Microsoft Patch Tuesday, June 2019 Edition
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-0973 +1 in the same advisory: …1053 | An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure libra An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior. A locally authenticated attacker could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. The security update addresses the vulnerability by correcting the input sanitization error to preclude unintended elevation. NVD description · AI analysis pending | 7.8 group max | 1% |
| — | ||
| CVE-2019-1035 +1 in the same advisory: …1034 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. To exploit the vulnerability, a user must open a specially crafted file with an affected version of Microsoft Word software. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file that is designed to exploit the vulnerability. However, an attacker would have no way to force the user to visit the website. Instead, an attacker would have to convince the user to click a link, typically by way of an enticement in an email or Instant Messenger message, and then convince the user to open the specially crafted file. The security update addresses the vulnerability by correcting how Microsoft Word handles files in memory. NVD description · AI analysis pending | 7.8 | 7% |
| — | ||
| CVE-2019-1064 | Local Privilege Escalation in Microsoft Windows AppX Deployment Service Microsoft Windows AppX Deployment Service (AppXSVC) improperly handles hard links, creating an elevation of privilege vulnerability tracked as CVE-2019-1064 (CWE-59, link following). The flaw is triggered when a local attacker who is already able to log on to an affected system runs a specially crafted application. Successful exploitation allows the attacker to run processes in an elevated context, then install programs and view, change, or delete data, effectively taking control of the affected system. Affected products span Windows 10 versions 1607, 1703, 1709, 1803, 1809, and 1903, plus Windows Server 1709, 1803, 1903, 2016, and 2019. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-15) with known ransomware use, so it is being actively exploited in the wild. Do: Apply Microsoft's security update for all affected Windows 10 and Windows Server builds per vendor instructions, as required by CISA's KEV catalog, and upgrade any systems on builds 1607-1903 that no longer receive updates to a supported Windows release. Because exploitation requires local logon, prioritize patching multi-user workstations, RDP-exposed servers, and systems at ransomware risk, and confirm remediation by checking that the OS build includes the AppXSVC hard-link fix. | 7.8 | 7% | KEV ransomware |
| masshundreds of millions of Windows 10 and Windows Server installations worldwide | |
| CVE-2019-1069 | Local Privilege Escalation in Microsoft Windows Task Scheduler CVE-2019-1069 is a local elevation-of-privilege flaw in the Microsoft Windows Task Scheduler Service, which fails to correctly validate certain file operations (improper link/path resolution, CWE-59) that the service performs on behalf of running tasks. An attacker who has already gained unprivileged code execution on a target machine can trigger the vulnerable file operation so it is carried out by the Task Scheduler service with its elevated rights. Successful exploitation yields elevated privileges on the victim system, with CVSS impact rated High for confidentiality, integrity and availability, effectively giving the attacker full control of the local host. Affected products are Windows 10 versions 1507 through 1903 and Windows Server 1803, 1903, 2016 and 2019 — i.e., the Task Scheduler component in all of these builds. The flaw is exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-15 with known ransomware use, a public proof-of-concept has existed since June 2019, and EPSS estimates a ~6.1% probability of exploitation within 30 days (93rd percentile). Do: Apply Microsoft's security updates for CVE-2019-1069 (released in the June 2019 Patch Tuesday cumulative updates) or later cumulative updates on Windows 10 1507–1903 and Windows Server 1803/1903/2016/2019, per CISA's required action. Verify installed OS builds against the affected list and prioritize shared/multi-user hosts (RDS/VDI, jump servers, workstations of users who run untrusted software), since ransomware operators chain this local privilege escalation after initial access. Where patching is delayed, restrict unprivileged code execution and monitor for suspicious scheduled-task and file-operation activity by the Task Scheduler service. | 7.8 | 6% | KEV ransomware PoC |
| masshundreds of millions of Windows 10/Windows Server installations (every unpatched Windows 10 1507–1903 or Server 1803/1903/2016/2019 machine carries the… |
Full article603 words · extracted from krebsonsecurity.com · click to collapse
Microsoft on Tuesday released updates to fix 88 security vulnerabilities in its Windows operating systems and related software. The most dangerous of these include four flaws for which there is already exploit code available. There’s also a scary bug affecting all versions of Microsoft Office that can be triggered by a malicious link or attachment. And of course Adobe has its customary monthly security update for Flash Player.
Microsoft says it has so far seen no exploitation against any of the four flaws that were disclosed publicly prior to their patching this week — nor against any of the 88 bugs quashed in this month’s release. All four are privilege escalation flaws: CVE-2019-1064 and CVE-2019-1069 affect Windows 10 and later; CVE-2019-1053 and CVE-2019-0973 both affect all currently supported versions of Windows.
Most of the critical vulnerabilities — those that can be exploited by malware or miscreants to infect systems without any action on the part of the user — are present in Microsoft’s browsers Internet Explorer and Edge.
According to Allan Liska, senior solutions architect at Recorded Future, serious vulnerabilities in this month’s patch batch reside in Microsoft Word (CVE-2019-1034 and CVE-2019-1035).
“This is another memory corruption vulnerability that requires an attacker to send a specially crafted Microsoft Word document for a victim to open, alternatively an attacker could convince a victim to click on a link to a website hosting a malicious Microsoft Word document,” Liska wrote. “This vulnerability affects all versions of Microsoft Word on Windows and Mac as well as Office 365. Given that Microsoft Word Documents are a favorite exploitation tool of cybercriminals, if this vulnerability is reverse engineered it could be widely exploited.”
Microsoft also pushed an update to plug a single critical security hole in Adobe’s Flash Player software, which is waning in use but it still is a target for malware purveyors. Google Chrome auto-updates Flash but also is now making users explicitly enable Flash every time they want to use it. By the summer of 2019 Google will make Chrome users go into their settings to enable it every time they want to run it.
Firefox also forces users with the Flash add-on installed to click in order to play Flash content; instructions for disabling or removing Flash from Firefox are here. Adobe will stop supporting Flash at the end of 2020.
Note that Windows 10 likes to install patches all in one go and reboot your computer on its own schedule. Microsoft doesn’t make it easy for Windows 10 users to change this setting, but it is possible. For all other Windows OS users, if you’d rather be alerted to new updates when they’re available so you can choose when to install them, there’s a setting for that in Windows Update. To get there, click the Windows key on your keyboard and type “windows update” into the box that pops up.
Staying up-to-date on Windows patches is good. Updating only after you’ve backed up your important data and files is even better. A good backup means you’re not pulling your hair out if the odd buggy patch causes problems booting the system. So do yourself a favor and backup your files before installing any patches.
As always, if you experience any problems installing any of the patches this month, please feel free to leave a comment about it below; there’s a good chance other readers have experienced the same and may even chime in here with some helpful tips.
Additional reading:
Text extracted automatically; images, tables and formatting may be missing. Original: https://krebsonsecurity.com/2019/06/microsoft-patch-tuesday-june-2019-edition/