ZeroHour
Cisco Talospublished ()ingested

Microsoft Patch Tuesday for May 2023 — Fewest vulnerabilities disclosed in a month in three

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-24941
Windows Network File System Remote Code Execution Vulnerability

Windows Network File System Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.895%
  • microsoft windows server 2012
  • microsoft windows server 2016
  • microsoft windows server 2019
  • +1 more
CVE-2023-24943
+4 in the same advisory: …29325 …28283 …29324 …24954
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.8
group max
5%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2023-24949
Windows Kernel Elevation of Privilege Vulnerability

Windows Kernel Elevation of Privilege Vulnerability

NVD description · AI analysis pending
7.825%
  • microsoft windows 10 1809
  • microsoft windows 10 20h2
  • microsoft windows 10 21h2
  • +1 more
CVE-2023-24950
Microsoft SharePoint Server Spoofing Vulnerability

Microsoft SharePoint Server Spoofing Vulnerability

NVD description · AI analysis pending
6.567%
  • microsoft sharepoint enterprise server
  • microsoft sharepoint server
CVE-2023-24955
Authenticated Code Injection RCE in Microsoft SharePoint Server (Actively Exploited)

CVE-2023-24955 is a code injection vulnerability (CWE-94) in on-premises Microsoft SharePoint Server that enables remote code execution over the network (CVSS 3.1: 7.2, AV:N/AC:L/PR:H/UI:N). Exploitation requires authentication with high privileges — e.g., a SharePoint site administrator account — and no user interaction, so an attacker who has obtained elevated site credentials can send crafted requests that execute code on the SharePoint server. A successful attacker gains code execution in the context of the SharePoint service, with high impact on confidentiality, integrity, and availability, providing a foothold for lateral movement or ransomware deployment. Organizations running affected on-premises SharePoint Server releases are affected; the flaw was demonstrated at Pwn2Own and Microsoft patched it in the May 2023 Patch Tuesday updates. The bug is now exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-03-26 with known ransomware use, and EPSS places its 30-day exploitation probability at 85.4% (100th percentile).

Do: Apply Microsoft's May 2023 (or later) security updates for SharePoint Server immediately, prioritizing internet-facing servers; CISA's KEV entry requires federal agencies to apply vendor mitigations or discontinue use of the product. Audit and tighten accounts holding SharePoint site-administrator rights, and hunt for signs of exploitation such as unexpected site-admin activity or unusual process launches from SharePoint service accounts. Public reporting on the 2024 exploitation suggests it may be chained with SharePoint privilege-escalation flaw CVE-2023-29357 to achieve unauthenticated access, so ensure both flaws are patched.

7.285% KEV ransomware
  • Microsoft SharePoint Server (on-premises)
  • Microsoft SharePoint Enterprise Server (CPE listing)
large≈ tens of thousands of on-premises SharePoint servers (10k–100k exposed systems)
CVE-2023-29336
Use-after-free privilege escalation to SYSTEM in Microsoft Win32k

CVE-2023-29336 is a use-after-free flaw (CWE-416) in Microsoft's Win32k kernel component that allows privilege escalation to SYSTEM. It is triggered by code running on a Windows host that causes the Win32k driver to reference freed kernel memory; the exact trigger path is not detailed in the available data, but as a kernel elevation-of-privilege issue it requires local code execution or an attacker already holding a foothold on the machine. A successful exploit grants SYSTEM privileges, giving the attacker full control of the compromised host. Because Win32k ships in every supported Windows client and server, effectively the entire Windows installed base is exposed to the flaw. The vulnerability is confirmed exploited in the wild — CISA added it to the KEV catalog on 2023-05-09 — and EPSS places its 30-day exploitation probability at 40.9% (99th percentile), though no public proof-of-concept is known and ransomware use is unconfirmed.

Do: Apply Microsoft's current cumulative Windows security updates (issued May 2023, per the CISA KEV required action) across all Windows clients and servers, prioritizing servers and systems exposed to untrusted users since the flaw is being actively exploited. Until patched, limit untrusted local code execution and restrict remote entry points such as RDP, because local privilege escalation flaws are commonly chained into full compromises. Verify update installation after deployment; specific affected build numbers and any ransomware involvement are not stated in the available data.

7.841% KEV PoC
  • Microsoft Win32k
mass≈1 billion+ Windows devices (Win32k ships in every supported Windows client and server)
Full article526 words · extracted from blog.talosintelligence.com · click to collapse

Tuesday, May 9, 2023 13:47

Microsoft disclosed 40 vulnerabilities across its suite of products and software Tuesday, the fewest the company’s included in a Patch Tuesday since December 2019.

However, two of the vulnerabilities is being actively exploited in the wild, according to Microsoft, the fourth month in a row in which this is the case for the monthly roundup of security issues.

In all, this Patch Tuesday includes seven critical vulnerabilities and 33 that are considered “important.”

One of the zero-day vulnerabilities included this month is CVE-2023-29336, an elevation of privilege vulnerability in the Win32k kernel mode driver. An adversary could exploit this vulnerability to gain SYSTEM privileges.

The most serious vulnerability disclosed Tuesday is CVE-2023-24941, a remote code execution vulnerability in the Windows Network File System that has a severity rating of 9.8 out of 10. An adversary could exploit this vulnerability over a network by making an unauthenticated, specially crafted call to an NFS service to execute code on the targeted machine. In addition to today’s patch, Microsoft also outlines several mitigation steps affected users can deploy to prevent the execution of this vulnerability.

Another remote code execution vulnerability, CVE-2023-29325, exists in Windows OLE that is also critical. An attacker could trigger this issue by tricking a target into opening a specially crafted, malicious email. The vulnerability can even trigger if the user just opens the email in the Preview pane.

CVE-2023-24955 is another remote code execution vulnerability in Microsoft SharePoint Server that Microsoft considers “more likely” to be exploited.

MSHTML, a software component that renders web pages in Microsoft browsers, also contains a critical vulnerability that could allow an attacker to gain admin privileges on a targeted device. CVE-2023-29324, however, is more difficult for an attacker to trigger than the other vulnerabilities mentioned above because it requires “an attacker to take additional actions prior to exploitation to prepare the target environment,” according to Microsoft.

There are two other critical vulnerabilities in this month’s security update that Microsoft considers “less likely” to be exploited:

There are also three important vulnerabilities considered to be “more likely” to be exploited, though are not considered as serious:

  • CVE-2023-24949: Windows Kernel elevation of privilege vulnerability
  • CVE-2023-24950: Microsoft SharePoint Server spoofing vulnerability
  • CVE-2023-24954: Microsoft SharePoint Server information disclosure vulnerability

A complete list of all the vulnerabilities Microsoft disclosed this month is available on its update page.

In response to these vulnerability disclosures, Talos is releasing a new Snort rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Cisco Secure Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.

The rules included in this release that protect against the exploitation of many of these vulnerabilities are 61705 - 61707,  61714 - 61720, 61722 and 61723.

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-for-may-2023/