ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

August 2018 Patch Tuesday: Microsoft fixes two actively exploited zero-days

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-8174
Out-of-Bounds Write RCE in Microsoft Windows VBScript Engine

CVE-2018-8174 is an out-of-bounds write (CWE-787) in the Microsoft Windows VBScript engine, caused by the way it handles objects in memory. An attacker triggers it by convincing a user to visit a specially crafted website or open crafted content that invokes the VBScript engine (for example via Internet Explorer or a document preview), requiring user interaction. Successful exploitation yields remote code execution with the privileges of the logged-on user, enabling program installation, data theft and account takeover. All listed Windows client and server releases are affected: Windows 7, 8.1, RT 8.1, Windows 10 (1607-1803), and Windows Server 2008/2008 R2, 2012/2012 R2, 2016. Exploitation is in the wild: the flaw was fixed in the May 2018 Patch Tuesday, is listed in CISA KEV with known ransomware use, and public PoCs (0patch, ExploitDB 44741) and exploit kit usage have been documented; EPSS puts its 30-day exploitation probability at 88.5%.

Do: Apply Microsoft's May 2018 security updates (and any later cumulative or Extended Security Updates) to every listed Windows client and server release, as required by the CISA KEV listing, prioritizing internet-reachable and user-facing systems given known ransomware use. Upgrade out-of-support platforms (Windows 7/8.1/RT 8.1, Server 2008/2008 R2, 2012/2012 R2) to supported builds or ensure ESU coverage. As interim mitigation, block VBScript execution in Internet Explorer web zones using Microsoft's documented Group Policy/registry settings, and hunt for prior exploitation on legacy systems.

7.588% KEV ransomware PoC ×2
  • microsoft windows 10 1607, 1703, 1709, 1803 (pre-May 2018 security updates)
  • microsoft windows 7 all supported builds prior to the May 2018 security update
  • microsoft windows 8.1 all supported builds prior to the May 2018 security update
  • +4 more
masshundreds of millions of Windows PCs and servers (affected desktop releases dominated the ~1B+ device Windows install base at disclosure)
CVE-2018-8340
A security feature bypass vulnerability exists when Active Directory Federation Services (AD FS) improperly handles multi-factor authentication requests, aka "A

A security feature bypass vulnerability exists when Active Directory Federation Services (AD FS) improperly handles multi-factor authentication requests, aka "AD FS Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows Server 2012 R2, Windows 10 Servers.

NVD description · AI analysis pending
6.58%
  • microsoft windows server 2012
  • microsoft windows server 2016
CVE-2018-8345
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed, aka "LNK Remote Code Execu

A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed, aka "LNK Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8346.

NVD description · AI analysis pending
7.514%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2018-8373
Memory Corruption RCE in Microsoft Internet Explorer Scripting Engine

CVE-2018-8373 is an out-of-bounds write (CWE-787) in the Microsoft scripting engine's handling of objects in memory, which can corrupt memory and enable remote code execution in Internet Explorer 9, 10, and 11. It is triggered when a user is lured to an attacker-crafted web page or script in IE, with no privileges required but user interaction and relatively high attack complexity per the CVSS vector (AV:N/AC:H/UI:R). A successful attacker gains arbitrary code execution in the context of the current user, compromising that workstation's data and credentials. Any Windows system whose users browse with Internet Explorer 9, 10, or 11 was affected, and Microsoft fixed the flaw in its August 2018 Patch Tuesday release. The flaw was exploited as a zero-day in the wild at the time of patching — press coverage describes an in-the-wild VBScript zero-day blocked by endpoint protection — and it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25; EPSS places the 30-day exploitation probability at 61.9% (99th percentile).

Do: Apply Microsoft's August 2018 security updates for Internet Explorer on all supported Windows versions — the required action listed in the CISA KEV — and verify patch deployment via WSUS/SCCM/Intune across end-user workstations and RDS/browsing hosts. As interim mitigation, consider Microsoft's documented workaround of disabling VBScript execution in IE via feature-control keys and steer users away from IE for web browsing. Finally, migrate any remaining IE9/10/11 usage to Microsoft Edge (using IE mode for legacy sites), since IE11 is retired and this flaw is confirmed exploited in the wild.

