ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

November 2020 Patch Tuesday: Microsoft fixes actively exploited Windows Kernel flaw

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-17040
Windows Hyper-V Security Feature Bypass Vulnerability

Windows Hyper-V Security Feature Bypass Vulnerability

NVD description · AI analysis pending
6.53%
  • microsoft windows 10
  • microsoft windows 8.1
  • microsoft windows server 2012
  • +1 more
CVE-2020-17051
Windows Network File System Remote Code Execution Vulnerability

Windows Network File System Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.811%
  • microsoft windows server 2008
  • microsoft windows server 2012
  • microsoft windows server 2016
  • +1 more
CVE-2020-17084
Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.54%
  • microsoft exchange server
CVE-2020-17087
Windows Kernel Buffer Overflow Enables Local Privilege Escalation (CVE-2020-17087)

CVE-2020-17087 is a local elevation-of-privilege flaw in the Windows kernel caused by an incorrect buffer size calculation (CWE-131), producing a kernel buffer overflow; public analyses from Microsoft and Google's disclosure place the vulnerable code in the kernel's cryptographic driver (cng.sys). A local attacker with low privileges can trigger the overflow without user interaction, gaining code execution in kernel context and effectively full control of the host (high impact on confidentiality, integrity, and availability; CVSS 7.8). Every Windows system on the affected builds is exposed: Windows 10 versions 1507 through 20H2, Windows 7, 8.1, RT 8.1, and Windows Server 2008, which at disclosure meant essentially the entire supported Windows install base. The flaw was exploited as a zero-day in the wild: Google disclosed its use in targeted attacks, reportedly chained with a Chrome zero-day, and CISA added it to the KEV catalog on 2021-11-03; EPSS currently estimates a 5.4% probability of exploitation within 30 days (92nd percentile), with ransomware association listed as unknown.

Do: Apply Microsoft's November 2020 Patch Tuesday security updates to all affected Windows 10, Windows 7, 8.1, RT 8.1, and Windows Server 2008 systems; this is CISA's required action for the KEV listing and no official workaround is known. Prioritize hosts where untrusted users can log on locally or via RDP, and ensure Chromium-based browsers are fully updated since this kernel bug was reportedly chained with a Chrome zero-day. After patching, verify the November 2020 update is installed; treat any ransomware association as currently unconfirmed.

7.85% KEV
  • microsoft Windows 10 1507, 1607, 1803, 1809, 1903, 1909, 2004, 20H2
  • microsoft Windows 7
  • microsoft Windows 8.1
  • +2 more
mass≈1 billion+ devices (essentially the entire supported Windows install base at disclosure)
CVE-2020-26950
In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition.

In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox < 82.0.3, Firefox ESR < 78.4.1, and Thunderbird < 78.4.2.

NVD description · AI analysis pending
8.842% PoC ×2
  • mozilla firefox
  • mozilla firefox esr
  • mozilla thunderbird
Full article768 words · extracted from helpnetsecurity.com · click to collapse

On this November 2020 Patch Tuesday:

  • Microsoft has plugged 112 security holes, including an actively exploited one
  • Adobe has delivered security updates for Adobe Reader Mobile and Adobe Connect
  • Intel has dropped a huge stack of security advisories and patches
  • SAP has released 12 security notes and updated three previously released ones
  • Mozilla has fixed a critical vulnerability affecting Firefox, Firefox ESR, and Thunderbird

November 2020 Patch Tuesday

Microsoft’s updates

Microsoft plugged 112 CVE-numbered flaws in a variety of its products. Of these, 17 are Critical, 93 as Important, and two are Low in severity.

Microsoft has changed the way it describes fixed vulnerabilities, and the new advisories unfortunately hold less information than before – information that may be crucial for admins to asses which patches are to be prioritized.

So this month, the most information is available about CVE-2020-17087, a Windows Kernel privilege escalation vulnerability, because it’s being actively exploited in the wild (together with a Chrome bug) and because Google disclosed it on October 29, along with PoC exploit code.

“While not explicitly stated, the language used makes it seem the exploit is not yet widespread. However, considering there is a full analysis of the bug weeks before the patch, it will likely be incorporated into other exploits quickly,” noted Trend Micro Zero Day Initiative’s Dustin Childs.

He also picked out a few other interesting vulnerabilities fixed by Microsoft this November 2020 Patch Tuesday:

  • CVE-2020-17051 – a critical Windows Network File System RCE flaw requires no user interaction and calls for low attack complexity, and may be wormable
  • CVE-2020-17040 – a Windows Hyper-V Security feature bypass vulnerability
  • CVE-2020-17084 – a RCE in Microsoft Exchange Server

The Critical vulnerabilities fixed this month are found in various image and video extensions (HEIF, HEVC, Raw Image, AV1), which the Microsoft Store will automatically update for affected customers. Others affect the Windows Print Spooler, the Chakra Scripting Engine, Internet Explorer, Edge, and Azure Sphere.

Microsoft has also patched many other Important vulnerabilities in Azure Sphere this month but, as Childs pointed out, since IoT devices running Azure Sphere are connected to the Internet and check for updates every day, patches for those have likely already been seamlessly implemented.

Adobe’s updates

Adobe has published two security bulletins, both for important (but not critical) vulnerabilities in Adobe Reader Mobile and Adobe Connect.

The Adobe Reader Mobile update fixes a single information disclosure bug. The Adobe Connect updates, which fix two vulnerabilities that may allow arbitrary JavaScript execution in the browser, will be staggered: for hosted services, the update is already available, for on-premise deployments it will be available from November 13.

None of the vulnerabilities are under active attack and the affected products have historically not been a target for attackers, so admins can prioritize other more critical updates and leave these for last.

Intel’s updates

Intel took advantage of the November 2020 Patch Tuesday to released a mammoth batch of advisories, covering vulnerabilities in drivers, server boards, various software, firmware, drones, BIOS, and so on.

Some advisories link to updates, some announced that there will be no security updates because the product is discontinued.

Two advisories cover issues that are deemed critical:

  • For Intel CSME, SPS, TXE, AMT and DAL – among the fixed flaws is an out-of-bounds write flaw in IPv6 subsystem that may allow an unauthenticated user to potentially enable escalation of privileges via network access
  • For Intel Wireless Bluetooth products – one of the fixed flaws is an improper buffer restriction that may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

It also has to be noted that Intel has fixed two flaws that may allow new side-channel attacks that may result in the attacker accessing sensitive data on Intel CPUs.

SAP’s updates

For November 2020 Patch Tuesday, SAP released 12 security notes and updated three previously released ones (for SAP Solution Manager, SAP NetWeaver, SAP Bank Analyzer and SAP S/4HANA Financial Products).

The most critical patches are for missing authentication check vulnerabilities in SAP Solution Manager (an integrated end-to-end platform intended to assist users in adopting new developments, managing the application lifecycle, and running SAP solutions) and a RCE flaw in SAP Data Services (an enterprise-class solution for data integration, data quality, data profiling, and text data processing).

Mozilla’s updates

Mozilla has released security updates to address a critical vulnerability (CVE-2020-26950) in Firefox, Firefox ESR, and Thunderbird.

They did not reveal many details about it, only that it may result in an exploitable use-after-free condition and that it has been revealed by a participant in the recently held Tianfu Cup 2020 International Cybersecurity Contest.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2020/11/10/november-2020-patch-tuesday/