ZeroHour
Security Affairspublished ()ingested @securityaffairs

Microsoft Patch Tuesday updates for September 2019 fix 2 privilege escalation flaws exploited in attacks

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-1215
+1 in the same advisory: …1214
Local Privilege Escalation in Microsoft Windows Winsock Driver (ws2ifsl.sys)

CVE-2019-1215 is an elevation-of-privilege vulnerability in ws2ifsl.sys, an auxiliary Winsock driver shipped with Windows, caused by improper handling of objects in memory (CWE-269). A local attacker with limited privileges can trigger the flaw via crafted requests to the driver, without user interaction, to execute code in kernel context. Successful exploitation grants elevated (SYSTEM-level) privileges, turning a low-privileged foothold into full control of the host and making the bug a useful link in ransomware attack chains. Affected systems include Windows 7, Windows 8.1, Windows RT 8.1, Windows 10 versions 1507 through 1903, and Windows Server versions 1803 and 1903. Microsoft patched the flaw in its October 2019 security updates; CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 with ransomware use known, and EPSS currently assigns a 19.3% probability of exploitation within 30 days (97th percentile).

Do: Apply the Microsoft security update issued October 8, 2019 across all affected Windows 7, 8.1, RT 8.1, Windows 10 (1507-1903), and Server 1803/1903 systems, prioritizing hosts where ransomware operators could chain this local privilege escalation. Systems no longer receiving updates (Windows 7 without Extended Security Updates, Windows 10 versions past end of service) should be upgraded to a supported release. Organizations subject to CISA's KEV binding requirements must patch per the vendor instructions within the required deadline, and defenders should hunt legacy endpoints for prior exploitation given the known ransomware linkage.

7.819% KEV ransomware
  • Microsoft Windows 10 1507, 1607, 1703, 1709, 1803, 1809, 1903
  • Microsoft Windows 7
  • Microsoft Windows 8.1
  • +2 more
masslikely hundreds of millions of devices at disclosure (the affected Windows 7/8.1 and Windows 10 1507-1903 releases dominated the global Windows PC installed…
CVE-2019-1235
+1 in the same advisory: …1294
An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server process does not validate the source of input or comm

An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server process does not validate the source of input or commands it receives, aka 'Windows Text Service Framework Elevation of Privilege Vulnerability'.

NVD description · AI analysis pending
7.8
group max
<1%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
Full article528 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 11, 2019

Microsoft Patch Tuesday updates for September 2019 address 80 flaws, including two privilege escalation issues exploited in attacks.

Microsoft Patch Tuesday security updates for September 2019 address 80 vulnerabilities, including two privilege escalation flaws that have been exploited in attacks in the wild.

The updates cover Microsoft Windows, Internet Explorer, Microsoft Edge, ChakraCore, Office and Microsoft Office Services and Web Apps, Skype for Business and Microsoft Lync, Visual Studio, .NET Framework, Exchange Server, Microsoft Yammer, and Team Foundation Server.

17 flaws are classified as Critical, 62 are listed as Important, and one is listed as Moderate in severity.

The first zero-day issue, tracked as CVE-2019-1214, resides in the Windows Common Log File System (CLFS) and could be exploited by an authenticated attacker with regular user privileges to escalate permissions to administrator.

The vulnerability affects all supported versions of Windows.

“An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context.” reads the security advisory published by Microsoft.

“To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted application to take control over the affected system.”

Microsoft addresses the vulnerability by correcting how CLFS handles objects in memory.

“According to Microsoft, this CVE is only being seen targeting older operating systems. This is a fine time to remind you that Windows 7 is less than six months from end of support, which means you won’t be getting updates for bugs like this one next February.” states a post published by ZDI.

The flaw was reported by a researcher from the Qihoo 360 Vulcan Team.

The second zero-day vulnerability tracked as CVE-2019-1215 affects Winsock (ws2ifsl.sys) and could be exploited by a local authenticated attacker to execute code with elevated privileges.

“An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated privileges.” reads the advisory.

“To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.”

Microsoft addressed the vulnerability by ensuring that ws2ifsl.sys properly handles objects in memory.

Microsoft confirmed that this flaw has been already exploited by malware since 2017.

“Microsoft reports this is being actively used against both newer and older supported OSes, but they don’t indicate where. Interestingly, this file has been targeted by malware in the past, with some references going back as far as 2007.” reads the analysis published by the Zero Day Initiative. “Not surprising, since malware often targets low-level Windows services. Regardless, since this is being actively used, put this one on the top of your patch list.”

Microsoft also addressed two vulnerabilities that were publicly disclosed before fixes were made available, the CVE-2019-1235 and the CVE-2019-1294.

The first issue is a privilege escalation issue in the Windows Text Service Framework, the second one is a Windows Secure Boot bypass issue.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – Microsoft Patch Tuesday, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/91089/security/microsoft-patch-tuesday-sept-2019.html