ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-0547
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka "Windows DHCP Clien

A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka "Windows DHCP Client Remote Code Execution Vulnerability." This affects Windows 10, Windows 10 Servers.

NVD description · AI analysis pending
9.8
group max
71%
  • microsoft windows 10
CVE-2019-0537
An information disclosure vulnerability exists when Visual Studio improperly discloses arbitrary file contents if the victim opens a malicious .vscontent file,

An information disclosure vulnerability exists when Visual Studio improperly discloses arbitrary file contents if the victim opens a malicious .vscontent file, aka "Microsoft Visual Studio Information Disclosure Vulnerability." This affects Microsoft Visual Studio.

NVD description · AI analysis pending
5.58%
  • microsoft visual studio
CVE-2019-0585
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft Word Remote Code Exec

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Microsoft SharePoint, Microsoft Office Online Server, Microsoft Word, Microsoft SharePoint Server.

NVD description · AI analysis pending
8.8
group max
22%
  • microsoft office
  • microsoft office 365 proplus
  • microsoft office online server
  • +1 more
CVE-2019-0539
+2 in the same advisory: …0567 …0568
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engi

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2019-0567, CVE-2019-0568.

NVD description · AI analysis pending
7.583% PoC ×3
  • microsoft chakracore
  • microsoft edge
CVE-2019-0541
Remote Code Execution in Microsoft MSHTML Engine (Office and Internet Explorer)

CVE-2019-0541 is a remote code execution vulnerability caused by improper input validation in Microsoft's MSHTML engine, the component that renders HTML content inside Internet Explorer and embedded objects in Office documents. It is triggered when a user opens attacker-crafted content, such as a malicious web page viewed in Internet Explorer or a specially crafted Office document, and requires no privileges but does require user interaction (CVSS 3.1 vector AV:N/AC:L/PR:N/UI:R). A successful attacker gains arbitrary code execution in the context of the current user, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score of 8.8). Affected products include Internet Explorer 9, 10, and 11, Microsoft Office including Office 365 ProPlus, and the legacy Office Word Viewer and Excel Viewer, meaning virtually any Windows environment using these components is exposed. The flaw has been exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 and a public proof of concept exists — EPSS estimates a 53.2% probability of exploitation within 30 days (99th percentile), and it was fixed in Microsoft's January 2019 Patch Tuesday updates.

Do: Apply Microsoft's January 2019 Patch Tuesday security updates immediately across all Windows, Internet Explorer, and Office installations (including Office 365 ProPlus), prioritizing endpoints required by CISA KEV's stated action to apply updates per vendor instructions. Remove or replace the end-of-life Office Word Viewer and Excel Viewer, and reduce reliance on Internet Explorer while warning users not to open untrusted documents or links, since user interaction is required for exploitation. Hunt for signs of compromise on unpatched systems, as the KEV listing confirms in-the-wild exploitation (ransomware use: unknown).

8.853% KEV PoC
  • Microsoft Internet Explorer 9, 10, and 11
  • Microsoft Office
  • Microsoft Office 365 ProPlus
  • +2 more
masshundreds of millions of endpoints (Internet Explorer 9–11 and Office are standard on most Windows systems; Office alone has on the order of 1 billion installs)
CVE-2019-0543
Local Privilege Escalation (Improper Authentication) in Windows 7/8.1/10 and Server

CVE-2019-0543 is an elevation-of-privilege flaw (CWE-287, improper authentication) that exists when Windows improperly handles authentication requests, affecting Windows 7, 8.1, RT 8.1, Windows 10 builds 1507 through 1809, and Windows Server 2008 through 2019. A local attacker who can already execute low-privileged code on a target machine can trigger the mishandled authentication handling with no user interaction and no special conditions (CVSS:3.1 AV:L/AC:L/PR:L/UI:N). Successful exploitation yields full control of the local system, with high confidentiality, integrity, and availability impact, so it is typically chained after an initial foothold such as phishing or malware. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-15 and notes known ransomware use; a public proof of concept is available (Exploit-DB 46156), and EPSS estimates a ~4.7% chance of exploitation in the next 30 days (91st percentile).

Do: Apply Microsoft's January 2019 Patch Tuesday security updates (or any later cumulative update) across all affected Windows 7, 8.1, and 10 clients and Windows Server 2008-2019 hosts; organizations on Windows 7/Server 2008 R2 need Extended Security Update (ESU) coverage if still unpatched. Prioritize domain controllers, file servers, and internet-facing endpoints given the CISA KEV listing and known ransomware use, and since this is a post-foothold privilege escalation, also verify the initial-access vector (RCE/phishing) is remediated and monitor for local privilege-escalation activity.

