collapse
Tuesday, October 8, 2019 13:11
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing a variety of vulnerabilities in several of its products. The latest Patch Tuesday discloses 60 vulnerabilities, nine of which are considered "critical," with the rest being deemed "important."
This month’s security update covers security issues in a variety of Microsoft services and software, the Chakra Scripting Engine, the Windows operating system and the SharePoint software.
Talos also released a new set of SNORTⓇ rules that provide coverage for some of these vulnerabilities. For more, check out the Snort blog post here.
Critical vulnerabilities Microsoft disclosed nine critical vulnerabilities this month, eight of which we will highlight below.
CVE-2019-1333 is a client-side remote execution vulnerability in Remote Desktop Services (RDP) that occurs when a user visits a malicious server. An attacker could exploit this vulnerability by having control of a malicious server, and then convincing the user to connect to it — likely via social engineering or a man-in-the-middle attack. An attacker could also compromise a legitimate server and then host malicious code on it, waiting for a user to connect. If successful, the attacker could gain the ability to remotely execute code on the victim machine that connected to the server.
CVE-2019-1238 and CVE-2019-1239 are remote code execution vulnerabilities that exist in the way VBScript handles objects in memory. These bugs all could lead to memory corruption in a way that would allow an attacker to execute arbitrary code on the victim machine. An attacker could exploit these vulnerabilities by tricking a user into visiting a specially crafted, malicious website through Internet Explorer. They could also embed an ActiveX control marked "safe for initialization" in an application or Microsoft Office document that utilizes the Internet Explorer rendering engine.
CVE-2019-1307, CVE-2019-1308, CVE-2019-1335 and CVE-2019-1366 are all memory corruption vulnerabilities in the Chakra Scripting Engine inside of the Microsoft Edge web browser. An attacker could use these bugs to corrupt memory on the victim machine in a way that would allow them to remotely execute arbitrary code. A user could trigger these vulnerabilities by visiting a specially crafted, malicious website in Edge.
CVE-2019-1372 is an elevation of privilege vulnerability on Azure Stack when the Azure App Service fails to properly check the length of a buffer prior to copying memory to it. An attacker could exploit this vulnerability to copy any function run by the user, thereby executing code in the context of NT AUTHORITY/system, which could allow the attacker to escape a sandbox.
There is also CVE-2019-1060, a remote code execution vulnerability in Microsoft XML Core Services.
Important vulnerabilities This release also contains 51 important vulnerabilities.
- CVE-2019-0608
- CVE-2019-1070
- CVE-2019-1166
- CVE-2019-1230
- CVE-2019-1311
- CVE-2019-1313
- CVE-2019-1314
- CVE-2019-1315
- CVE-2019-1316
- CVE-2019-1317
- CVE-2019-1318
- CVE-2019-1319
- CVE-2019-1320
- CVE-2019-1321
- CVE-2019-1322
- CVE-2019-1323
- CVE-2019-1325
- CVE-2019-1326
- CVE-2019-1327
- CVE-2019-1328
- CVE-2019-1329
- CVE-2019-1330
- CVE-2019-1331
- CVE-2019-1334
- CVE-2019-1336
- CVE-2019-1337
- CVE-2019-1338
- CVE-2019-1339
- CVE-2019-1340
- CVE-2019-1341
- CVE-2019-1342
- CVE-2019-1343
- CVE-2019-1344
- CVE-2019-1345
- CVE-2019-1346
- CVE-2019-1347
- CVE-2019-1356
- CVE-2019-1357
- CVE-2019-1358
- CVE-2019-1359
- CVE-2019-1361
- CVE-2019-1362
- CVE-2019-1363
- CVE-2019-1364
- CVE-2019-1365
- CVE-2019-1368
- CVE-2019-1369
- CVE-2019-1371
- CVE-2019-1375
- CVE-2019-1376
- CVE-2019-1378
Coverage In response to these vulnerability disclosures, Talos is releasing a new SNORTⓇ rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Firepower customers should use the latest update to their ruleset by updating their SRU. Open Source Snort Subscriber Rule Set customers can stay up-to-date by downloading the latest rule pack available for purchase on Snort.org.
These rules are: 51733 - 51736, 51739 - 51742, 51781 - 51794
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-oct-2019/