ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Microsoft Fixes Windows Defender Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-1458
Win32k Object-Handling Flaw Enables Local Privilege Escalation in Microsoft Windows

An elevation of privilege vulnerability exists in the Windows kernel's Win32k component, which fails to properly handle objects in memory (an uninitialized-variable condition). A local attacker who can already execute limited code on a target machine can trigger the flaw to gain kernel-level execution and elevate to SYSTEM privileges, giving full control of the host. Affected platforms are Windows 7, Windows 8.1, Windows RT 8.1, Windows 10 1507 and 1607, and Windows Server 2008, 2012 and 2016. The bug was patched in Microsoft's December 2019 Patch Tuesday after being actively exploited as a zero-day, including in the WizardOpium campaign attributed to a North Korea-linked actor. It is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-01-10, with known ransomware use) and carries a high EPSS of 74.3%.

Do: Apply the December 2019 security updates (or later cumulative updates) from Microsoft per CISA's required action. Because Windows 7/8.1 and Server 2008/2012 are past end of support and Server 2016 support is winding down, prioritize migration to supported Windows versions. Hunt for signs of local privilege escalation and follow-on activity, since this bug was used as a zero-day and appears in ransomware attack chains.

7.874% KEV ransomware PoC ×2
  • microsoft windows 10 1507 all supported editions at time of patch (December 2019)
  • microsoft windows 10 1607 all supported editions at time of patch (December 2019)
  • microsoft windows 7 all supported editions
  • +5 more
masshundreds of millions of devices (Windows 7 alone held roughly a third of desktop market share at disclosure; millions of Server 2008/2012/2016 hosts remain…
CVE-2021-1647
Remote Code Execution Vulnerability in Microsoft Defender Antimalware Engine

CVE-2021-1647 is a remote code execution flaw in Microsoft Defender's antimalware engine, categorized by CISA as a heap-based buffer overflow (CWE-122) arising from improper validation of crafted input values (CWE-1285). It is triggered when the Defender engine processes maliciously crafted content, for example a crafted file delivered via email or the web that Defender scans, causing the overflow during processing. Successful exploitation lets an attacker run arbitrary code on the target machine in the context of the Defender process, potentially leading to full system compromise. Any system running the affected Defender engine is exposed, including Windows 10 and Windows Server deployments where Defender is the default or widely deployed antivirus; the source data provides no fixed version numbers, only the vendor-issued update. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog as of 2021-11-03, indicating exploitation has been observed in the wild, though no public PoC is known and ransomware use is listed as unknown.

Do: Apply Microsoft's Defender antimalware engine/platform updates per vendor instructions and ensure Defender security intelligence and platform updates are enabled everywhere, including infrequently updated servers and endpoints. After updating, verify the Defender engine version on high-value hosts is current, prioritizing systems listed in CISA KEV remediation requirements.

7.839% KEV
  • Microsoft Defender (antimalware engine, e.g., Microsoft Defender Antivirus / Microsoft Defender for Endpoint) Versions running the Defender antimalware engine prior to Microsoft's security update for CVE-2021-1647; exact affected and fixed version ranges are not specifi
mass≈1 billion+ Windows devices (Defender is the built-in AV on Windows 10 and ships broadly on Windows Server)
CVE-2021-1666
+2 in the same advisory: …1648 …1709
Remote Procedure Call Runtime Remote Code Execution Vulnerability

Remote Procedure Call Runtime Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.8
group max
3%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
Full article331 words · extracted from infosecurity-magazine.com · click to collapse

Microsoft has patched a zero-day bug in Windows Defender being actively exploited in the wild, as part of its monthly update round.

The first Patch Tuesday of 2021 featured fixes for 83 vulnerabilities in Windows OS, Edge, Office, Visual Studio, .Net Core, .Net Repository, ASP .Net, Azure, Malware Protection Engine and SQL Server.

Remote code execution bug CVE-2021-1647 is the most urgent, according to Chris Goettl, director of product management for security products at Ivanti. He recommended organizations ensure their Microsoft Malware Protection Engine is version 1.1.17700.4 or higher.

“Microsoft frequently updates malware definitions and the malware protection engine and has already pushed the update to resolve the vulnerability,” Goettl explained.

“For organizations that are configured for automatic updating no actions should be required, but one of the first actions a threat actor or malware will try to attempt is to disrupt threat protection on a system so definition and engine updates are blocked.”

Another CVE high up the priority list this month is CVE-2021-1648, a bug in the Windows splwow64 service that could allow an attacker to elevate their privilege level. Although publicly disclosed last month it isn’t thought to have been exploited yet.

Experts also highlighted CVE-2021-1666 as worthy of attention: the flaw in Microsoft’s GDI+ component impacts the unsupported Windows 7 and Windows Server 2008 products, as well as newer versions.

Allan Liska, senior security architect at Recorded Future, also flagged CVE-2021-1709, an elevation of privilege vulnerability in the Win32 kernel. The bug, which affects Windows 8-10 and Windows Server 2008-2019, should be prioritized despite its “Important” rating, he argued.

“Unfortunately, this type of vulnerability is often quickly exploited by attackers,” Liska warned. “For example, CVE-2019-1458 was announced on December 10 2019, and by December 19 an attacker was seen selling an exploit for the vulnerability on underground markets.”

Elsewhere, Adobe released fixes for vulnerabilities in its Adobe Bridge, Captivate, InCopy, Campaign Classic, Animate, Illustrator and Photoshop products. There was also a critical Mozilla Thunderbird update.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-fixes-windows-defender/