ZeroHour
Cisco Talospublished ()ingested

Microsoft Patch Tuesday for Sept. 2020 — Snort rules and prominent vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-0922
+3 in the same advisory: …1115 …1508 …1593
A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles objects in memory.

A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have to open a specially crafted file or lure the target to a website hosting malicious JavaScript. The security update addresses the vulnerability by correcting how Microsoft COM for Windows handles objects in memory.

NVD description · AI analysis pending
8.8
group max
5%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2020-1057
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory.

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. The security update addresses the vulnerability by modifying how the ChakraCore scripting engine handles objects in memory.

NVD description · AI analysis pending
4.22%
  • microsoft edge
  • microsoft chakracore
CVE-2020-1172
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory.

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. The security update addresses the vulnerability by modifying how the ChakraCore scripting engine handles objects in memory.

NVD description · AI analysis pending
4.22%
  • microsoft chakracore
  • microsoft edge
CVE-2020-1332
+3 in the same advisory: …1594 …1218 …1193
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory.

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Excel. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) containing a specially crafted file designed to exploit the vulnerability. An attacker would have no way to force users to visit the website. Instead, an attacker would have to convince users to click a link, typically by way of an enticement in an email or instant message, and then convince them to open the specially crafted file. The security update addresses the vulnerability by correcting how Microsoft Excel handles objects in memory.

NVD description · AI analysis pending
7.84%
  • microsoft 365 apps
  • microsoft excel
  • microsoft office
Full article468 words · extracted from blog.talosintelligence.com · click to collapse

Tuesday, September 8, 2020 16:27

By Jon Munshaw.

Microsoft released its monthly security update Tuesday, disclosing more than 120 vulnerabilities across its array of products.

Twenty-three of the vulnerabilities are considered “critical" while the vast remainder are ranked as “important.” Users of all Microsoft and Windows products are urged to update their software as soon as possible to avoid possible exploitation of all these bugs.

The security updates cover several different products including the Microsoft Office suite of products, Windows Media Audo Decoder and the Hyper-V virtual machine software.

Talos also released a new set of SNORTⓇ rules that provide coverage for some of these vulnerabilities. For complete details, check out the latest Snort advisory here.

One of the most severe vulnerabilities exists in Microsoft COM. CVE-2020-0922 received a CVSS severity score of 8.8 out of a possible 10. An adversary could exploit this bug to gain the ability to remotely execute code on the victim machine after a user opens an attacker-controlled web page that contains specially crafted JavaScript.

A similar attack vector could allow a user to exploit CVE-2020-1508 and CVE-2020-1593, both code execution bugs in Media Audio Decoder. If a user visits a specially crafted, attacker-controlled web page, the attacker could then take control of the affected system.

The ChakraCore scripting engine also contains two remote code execution vulnerabilities that an attacker could use to execute code in the context of the current user. CVE-2020-1057 and CVE-2020-1172 both address how the scripting engine handles objects in memory.

Among the important vulnerabilities, we would like to highlight four vulnerabilities in Office products — three that affect Excel and one that affects Word. CVE-2020-1193, CVE-2020-1218, CVE-2020-1332 and CVE-2020-1594 are all likely to be exploited via phishing emails with malicious attachments. If a user were to open one of these attachments for the corresponding affected software, the adversary could then gain the ability to execute code on the victim machine.

Talos specifically discovered one vulnerability: CVE-2020-1115, a privilege escalation vulnerability in the Windows 10 Common Log File System.

For a complete list of all the vulnerabilities Microsoft disclosed this month, check out their update page.

In response to these vulnerability disclosures, Talos is releasing a new SNORTⓇ rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Firepower customers should use the latest update to their ruleset by updating their SRU. Open Source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.

The rules included in this release that protect against the exploitation of many of these vulnerabilities are 55139 - 55146, 55161, 55162, 55187, 55188 and 55206.

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-for-sept-2020/