ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Microsoft Patches 5 Zero-Day Vulnerabilities Being Exploited in the Wild

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-0142
Video Control in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute

Video Control in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute arbitrary code via a crafted web page, aka "Microsoft Video Control Remote Code Execution Vulnerability."

NVD description · AI analysis pending
7.820%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2016-3298
Information Disclosure in Microsoft Internet Explorer Messaging API

CVE-2016-3298 is an information disclosure flaw (CWE-200) in the Microsoft Internet Messaging API used by Internet Explorer, in which the API improperly handles objects in memory. Exploitation requires driving Internet Explorer to process attacker-influenced content so the Messaging API mishandles memory, after which the attacker can probe whether specific files exist on the victim's disk. An attacker gains only limited reconnaissance value — confirming file presence for fingerprinting — rather than code execution or direct data theft. Only systems running Microsoft Internet Explorer, as cataloged by CISA, are affected; CISA added the bug to the Known Exploited Vulnerabilities catalog on 2022-05-24, confirming exploitation in the wild, though any ransomware association is unknown. EPSS estimates a 32.8% probability of exploitation within 30 days (98th percentile), no public proof-of-concept is known, and a CVSS score has not yet been published in this dataset.

Do: Apply Microsoft's security update for CVE-2016-3298 per vendor instructions, as mandated by the CISA KEV catalog (added 2022-05-24, so remediation deadlines apply to federal agencies and many regulated environments). Audit any Windows hosts where Internet Explorer is still used for interactive browsing and confirm the patch is installed; because the flaw only permits probing for file existence, residual risk after patching is low.

6.533% KEV
  • Microsoft Internet Explorer
masshundreds of millions of Windows devices (Internet Explorer shipped as a built-in Windows component for decades)
CVE-2016-3393
Remote Code Execution in Microsoft Windows GDI/GDI+ Graphics Component

CVE-2016-3393 is a remote code execution vulnerability in the Windows Graphics Device Interface (GDI/GDI+), the component that renders text, images and graphics across Windows. An attacker triggers it by getting a user to visit a crafted website or otherwise view attacker-supplied content that is rendered through GDI (the CVSS vector confirms user interaction is required), and successful exploitation yields arbitrary code execution in the context of the current user. Affected software spans essentially the entire Windows estate of the era: Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 1507/1511/1607, and Windows Server 2008 SP2 and R2 SP1 and Server 2012 and 2012 R2. The flaw was patched in Microsoft's November 2016 Patch Tuesday, which fixed five zero-days being exploited in the wild, and reporting at the time attributed exploitation of this Windows graphics zero-day to the FruityArmor APT in targeted attacks. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-25), has a high EPSS score (68.7%, 99th percentile), and no public proof-of-concept is known.

Do: Apply the November 2016 Microsoft security updates for the Windows Graphics Component to every affected Windows client and server version, per vendor instructions and CISA KEV's required action. For versions past end of support (Vista, 7, 8.1, RT 8.1, Server 2008/2012), move to a supported Windows release or apply Extended Security Updates. Until patched, discourage users from visiting untrusted websites or opening untrusted documents/images, and prioritize remediation on internet-facing servers and endpoints used by high-value users, given the documented targeted-attack use by the FruityArmor APT.

7.869% KEV
  • Microsoft Windows Vista SP2
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8.1 all supported editions
  • +4 more
mass~hundreds of millions of Windows PCs and servers at the time of disclosure (affected versions spanned nearly the entire Windows installed base); today the…
CVE-2016-7189
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via a crafted web site, aka "Scripting Engine Remote Code Execu

The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via a crafted web site, aka "Scripting Engine Remote Code Execution Vulnerability."

NVD description · AI analysis pending
7.548%
  • microsoft edge
CVE-2016-7193
Memory Corruption RCE in Microsoft Word and Office Components via Crafted RTF Files

Microsoft Word and several related Office components contain a memory corruption flaw (CWE-119) in their handling of Rich Text Format (RTF) documents. An attacker triggers it by persuading a user to open a specially crafted RTF file, typically delivered as an email attachment, which corrupts memory and permits arbitrary code execution in the context of the current user (CVSS 3.1: 7.8, with user interaction required). The affected footprint is unusually broad, spanning Word 2007 SP2 through Word 2016 on Windows, Word for Mac 2011 and 2016, Word Viewer, the Office Compatibility Pack, Word Automation Services in SharePoint 2010/2013, and Office Web Apps/Office Online Server. The vulnerability is listed in the CISA Known Exploited Vulnerabilities catalog (added 2022-03-03) and carries an EPSS of 57.7 percent (99th percentile), indicating active in-the-wild exploitation; Microsoft addressed it in its November 2016 security updates.