7.85% KEV ransomware PoC
  • Microsoft Windows 10 1507, 1607, 1703, 1709, 1803, 1809
  • Microsoft Windows 10 Servers Server 2016, Server 2019, version 1709, version 1803
  • Microsoft Windows 7
  • +9 more
masshundreds of millions of devices (~10^8-10^9): effectively every Windows 7/8.1/10 client or Windows Server 2008-2019 host that lacked the January 2019 updates
CVE-2019-0545
An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka "

An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7/4.7.1/4.7.2, .NET Core 2.1, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 2.2, Microsoft .NET Framework 4.7.2.

NVD description · AI analysis pending
7.510%
  • microsoft .net framework
  • microsoft .net core
CVE-2019-0546
A remote code execution vulnerability exists in Visual Studio when the C++ compiler improperly handles specific combinations of C++ constructs, aka "Visual Stud

A remote code execution vulnerability exists in Visual Studio when the C++ compiler improperly handles specific combinations of C++ constructs, aka "Visual Studio Remote Code Execution Vulnerability." This affects Microsoft Visual Studio.

NVD description · AI analysis pending
7.816%
  • microsoft visual studio 2017
CVE-2019-0564
+1 in the same advisory: …0548
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP

A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548.

NVD description · AI analysis pending
7.58%
  • microsoft asp.net core
CVE-2019-0557
+1 in the same advisory: …0556
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected Sha

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2019-0556, CVE-2019-0558.

NVD description · AI analysis pending
5.42%
  • microsoft sharepoint server
CVE-2019-0558
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected Sha

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint, Microsoft Business Productivity Servers. This CVE ID is unique from CVE-2019-0556, CVE-2019-0557.

NVD description · AI analysis pending
5.42%
  • microsoft business productivity servers
  • microsoft sharepoint server
CVE-2019-0562
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected ShareP

An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint.

NVD description · AI analysis pending
5.42%
  • microsoft sharepoint enterprise server
  • microsoft sharepoint server
CVE-2019-0566
+1 in the same advisory: …0565
An elevation of privilege vulnerability exists in Microsoft Edge Browser Broker COM object, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affe

An elevation of privilege vulnerability exists in Microsoft Edge Browser Broker COM object, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge.

NVD description · AI analysis pending
8.8
group max
19% PoC
  • microsoft edge
CVE-2019-0586
+1 in the same advisory: …0588
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchang

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server.

NVD description · AI analysis pending
9.8
group max
15%
  • microsoft exchange server
CVE-2019-0622
An elevation of privilege vulnerability exists when Skype for Andriod fails to properly handle specific authentication requests, aka "Skype for Android Elevatio

An elevation of privilege vulnerability exists when Skype for Andriod fails to properly handle specific authentication requests, aka "Skype for Android Elevation of Privilege Vulnerability." This affects Skype 8.35.

NVD description · AI analysis pending
4.62%
  • microsoft skype
Full article986 words · extracted from securityaffairs.com · click to collapse

Microsoft has released the January 2019 Patch Tuesday updates that address 51 vulnerabilities in Windows OSs and other products.

Microsoft has released Microsoft January 2019 Patch Tuesday that solve 51 vulnerabilities in Windows operating system and in the following solutions:

  • Adobe Flash Player
  • Internet Explorer
  • Microsoft Edge
  • Microsoft Windows
  • Microsoft Office and Microsoft Office Services and Web Apps
  • ChakraCore
  • .NET Framework
  • ASP.NET
  • Microsoft Exchange Server
  • Microsoft Visual Studio

A close look at the list of issues addressed with the Microsoft January 2019 Patch Tuesday reveals that 7 flaws are rated critical, none was exploited in attacks in the wild.

The vulnerabilities rated as critical could be exploited by attackers for remote code execution, most of them affect Windows 10 and Server editions.

Three out of seven critical issues affect the ChakraCore scripting engine in the Edge browser, two affect Microsoft’s Hyper-V server virtualization environment, one impacts Edge, and one affects the Windows DHCP client.

The CVE-2019-0547 vulnerability resides in the Mitch Adair of the Microsoft Windows Enterprise Security Team, it could be exploited by an attacker to send a specially crafted DHCP response to a client in order to perform arbitrary code execution.

“A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client. An attacker who successfully exploited the vulnerability could run arbitrary code on the client machine.” reads the security advisory.

“To exploit the vulnerability, an attacker could send a specially crafted DHCP responses to a client. The security update addresses the vulnerability by correcting how Windows DHCP clients handle certain DHCP responses.”

Other two Windows Hyper-V vulnerabilities (CVE-2019-0550 & CVE-2019-0551) can lead to remotely execute code on the host.

“A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system.” reads the security advisory related to the
CVE-2019-055 issue. “To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary code.”

