Microsoft Patch Tuesday
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2016-0022 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps Server 2013 SP1, and SharePoint Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0052. NVD description · AI analysis pending | 7.8 | 19% |
| — | ||
| CVE-2016-0047 +1 in the same advisory: …0033 | WinForms in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to obtain sensitive information from process memory via WinForms in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to obtain sensitive information from process memory via crafted icon data, aka "Windows Forms Information Disclosure Vulnerability." NVD description · AI analysis pending | 7.5 | 20% |
| — | ||
| CVE-2016-0036 | The Remote Desktop Protocol (RDP) implementation in Microsoft Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows remote authenti The Remote Desktop Protocol (RDP) implementation in Microsoft Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows remote authenticated users to execute arbitrary code via crafted data, aka "Remote Desktop Protocol (RDP) Elevation of Privilege Vulnerability." NVD description · AI analysis pending | 8.1 group max | 11% |
| — | ||
| CVE-2016-0037 | The forms-based authentication implementation in Active Directory Federation Services (ADFS) 3.0 in Microsoft Windows Server 2012 R2 allows remote attackers to The forms-based authentication implementation in Active Directory Federation Services (ADFS) 3.0 in Microsoft Windows Server 2012 R2 allows remote attackers to cause a denial of service (daemon outage) via crafted data, aka "Microsoft Active Directory Federation Services Denial of Service Vulnerability." NVD description · AI analysis pending | 7.5 | 26% |
| — | ||
| CVE-2016-0040 | Local Privilege Escalation in Microsoft Windows Kernel (Win32k) CVE-2016-0040 is an elevation-of-privilege flaw in the Microsoft Windows kernel's kernel-mode drivers (win32k) that a local user can exploit by running a specially crafted application. Successful exploitation executes code in kernel mode, effectively granting the attacker SYSTEM-level control of the host — typically used to climb from an initial foothold to full system compromise. The flaw is not remotely exploitable on its own; it requires pre-existing local code execution, so it is usually chained after an RCE, a malware dropper, or malicious user activity. At disclosure it affected all mainstream Windows releases of the era — Windows Vista/Server 2008 through Windows 10 (1511 and earlier)/Server 2012 R2 — patched via Microsoft's January 2016 kernel-mode driver bulletin (MS16-005) and included in all later cumulative updates, so the realistic residual exposure is legacy Windows estates that never applied those patches (end-of-support Windows 7, Server 2008/2012). CISA added it to the KEV catalog on 2022-03-28, confirming in-the-wild exploitation; it also ranks in the 98th EPSS percentile (24.5% chance of exploitation activity in 30 days), though no public PoC is catalogued and ransomware use is unknown. Do: Verify that every Windows host has Microsoft's January 2016 kernel-mode driver update (MS16-005) or a later cumulative update installed — any modern Windows 10/11 patch level includes the fix, so prioritize legacy Windows 7, Server 2008/2008 R2, and Server 2012/2012 R2 systems, including ESU-enrolled and fully unpatched machines. Because exploitation requires local code execution, patch first where untrusted users run applications or where RDP/terminal services are exposed. CISA's required action is to apply updates per vendor instructions; where patching is not possible, restrict local logon rights and limit untrusted users on affected hosts. | 7.8 | 24% | KEV PoC |
| massApproximately hundreds of millions of Windows devices at the January 2016 patch date (every mainstream release was affected); residual unpatched exposure today… | |
| CVE-2016-0063 | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0060, CVE-2016-0061, CVE-2016-0067, and CVE-2016-0072. NVD description · AI analysis pending | 8.8 group max | 39% | PoC ×2 |
| — | |
| CVE-2016-0044 | Sync Framework in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows remote attackers to cause a denial of service (SyncShareSvc service o Sync Framework in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows remote attackers to cause a denial of service (SyncShareSvc service outage) via crafted "change batch" data, aka "Windows DLL Loading Denial of Service Vulnerability." NVD description · AI analysis pending | 7.5 | 14% |
| — | ||
| CVE-2016-0050 | Network Policy Server (NPS) in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 misparses username queries, which allows remote attacker Network Policy Server (NPS) in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 misparses username queries, which allows remote attackers to cause a denial of service (RADIUS authentication outage) via crafted requests, aka "Network Policy Server RADIUS Implementation Denial of Service Vulnerability." NVD description · AI analysis pending | 5.3 | 18% |
| — | ||
| CVE-2016-0052 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps Server 2013 SP1, and SharePoint Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0022. NVD description · AI analysis pending | 7.8 | 19% |
| — | ||
| CVE-2016-0060 | Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) vi Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0061, CVE-2016-0063, CVE-2016-0067, and CVE-2016-0072. NVD description · AI analysis pending | 8.8 group max | 27% |
| — |
Full article781 words · extracted from blog.talosintelligence.com · click to collapse
Tuesday, February 9, 2016 15:59
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release contains twelve bulletins addressing 37 vulnerabilities. Five bulletins are rated critical and address vulnerabilities in Internet Explorer, Edge, Windows Journal, Office and Windows PDF. The remaining seven bulletins are rated important and address vulnerabilities in the Network Policy Server (NPS), Active Directory, Windows, Remote Desktop Protocol, WebDAV, Kernel Mode Driver and the .NET Framework.
