ZeroHour
Krebs on Securitypublished ()ingested

Patch Tuesday, February 2019 Edition

criticalVulnerability exploited in the wildimportance 60CVE-2019-0676CVE-2019-0626CVE-2019-0686

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-0626
A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server, aka 'Windows DHCP

A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.

NVD description · AI analysis pending
9.869%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2019-0676
Information Disclosure in Microsoft Internet Explorer via Improper Memory Handling

CVE-2019-0676 is an information disclosure vulnerability in Microsoft Internet Explorer caused by improper handling of objects in memory. It is exploited remotely via attacker-crafted content, most likely a malicious web page or link, that the victim must open in Internet Explorer, as reflected by the user-interaction requirement in the CVSS vector. A successful attacker can probe the victim's system and test for the presence of specific files on disk, which is useful for reconnaissance and tailoring follow-on attacks; there is no integrity or availability impact. Affected systems are those running Microsoft Internet Explorer, per CISA and Microsoft data. The flaw is listed in the CISA KEV catalog (added 2022-05-23), confirming known exploitation in the wild, with an EPSS 30-day exploitation probability of 7.5% (94th percentile), and remediation is via Microsoft security updates.

Do: Apply Microsoft security updates for Internet Explorer/Windows per vendor instructions, as required by the CISA KEV listing, and verify patch status across internet-exposed and user workstations. Because exploitation requires user interaction, caution users against opening untrusted links in IE, and consider disabling or removing Internet Explorer where it is no longer needed. Monitor for KEV-driven remediation deadlines and check environments for evidence of the file-existence probing behavior.

6.58% KEV
  • microsoft Internet Explorer
masshundreds of millions of Windows devices (Internet Explorer ships bundled with Windows)
CVE-2019-0686
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'.

An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0724.

NVD description · AI analysis pending
7.45%
  • microsoft exchange server
Full article735 words · extracted from krebsonsecurity.com · click to collapse

Microsoft on Tuesday issued a bevy of patches to correct at least 70 distinct security vulnerabilities in Windows and software designed to interact with various flavors of the operating system. This month’s patch batch tackles some notable threats to enterprises — including multiple flaws that were publicly disclosed prior to Patch Tuesday. It also bundles fixes to quash threats relevant to end users, including critical updates for Adobe Flash Player and Microsoft Office, as well as a zero-day bug in Internet Explorer.

Some 20 of the flaws addressed in February’s update bundle are weaknesses labeled “critical,” meaning Microsoft believes that attackers or malware could exploit them to fully compromise systems through little or no help from users — save from convincing a user to visit a malicious or hacked Web site.

Microsoft patched a bug in Internet Exploder Explorer (CVE-2019-0676) discovered by Google that attackers already are using to target vulnerable systems. This flaw could allow malware or miscreants to check for the presence of specific files on the target’s hard drive.

Another critical vulnerability that impacts both end users and enterprises is a weakness in the Windows component responsible for assigning Internet addresses to host computers (a.k.a. “Windows DHCP client”). That flaw, CVE-2019-0626, could let an attacker execute malcode of his choice just by sending the target a specially crafted DHCP request.

At the top of the list of patch concerns mainly for companies is a publicly disclosed issue with Microsoft Exchange services (CVE-2019-0686) that could allow an attacker on the same network as the target to access the inbox of other users. Microsoft said it has not seen active exploitation of this bug yet, but considers it likely to be exploited soon.

Security experts are fond of saying “patch now!” when it comes to Windows bugs, but in general it can’t hurt for regular users to wait a day or two after Microsoft releases monthly security updates before installing the fixes. That’s because occasionally buggy patches can cause serious headaches for users who install them before all the kinks are worked out.

Just don’t put off the task too long. And bear in mind it’s a good idea to get in the habit of backing up your data before installing Windows updates, to hedge against the odd case in which a wonky patch ends up rendering your system unusable until you can work out how to reverse the changes.

Windows 10 likes to install patches all in one go and reboot your computer on its own schedule. Microsoft doesn’t make it easy for Windows 10 users to change this setting, but it is possible. For all other Windows OS users, if you’d rather be alerted to new updates when they’re available so you can choose when to install them, there’s a setting for that in Windows Update.

Microsoft also included fixes to address a single vulnerability in Adobe Flash Player. Microsoft and Adobe disagree on the severity of this flaw, according to security firm Qualys. Adobe labels it an “important” bug, while Microsoft tags it with a far more severe “critical” label. Regardless, Flash flaws are favorite targets of attackers. If you browse the Web with IE or Edge, this month’s patch batch from Microsoft has you covered.

Fortunately, the most popular Web browser by a long shot — Google Chrome — auto-updates Flash but also is now making users explicitly enable Flash every time they want to use it (Microsoft also bundles Flash with IE/Edge and updates it whenever Windows systems install monthly updates). By the summer of 2019 Google will make Chrome users go into their settings to enable it every time they want to run it.

Firefox also forces users with the Flash add-on installed to click in order to play Flash content; instructions for disabling or removing Flash from Firefox are here. Adobe will stop supporting Flash at the end of 2020.

Adobe also released updates for Adobe Acrobat and Reader that plug at least 70 security holes in these applications, so if you have either installed please be sure to update those.

As always, if you experience any problems installing any of these patches this month, please feel free to leave a comment about it below; there’s a good chance other readers have experienced the same and may even chime in here with some helpful tips.

Text extracted automatically; images, tables and formatting may be missing. Original: https://krebsonsecurity.com/2019/02/patch-tuesday-february-2019-edition/