Only one of the issues addressed with Microsoft January 2019 Patch Tuesday that resides in the Microsoft JET Database Engine was publicly known, but it was not exploited in the wild.
The flaw tracked as CVE-2019-0579 and rated as important could be exploited to execute arbitrary code on a target’s system by tricking users into opening a specially-crafted file.

The tech giant also fixed a vulnerability in Skype for Android (CVE-2019-0622) that could have allowed a local attacker with physical access to an Android device to bypass the lock screen and potentially expose victim’s data.

Below there is the full list of vulnerabilities addressed by the Microsoft January 2019 Patch Tuesday.

TagCVE IDCVE Title
.NET FrameworkCVE-2019-0545.NET Framework Information Disclosure Vulnerability
Adobe Flash PlayerADV190001January 2019 Adobe Flash Update
Android AppCVE-2019-0622Skype for Android Elevation of Privilege Vulnerability
ASP.NETCVE-2019-0548ASP.NET Core Denial of Service Vulnerability
ASP.NETCVE-2019-0564ASP.NET Core Denial of Service Vulnerability
Internet ExplorerCVE-2019-0541MSHTML Engine Remote Code Execution Vulnerability
Microsoft EdgeCVE-2019-0565Microsoft Edge Memory Corruption Vulnerability
Microsoft EdgeCVE-2019-0566Microsoft Edge Elevation of Privilege Vulnerability
Microsoft Exchange ServerCVE-2019-0586Microsoft Exchange Memory Corruption Vulnerability
Microsoft Exchange ServerCVE-2019-0588Microsoft Exchange Information Disclosure Vulnerability
Microsoft JET Database EngineCVE-2019-0576Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2019-0538Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2019-0575Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2019-0577Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2019-0582Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2019-0583Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2019-0584Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2019-0581Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2019-0578Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2019-0579Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2019-0580Jet Database Engine Remote Code Execution Vulnerability
Microsoft OfficeCVE-2019-0560Microsoft Office Information Disclosure Vulnerability
Microsoft OfficeCVE-2019-0561Microsoft Word Information Disclosure Vulnerability
Microsoft OfficeCVE-2019-0585Microsoft Word Remote Code Execution Vulnerability
Microsoft OfficeCVE-2019-0559Microsoft Outlook Information Disclosure Vulnerability
Microsoft Office SharePointCVE-2019-0562Microsoft SharePoint Elevation of Privilege Vulnerability
Microsoft Office SharePointCVE-2019-0556Microsoft Office SharePoint XSS Vulnerability
Microsoft Office SharePointCVE-2019-0558Microsoft Office SharePoint XSS Vulnerability
Microsoft Office SharePointCVE-2019-0557Microsoft Office SharePoint XSS Vulnerability
Microsoft Scripting EngineCVE-2019-0568Chakra Scripting Engine Memory Corruption Vulnerability
Microsoft Scripting EngineCVE-2019-0567Chakra Scripting Engine Memory Corruption Vulnerability
Microsoft Scripting EngineCVE-2019-0539Chakra Scripting Engine Memory Corruption Vulnerability
Microsoft WindowsCVE-2019-0574Windows Data Sharing Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2019-0573Windows Data Sharing Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2019-0571Windows Data Sharing Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2019-0572Windows Data Sharing Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2019-0543Microsoft Windows Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2019-0570Windows Runtime Elevation of Privilege Vulnerability
Microsoft XMLCVE-2019-0555Microsoft XmlDocument Elevation of Privilege Vulnerability
Servicing Stack UpdatesADV990001Latest Servicing Stack Updates
Visual StudioCVE-2019-0537Microsoft Visual Studio Information Disclosure Vulnerability
Visual StudioCVE-2019-0546Visual Studio Remote Code Execution Vulnerability
Windows COMCVE-2019-0552Windows COM Elevation of Privilege Vulnerability
Windows DHCP ClientCVE-2019-0547Windows DHCP Client Remote Code Execution Vulnerability
Windows Hyper-VCVE-2019-0550Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-VCVE-2019-0551Windows Hyper-V Remote Code Execution Vulnerability
Windows KernelCVE-2019-0569Windows Kernel Information Disclosure Vulnerability
Windows KernelCVE-2019-0536Windows Kernel Information Disclosure Vulnerability
Windows KernelCVE-2019-0554Windows Kernel Information Disclosure Vulnerability
Windows KernelCVE-2019-0549Windows Kernel Information Disclosure Vulnerability
Windows Subsystem for LinuxCVE-2019-0553Windows Subsystem for Linux Information Disclosure Vulnerability
[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs –  Cybersecurity, Microsoft January 2019 Patch Tuesday)

[adrotate banner=”5″] [adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/79671/security/january-2019-patch-tuesday.html