Microsoft Update Tuesday September 2014: another generally light month but with a significant IE bulletin
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2013-7331 | Information Disclosure in Microsoft Internet Explorer Lets Pages Detect Anti-Malware CVE-2013-7331 is an information disclosure flaw (CWE-200) in Microsoft Internet Explorer in which resources loaded into memory can be queried by web content. An attacker triggers it by luring a user to a malicious or compromised webpage whose crafted script probes memory-resident resources, requiring no authentication and no interaction beyond ordinary browsing. What the attacker gains is knowledge of which anti-malware applications are installed on the victim, information commonly used for victim fingerprinting; related coverage of the Nuclear exploit kit reflects how exploit kits leveraged this kind of security-product detection to tailor or withhold follow-on exploits. Any Microsoft Internet Explorer deployment is affected; the provided data does not specify exact version ranges, and the flaw was addressed in Microsoft's significant September 2014 Internet Explorer security bulletin. Exploitation is confirmed in the wild: the flaw was added to the CISA KEV catalog on 2022-05-25 with a high EPSS of 58% (99th percentile), though ransomware association is listed as unknown and no public proof-of-concept is known. Do: Apply Microsoft's September 2014 Internet Explorer security updates (or any later cumulative IE updates) per vendor instructions, as required by the CISA KEV catalog, and audit for Windows systems still running unpatched IE builds. Prioritize general-purpose browsing and internet-facing endpoints since the flaw is used to fingerprint victims, and migrate any remaining legacy Internet Explorer usage to a supported browser such as Microsoft Edge (with IE mode for legacy dependencies). | — | 58% | KEV |
| masshundreds of millions of Windows devices with Internet Explorer installed |
Full article370 words · extracted from blog.talosintelligence.com · click to collapse
Tuesday, September 9, 2014 13:04
This month’s Microsoft Update Tuesday is pretty light save for the Internet Explorer bulletin. While there’s only a total of 4 bulletins, they cover a total of 42 CVEs. The IE bulletin, as is usual, has the most updates for bugs and is rated critical. It covers a total of 37 CVEs. The other three bulletins are rated as important and provide updates for the remaining five vulnerabilities.
MS14-052 is the IE bulletin and is rated critical. It covers a total of 37 CVEs. Of these 37 CVEs, 36 are remote code execution vulnerabilities, the other one is an information disclosure vulnerability (CVE-2013-7331). This last vulnerability is publicly known and under active exploitation. This vulnerability allows attackers to use Microsoft’s XMLDOM ActiveX object to gain information on local drive and network settings. The attack can be used to detect if files or folders are present on the machine due to different error messages being returned depending on if the files or folder exist or not. An attacker can similarly figure out internal IP addresses using this vulnerability. The remaining 36 vulnerabilities are mostly the result of use-after-free vulnerabilities.
The three remaining bulletins are all rated as important:
Bulletin MS14-053 deals with a single CVE (CVE-2014-4072) in .NET. The vulnerability results in a Denial of Service. This is due to a hash collision that can be exploited by an attacker, which will result in resource exhaustion.
CVE-2014-4074 is fixed by bulletin MS14-054, it deals with a vulnerability in the Windows Task Scheduler that could allow a logged on user to schedule a task that would run code at the system level.
The final bulletin is MS14-055 and fixes three vulnerabilities in Lync. Two of the vulnerabilities, CVE-2014-4068 and CVE-2014-4071, could result in Denial of Services. An attacker could create a legitimate meeting and then modify the SIP information, which would result in a DoS on the Lync server. The third vulnerability that is covered by this bulletin is CVE-2014-4070 and can result in information disclosure due to a Cross Site Scripting (XSS) vulnerability on the server.
To address these issues, Talos has the following SIDs: 29821-29822, 30110-30113, 31782-31797, 31799-31802, 31811-31812
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-update-tuesday-september-2014/