7.562% KEV
  • microsoft Internet Explorer (Scripting Engine) Internet Explorer 9, Internet Explorer 10, Internet Explorer 11
masshundreds of millions of Windows devices (IE9–11 shipped with Windows; IE11 present by default on Windows 7/8.1/10)
CVE-2018-8414
File Path Validation RCE in Microsoft Windows Shell (Windows 10 and Server 1703–1803)

Microsoft's Windows Shell improperly validates file paths in certain Windows 10 and Windows Server releases, a remote code execution flaw rooted in improper input validation (CWE-20). The flaw is triggered when the shell processes a specially crafted file path, typically requiring the victim to interact with a malicious file, as reflected in the CVSS user-interaction (UI:R) requirement. Successful exploitation lets an attacker execute arbitrary code in the context of the current user, with high impact on confidentiality, integrity, and availability. Affected products are Windows 10 versions 1703, 1709, and 1803 and Windows Server (Semi-Annual Channel) versions 1709 and 1803. The bug was patched in Microsoft's August 2018 Patch Tuesday after being reported as one of two zero-days actively exploited in attacks in the wild, was later added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25, and EPSS currently estimates a 74% probability of exploitation within 30 days.

Do: Apply Microsoft's August 2018 security updates or later cumulative updates for Windows 10 1703/1709/1803 and Windows Server 1709/1803, consistent with Microsoft guidance and CISA's KEV required action; because these builds are now legacy, upgrading to a currently supported Windows release is the durable fix. Until patched, treat untrusted files and shortcuts with caution since exploitation requires user interaction. Inventory endpoints for the affected builds to confirm they are fully remediated.

8.874% KEV
  • Microsoft Windows 10 1703
  • Microsoft Windows 10 1709
  • Microsoft Windows 10 1803
  • +2 more
mass≈ hundreds of millions of Windows 10 devices at the time of disclosure (builds 1703–1803 were then-current Windows 10 releases); today only residual legacy,…
Full article596 words · extracted from helpnetsecurity.com · click to collapse

In the August 2018 Patch Tuesday, Microsoft has plugged over 60 vulnerabilities, two of which are being actively exploited in the wild. In addition to those, the company has also released a critical update advisory that addresses vulnerabilities found and patched in Adobe Flash.

August 2018 Patch Tuesday

Exploited zero-days

The two patched zero-days are:

  • CVE-2018-8414 – A vulnerability in Windows Shell that can be triggered by a user opening a specially crafted file and could allow the attacker to un arbitrary code in the context of the current user. It is being exploited in the wild through malicious PDF files, but any filetype can do the trick. The vulnerability has actually been patched out-of-band on August 2nd but it has been updated yesterday.
  • CVE-2018-8373 – A remote code execution vulnerability affecting the scripting engine in Internet Explorer that can be exploited either via a specially crafted website, specially crafted content or ads on websites, or via an embedded ActiveX control marked “safe for initialization” in an application or Microsoft Office document that hosts the IE rendering engine.

“[CVE-2018-8373] is one of the two active attacks this month, and this one was detected just after July’s patch Tuesday. It’s also very similar to the previously patched CVE-2018-8174, which was patched back in May,” says ZDI’s Dustin Childs.

“Analysis from Elliot Cao, the Trend Micro researcher who discovered this, revealed that it used a new UAF vulnerability in vbscript.dll. This UAF occurs when the VBScript engine uses AssignVar to assign a value to the element of an array accessed by AccessArray. Interestingly, the previous CVE was also being actively exploited when patched. In other words, if there are similar bugs to this one, they will likely be found and exploited, too. This patch should be one of your top priorities.”

Patches to prioritize

Jimmy Graham, Director of Product Management at Qualys, says that the browser and Scripting Engine patches should be prioritized for workstation-type devices.

“Microsoft has disclosed that CVE-2018-8373 has active exploits against Internet Explorer, making these patches a high priority. The PDF viewer, Windows Font Library, and GDI+ also have patches available that require a user to interact with a malicious site or file,” he notes.

CVE-2018-8345, a Windows RCE that could allow remote code execution if a malicious .LNK file is processed. “This patch should be prioritized for both workstations and servers, as the user does not need to click the file to exploit. Simply viewing a malicious LNK file can execute code as the logged-in user,” Graham explained.

Another critical flaw that has to be fixed quickly is CVE-2018-8345, a memory corruption vulnerability affecting Microsoft Exchange that could lead to remote code execution. Exploitation of the vulnerability requires that a specially crafted email be sent to a vulnerable Exchange server.

“Exchange patches are always frightening – no one wants to be the one that crashed the email server – but this bug is certainly nothing to overlook,” says Childs. More information about the flaw and a demonstration of the attack can be found here.

Administrators should also be aware of a vulnerability (CVE-2018-8340) in Microsoft Active Directory Federation Services (ADFS) that could allows attackers to bypass multi-factor authentication safeguards employed by enterprises.

Finally, Microsoft has also released updates and advice for mitigating the risk brought on by:

  • The newly revealed speculative execution side channel issue known as L1 Terminal Fault (L1TF). The issue (three distinct CVE-numbered vulnerabilities) affects Intel Core processors and Intel Xeon processors.
  • The Lazy FP State Restore issue (allowing side channel speculative execution) revealed in June 2018.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2018/08/15/august-2018-patch-tuesday/