ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

December 2023 Patch Tuesday: 33 fixes to wind the year down

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-20588
A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality.

A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality.

NVD description · AI analysis pending
5.511%
  • debian debian linux
  • debian epyc 7351p firmware
  • debian epyc 7401p firmware
  • +1 more
CVE-2023-23397
Zero-Click Elevation of Privilege in Microsoft Outlook (Forced NTLM Credential Leak)

CVE-2023-23397 is an elevation of privilege vulnerability in Microsoft Outlook caused by improper input validation (CWE-20) combined with authentication bypass via spoofed authentication data on the channel (CWE-294), allowing an attacker to force Outlook to authenticate to an attacker-controlled SMB/WebDAV server. It is triggered when Outlook processes a crafted email or calendar object — for example a meeting or task reminder whose sound property points to an attacker-supplied UNC path — and requires no user interaction. That authentication exchange leaks the victim's NTLM credential hash, which the attacker can crack offline or relay to authenticate as the victim and access resources such as Exchange mailboxes, effectively escalating privileges. Affected software spans Microsoft 365 Apps, Microsoft Office (including the Long Term Servicing Channel), and Microsoft Outlook, which are deployed across enterprises, governments, and militaries worldwide. It is actively exploited in the wild — added to CISA's Known Exploited Vulnerabilities catalog on 2023-03-14 with a 97.4% EPSS — and Microsoft has warned of exploitation by Russia-aligned threat actors in campaigns against government and military mail servers, with patches shipped in Microsoft's March 2023 security updates.

Do: Apply Microsoft's March 2023 security updates to Microsoft 365 Apps, Office/LTSC, and Outlook immediately, per CISA's required action. As interim mitigation, enable Extended Protection for Authentication or add accounts to the Protected Users group to block the NTLM credential leak, and audit calendar and task reminder sound properties for UNC paths (Microsoft published an audit/cleanup script for this) while watching for unexpected outbound SMB/WebDAV connections from hosts running Outlook.

9.897% KEV
  • Microsoft 365 Apps Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • Microsoft Office Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • Microsoft Office Long Term Servicing Channel (LTSC) Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • +1 more
masson the order of hundreds of millions of users (Outlook ships with Microsoft Office/Microsoft 365, the dominant enterprise and government email suite)
CVE-2023-35628
Windows MSHTML Platform Remote Code Execution Vulnerability

Windows MSHTML Platform Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.193%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2023-35636
Microsoft Outlook Information Disclosure Vulnerability

Microsoft Outlook Information Disclosure Vulnerability

NVD description · AI analysis pending
6.518%
  • microsoft 365 apps
  • microsoft office
  • microsoft office long term servicing channel
CVE-2023-36019
Microsoft Power Platform Connector Spoofing Vulnerability

Microsoft Power Platform Connector Spoofing Vulnerability

NVD description · AI analysis pending
7.416%
  • microsoft azure logic apps
  • microsoft power platform
CVE-2023-36036
Local Privilege Escalation in Microsoft Windows Cloud Files Mini Filter Driver

CVE-2023-36036 is a high-severity (CVSS 7.8) elevation-of-privilege flaw caused by an out-of-bounds/heap-based buffer overflow write (CWE-122, CWE-787) in the Windows Cloud Files Mini Filter Driver, the kernel component that manages cloud-synced placeholder files (e.g., cloud storage 'files on demand' such as OneDrive). A local attacker who can already run low-privileged code on a vulnerable machine can trigger the flaw with no user interaction and escalate to SYSTEM/administrator-level privileges, enabling full control of the host and potential chaining with other vulnerabilities. The affected scope spans Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), and Windows Server 2008, 2012, 2016, and 2019, meaning the driver is present by default across essentially the entire Windows install base until patched. The vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-11-14, and it was among the three actively exploited flaws fixed in Microsoft's November 2023 Patch Tuesday; ransomware use is unknown. No public proof-of-concept is catalogued, but the EPSS probability of 16.7% (97th percentile) and the KEV listing make this a patching priority.