Bulletins Rated Critical
Microsoft bulletins MS16-009, MS16-011 through MS16-013, and MS16-015 are rated as critical in this month's release.
MS16-009 and MS16-011 are this month's Internet Explorer and Edge security bulletin respectively. In total, sixteen vulnerabilities were addressed with four vulnerabilities impacting both browsers. The vulnerabilities impacting both browsers include three critical memory corruption issues (CVE-2016-0060, CVE-2016-0061 and CVE-2016-0062) along with CVE-2016-0077 that addresses a critical spoofing vulnerability.
- MS16-009 is the IE bulletin for IE versions 9 through 11. Three critical memory corruption issues specific to Internet Explorer are addressed (CVE-2016-0063, CVE-2016-0067 and CVE-2016-0072).
- MS16-011 is the Edge bulletin. A critical memory corruption issues specific to Edge is addressed (CVE-2016-0084). MS16-012 addresses two vulnerabilities in the Microsoft Windows PDF Library. CVE-2016-0058 is a buffer overflow vulnerability invoked when the PDF Library improperly handles application programming interface (API) calls. CVE-2016-0046 is a remote code execution vulnerability that can be exploited by convincing the user to open a specially crafted file in Windows Reader.
MS16-013 addresses a single vulnerability in Windows Journal. CVE-2016-0038 is a memory corruption issue. An attacker who tricks a user into opening a specially crafted journal file and successfully exploits this vulnerability can cause arbitrary code execution.
MS16-015 is this month’s Microsoft Office bulletin. CVE-2016-0052 and CVE-2016-0053 are critical while the other five vulnerabilities are rated important. Three vulnerabilities (CVE-2016-054, CVE-2016-0055 and CV-2016-2016-0056) involve memory corruption that can be exploited if a user opens a crafted file. Three other vulnerabilities (CVE-2016-0022, CVE-2016-0052 and CVE-2016- 0053) also involve memory corruption but they can be exploited by either opening a file or through the preview pane. CVE-2016-039 addresses an elevation of privilege vulnerability when SharePoint does not properly sanitize web requests. An authenticated attacker could exploit this vulnerability perform cross-site scripting attacks and running scripts on the server.
Bulletins Rated Important
Microsoft bulletins MS16-014 and MS16-016 through MS16-021 are rated as important in this month's release.
MS16-014 addresses five vulnerabilities in Microsoft Windows impacting all supported releases. CVE-2016-0040 addresses a privilege escalation issue. Three vulnerabilities involve issues related to loading dynamic link libraries. CVE-2016-0041 & CVE-2016-0042 address remote code execution vulnerabilities while CVE-2016-0044 addresses a denial of service issue. Finally, CVE-2016-0049 addresses a kerberos security feature bypass that would allow an attacker to bypass Kerberos authentication on a target machine and decrypt the drive protected by BitLocker.
MS16-016 addresses a single privilege escalation vulnerability (CVE-2016-0051) in the Microsoft Web Distributed Authoring and Versioning (WebDAV) client.
MS16-017 addresses a single privilege escalation vulnerability (CVE-2016-0036) in the Remote Desktop Protocol (RDP). An authenticated attacker could then send crafted traffic to cause a crash condition that leads to elevated privileges.
MS16-018 addresses a single Windows Kernel Mode Driver privilege escalation vulnerability (CVE-2016-0048). An authenticated attacker could take control of an affected system by logging onto the system and running a specially crafted application.
MS16-019 addresses two vulnerabilities in Microsoft .NET Framework. CVE-2016-0033 is a stack overflow denial of service vulnerability that involves the attacker sending to the server a specially crafted XSLT (Extensible Stylesheet Language Transformation) that would cause the server to recursively compile the XLST transformation. CVE-2016-0047 is an information disclosure vulnerability that allows an attacker to retrieve information using a specially crafted icon.
MS16-020 addresses a single vulnerability in Active Directory Federation Services (ADFS). CVE-2016-0037 is a denial of service vulnerability which manifests when ADFS fails to properly process certain input during forms-based authentication. An attacker who exploits this vulnerability could cause the server to become unresponsive.
MS16-021 addresses a single vulnerability in the Microsoft Windows Network Policy Server (NPS) using RADIUS. CVE-2016-0050 is a denial of service flaw which manifests due to the improper handling of RADIUS authentication requests. An unauthenticated attacker who exploits this vulnerability could transmit specially crafted username strings to a Network Policy Server (NPS) and trigger a denial of service condition for RADIUS authentication on the NPS.
Coverage
In response to these bulletin disclosures, Talos is releasing the following rules to address these vulnerabilities. Please note that additional rules may be released at a future date and current rules are subject to change pending additional vulnerability information. For the most current rule information, please refer to your Defense Center, FireSIGHT Management Center or Snort.org.
Snort SIDs: 37553-37617
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/ms-tuesday-63063210e63ef5e7e1ec315a/