Microsoft hurries to patch 'worst' Windows vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-0920 | GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::Creat GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance. NVD description · AI analysis pending | 4.3 | <1% |
| — |
Full article661 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Microsoft has rushed out a self-installing patch for a vulnerability in a Windows security program that allows hackers to take over a computer just by sending an email.
Microsoft has rushed out a self-installing patch for a zero-day vulnerability in a Windows security program that allows hackers to take over a computer just by sending an email.
“The update addresses a vulnerability that could allow remote code execution if the Microsoft Malware Protection Engine scans a specially crafted file,” reads the advisory about the patch Microsoft issued Monday.
That means hackers can exploit the flaw simply by sending an email with a specially designed attachment. As soon as the malware engine scans the attachment, the code opens the vulnerability and the attacker can take control.
Remote code execution bugs are considered the most severe kind of security vulnerability, and flaws in security software are often especially bad because of its trusted status on the machine.
The Microsoft security advisory said there was no evidence the vulnerability— designated CVE-2017-0920 — “had been publicly used to attack customers” at the time of publication.
The company added that no action would be needed by end-users to apply the patch, since the security software automatically updates itself.
“Typically, no action is required of enterprise administrators or end users to install updates for the Microsoft Malware Protection Engine, because the built-in mechanism for the automatic detection and deployment of updates will apply the update within 48 hours,” states the advisory.
“The exact time frame depends on the software used, Internet connection, and infrastructure configuration.”
The bug was discovered by Google Project Zero researchers, who said — in a coordinated disclosure — that the target wouldn’t even have to open the attachment or read the email. Because the Malware Protection Engine, or “mpengine” is designed to stop bad code before it executes, it has a “filesystem mini-filter to intercept and inspect all system … activity,” so anytime the computer starts writing data “to anywhere on disk (e.g. caches, temporary internet files, downloads — even unconfirmed downloads — attachments, etc)” the engine’s functionality, thus its vulnerability, is accessed.
This means, explained Project Zero bug hunters Natalie Silvanovich and Tavis Ormandy, that “On workstations, attackers can access mpengine by sending emails to users (reading the email or opening attachments is not necessary)…”
Ormandy dropped a hint about the forthcoming disclosure late Friday night in a tweet: I think [Silvanovich] and I just discovered the worst Windows remote code exec[ution flaw] in recent memory. This is crazy bad. Report on the way.”
On Monday, Ormandy praised Microsoft for its response:
Still blown away at how quickly @msftsecurity responded to protect users, can't give enough kudos. Amazing.
— Tavis Ormandy (@taviso) May 9, 2017
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-hurries-patch-worst-windows-vulnerability/