August 2019 Patch Tuesday: Microsoft plugs critical wormable RDP holes
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-1181 | A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would need to send a specially crafted request to the target systems Remote Desktop Service via RDP. The update addresses the vulnerability by correcting how Remote Desktop Services handles connection requests. NVD description · AI analysis pending | 9.8 group max | 76% |
| — | ||
| CVE-2019-1201 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. The file could then take actions on behalf of the logged-on user with the same permissions as the current user. To exploit the vulnerability, a user must open a specially crafted file with an affected version of Microsoft Word software. Two possible email attack scenarios exist for this vulnerability: • With the first email attack scenario, an attacker could send a specially crafted email message to the user and wait for the user to click on the message. When the message renders via Microsoft Word in the Outlook Preview Pane, an attack could be triggered. • With the second scenario, an attacker could attach a specially crafted file to an email, send it to a user, and convince them to open it. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file that is designed to exploit the vulnerability. However, an attacker would have no way to force the user to visit the website. Instead, an attacker would have to convince the user to click a link, typically by way of an enticement in an email or other message, and then convince the user to open the specially crafted file. The security update addresses the vulnerability by correcting how Microsoft Word handles files in memory. For users who view their emails in Outlook, the Preview Pane attack vector can be mitigated by disabling this feature. The following registry keys can be set to disable the Preview Pane in Outlook on Windows, either via manual editing of the registry or by modifying Group Policy. Note Using Registry Editor incorrectly can cause serious problems that may require you to reinstall your operating system. Microsoft cannot guarantee that problems resulting from the incorrect use of Registry Editor can be solved. Use Registry Editor at your own risk. For information about how to edit the registry, view the "Changing Keys and Values" Help topic in Registry Editor (Regedit.exe) or view the "Add and Delete Information in the Registry" and "Edit Registry Data" Help topics in Regedt32.exe. Outlook 2010: HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Options DWORD: DisableReadingPane Value: 1 Outlook 2013: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Options DWORD: DisableReadingPane Value: 1 Outlook 2016, Outlook 2019, and Office 365 ProPlus: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Options DWORD: DisableReadingPane Value: 1 NVD description · AI analysis pending | 7.8 | 5% |
| — |
Full article761 words · extracted from helpnetsecurity.com · click to collapse
It’s that time of the month again: Microsoft, Adobe and Intel have pushed out fixes for a bucketload of security issues in their various software.

Microsoft’s security updates should take precedence, though, as they fix 29 critical vulnerabilities, including four in Remote Desktop Services, two of which – Microsoft warns – are wormable, just like BlueKeep before them.
Microsoft patches
Microsoft has plugged 93 CVEs and has released two advisories – one recommends a new set of safe default configurations for LDAP channel binding and LDAP signing on Active Directory Domain Controllers, the other makes it known that the company has mitigated an elevation of privilege vulnerability in Outlook Web Access, which could have allowed attackers to access a target’s email inbox.
The fixed vulnerabilities of note this time are:
CVE-2019-1181 and CVE-2019-1182 – two RDP unauthenticated remote code execution flaws that can be widely exploited through worms, without any user interaction. They affect Windows 7 SP1, Windows Server 2008 R2 SP1, Windows Server 2012, Windows 8.1, Windows Server 2012 R2, and all supported versions of Windows 10, including server versions.
“These vulnerabilities were discovered by Microsoft during hardening of Remote Desktop Services as part of our continual focus on strengthening the security of our products. At this time, we have no evidence that these vulnerabilities were known to any third party,” Simon Pope, Director of Incident Response, Microsoft Security Response Center (MSRC), noted.
Aside from implementing the patches, users and admins can mitigate the danger of exploitation by enabling Network Level Authentication (NLA) on affected systems, making the flaws exploitable only if the attacker has valid credentials that can be used to successfully authenticate.
RDP also sports two other similarly critical RCEs (CVE-2019-1222 and CVE-2019-1226), as well as three less critical flaws (CVE-2019-1223, CVE-2019-1224 and CVE-2019-1225) that could lead to DoS and information disclosure. These affect only the newest Windows and Windows Server versions.
CVE-2019-1188 – a LNK remote code execution vulnerability – is similar the one used by Stuxnet. “An attacker could use this vulnerability to get code execution by having an affected system process a specially crafted .LNK file. This could be done by convincing a user to open a remote share, or – as has been seen in the past – placing the .LNK file on a USB drive and having the user open it. It’s a handy way to exploit an air-gapped system,” says Trend Micro ZDI’s Dustin Childs.
CVE-2019-0736, a RCE affecting the Windows DHCP client, is also theoretically wormable, as it doesn’t require authentication or user interaction to be exploited.
There’s also a critical Word flaw: CVE-2019-1201.
“An attacker could exploit this flaw by creating a specially crafted Microsoft Word file and convincing their victim to open the file on a vulnerable system, either by attaching it to a malicious email or hosting it on a malicious website,” Satnam Narang, senior research engineer at Tenable, pointed out.
“Microsoft notes that the Outlook Reading/Preview Pane is an attack vector, meaning the vulnerability could be exploited by merely viewing the email without opening an attachment. Successful exploitation would allow an attacker to perform actions on the system using the same permissions as the current user.”
Finally, CVE-2019-1162 is an old elevation of privilege bug affecting Advanced Local Procedure Call (ALPC). Recently discovered by Google Project Zero researcher Tavis Ormandy, it’s present in all Windows versions since Windows XP and can allow attackers to elevate their privilege on a previously compromised system.
Jimmy Graham, Senior Director of Product Management at Qualys, advises prioritizing Scripting Engine, Browser, Office, Graphics/Font, and LNK patches for workstation-type devices (i.e., any system that is used for email or to access the internet via a browser), including multi-user servers that are used as remote desktops for users.
He also singled out CVE-2019-0720 and CVE-2019-0965, two RCE flaws in Hyper-V and Hyper-V Network Switch, as a patching priority for those systems.
As a sidenote: users of Symantec or Norton security programs will have to wait a bit for the installation of the offered updates, as they still do not support SHA-2 certificates (and Microsoft’s updates are signed with those).
Adobe’s and Intel’s patches
Following a pretty light July Patch Tuesday, Adobe has dropped fixes for a whooping 119 CVEs in its various products.
The Acrobat and Reader updates fix many important flaws (none critical), but the fixed Photoshop CC flaws are mostly critical, so get patching.
Intel’s updates are available here. Take a look to see if you need any of them.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2019/08/14/august-2019-patch-tuesday/