Do: Apply Microsoft's security updates for every affected component per vendor instructions, which is the required action in CISA's KEV catalog. Because exploitation occurs via malicious RTF files, consider blocking or sandboxing RTF email attachments and opening them in a protected/isolated mode until patches are deployed. Audit for legacy and easily overlooked components, including Word Viewer, the Office Compatibility Pack, Office Web Apps 2010/2013, SharePoint Word Automation Services, and Office Online Server, and upgrade or decommission any that remain unpatched.

7.858% KEV
  • Microsoft Word 2007 SP2
  • Microsoft Office 2010 SP2
  • Microsoft Word 2013 SP1
  • +9 more
masshundreds of millions of Office/Word installations worldwide (order of magnitude 10^8)
Full article578 words · extracted from thehackernews.com · click to collapse

Swati KhandelwalOct 12, 2016

Microsoft has released its monthly Patch Tuesday update including a total of 10 security bulletin, and you are required to apply the whole package of patches altogether, whether you like it or not.

That's because the company is kicking off a controversial new all-or-nothing patch model this month by packaging all security updates into a single payload, removing your ability to pick and choose which individual patches to install.

October's patch bundle includes fixes for at least 5 separate dangerous zero-day vulnerabilities in Internet Explorer, Edge, Windows and Office products that attackers were already exploiting in the wild before the patch release.

The patches for these zero-day flaws are included in MS16-118, MS16-119, MS16-120, MS16-121 and MS16-126. All the zero-days are being exploited in the wild, allowing attackers to execute a remote command on victim's system.

Although none of the zero-day flaws were publicly disclosed prior to Tuesday, the company was aware of attacks exploiting these flaws, said Microsoft.

Here's the list of Zero-Day Vulnerabilities:


  1. CVE-2016-3298: An Internet Explorer zero-day flaw is a browser information disclosure vulnerability patched in MS16-118 bulletin among 11 other vulnerabilities. It could allow attackers to "test for the presence of files on disk."
  2. CVE-2016-7189: A zero-day in the browser's scripting engine has been patched in Microsoft Edge bulletin, MS16-119, among others. The flaw is a remote code execution vulnerability.
  3. CVE-2016-3393: Another zero-day in Microsoft Windows Graphics Component has been addressed in MS16-120 that could be exploited over the web, or via an email containing malicious file or over a file-sharing app to conduct RCE attack.
  4. CVE-2016-7193: A single zero-day in Office has been addressed in MS16-121 bulletin. The flaw is a remote code execution vulnerability caused by the way Office handles RTF files.
  5. CVE-2016-3298: The last publicly attacked zero-day has been patched in MS16-126, which is the only zero-day that is not rated critical, just moderate. The flaw is an information disclosure bug affecting Vista, Windows 7 and 8 and exists in the Microsoft Internet Messaging API.

Another bulletin rated critical is MS16-122 that patches a remote code execution flaw, CVE-2016-0142, in the Windows Video Control, affecting Windows Vista, 7, 8 and 10. The bug can be exploited when a user opens a crafted file or app from the web page or email.

Microsoft also patched twelve vulnerabilities in Adobe Flash Player for Windows 8.1, Windows 10, and Server 2012 in MS16-127.

Rest bulletins rated important or moderate, including MS16-123, MS16-124 and MS16-125, patches five elevation of privilege vulnerabilities in Windows Kernel-Mode, four elevation of privilege vulnerabilities in Windows Registry, and an elevation of privilege flaw in Windows Diagnostics Hub respectively.

Adobe Patch Update

Adobe also released a new version of Flash Player today that patched a dozen of vulnerabilities in its software, most of which were remote code execution flaws.

Adobe has also published code clean-ups for 71(!) CVE-listed security flaws in Acrobat and Reader, along with a fix for a single elevation of privilege bug in Creative Cloud.

Users are advised to apply Windows and Adobe patches to keep away hackers and cybercriminals from taking control over your computer.

A system reboot is necessary for installing updates, so admins are advised to save work on PCs where the whole package of patches is deployed before initiating the process.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2016/10/Microsoft-security-patch-updates.html