Do: Apply the Microsoft November 2023 Patch Tuesday security updates (released 2023-11-14) to every in-scope Windows 10, Windows 11, and Windows Server host, prioritizing endpoints where untrusted or low-privileged users can execute code, and verify installation via Windows Update history or patch-management reporting. Per CISA's KEV required action, apply vendor mitigations or discontinue use of unpatched versions; no standalone workaround or public PoC is catalogued, so patching is the primary remediation. Because the flaw requires local access, focus early deployment on shared workstations, RDS/VDI hosts, and servers that expose interactive logon to non-administrative users.

7.817% KEV
  • microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • microsoft Windows 11 21H2, 22H2, 23H2
  • microsoft Windows Server 2008, 2012, 2016, 2019
masshundreds of millions of Windows 10/11 and Windows Server installations (order 10^8-10^9)
CVE-2023-36696
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

NVD description · AI analysis pending
7.8<1%
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • microsoft windows 10 22h2
  • +1 more
Full article591 words · extracted from helpnetsecurity.com · click to collapse

Microsoft’s December 2023 Patch Tuesday is a light one: 33 patches, only four of which are deemed critical.

December 2023 Patch Tuesday

“This month, Microsoft did not patch any zero-day vulnerabilities, marking only the second time in 2023 that no zero-days were fixed (June was the other month),” noted Satnam Narang, senior staff research engineer at Tenable.

“Of the 33 vulnerabilities patched this month, 11 vulnerabilities are rated as Exploitation More Likely according to Microsoft. Nearly three-quarters of these flaws are elevation of privilege vulnerabilities, followed by remote code execution flaws at 18.2%.”

December 2023 Patch Tuesday: Vulnerabilities of note

Among the flaws for which exploitation is more likely is CVE-2023-35628, a RCE flaw in Windows MSHTML Platform.

“The attacker could exploit this vulnerability by sending a specially crafted email which triggers automatically when it is retrieved and processed by the Outlook client. This could lead to exploitation BEFORE the email is viewed in the Preview Pane,” Microsoft explained.

The only thing that makes exploitation difficult to pull off is the fact that the attackers must also be able to simultaneously use “complex memory shaping techniques.”

CVE-2023-35636, a flaw in Microsoft Outlook, may allow an attacker to grab NTLM hashes.

“An attacker could exploit this flaw by convincing a potential victim to open a specially crafted file that could be delivered via email or hosted on a malicious website. What makes this one stand out is that exploitation of this flaw would lead to the disclosure of NTLM hashes, which could be leveraged as part of an NTLM relay attack,” Narang commented.

“It is reminiscent of CVE-2023-23397, an elevation of privilege vulnerability in Microsoft Outlook that was exploited in the wild as a zero day and patched in the March 2023 Patch Tuesday release. However, unlike CVE-2023-23397, CVE-2023-35636 is not exploitable via Microsoft’s Preview Pane, which lowers the severity of this flaw.”

Dustin Childs, head of threat awareness at Trend Micro Inc.’s Zero Day Initiative, has also singled out CVE-2023-36019, a Microsoft Power Platform (and Azure Logic Apps) Connector spoofing vulnerability that, he says, “acts more like a code execution bug than a spoofing bug.”

“The vulnerability is in the web server, but the malicious scripts execute in the victim’s browser on their machine,” Microsoft noted. “The user would have to click on a specially crafted URL to be compromised by the attacker. An attacker could manipulate a malicious link, application, or file to disguise it as a legitimate link or file to trick the victim.”

The vulnerability has been addressed by Microsoft by making newly created custom connectors that use OAuth 2.0 to authenticate automatically have a per connector redirect URI.

But admins must close the hole completely by updating existing custom OAuth 2.0 connectors to do the same before February 17th, 2024, Microsoft urged. “Any custom connector that has not been updated to use a per connector redirect URI will stop working for new connections, and show an error message to the user.”

Microsoft has also fixed CVE-2023-20588, a flaw in certain AMD processor models that could result in loss of confidentiality (it required a Windows update), and CVE-2023-36696, an elevation of privilege vulnerability in the Windows Cloud Files Mini Filter driver.

“An attacker could exploit this vulnerability as part of post-compromise to elevate privileges to SYSTEM,” Narang told Help Net Security.

“It’s the sixth elevation of privilege vulnerability discovered in this driver in 2023. Last month, Microsoft patched CVE-2023-36036, a separate elevation of privilege flaw in the same driver that was exploited in the wild as a zero day.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/12/12/december-2023-patch-tuesday/