ZeroHour
Security Affairspublished ()ingested @securityaffairs1

Microsoft Patch Tuesday security updates fixed 3 actively exploited flaws

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-36025
+2 in the same advisory: …36036 …36033
Windows SmartScreen Bypass (CVE-2023-36025) Exploited via Crafted Shortcut Files

CVE-2023-36025 is a security feature bypass in Windows SmartScreen in which a specially crafted file — exploited in the wild using Internet Shortcut (.url) files — evades the Mark-of-the-Web warning SmartScreen normally displays for content downloaded from the internet. The flaw is network-reachable and requires no authentication, but user interaction is required: it triggers when a user clicks the crafted file delivered via phishing email, chat, or a web download. By bypassing the SmartScreen prompt, the attacker removes a key user-facing defense that would otherwise flag or warn about the file, which facilitated delivery of malware in the observed DarkGate and Mispadu campaigns. Any unpatched Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), or Windows Server 2008/2012/2016/2019 system is affected, which at the time of disclosure effectively meant the entire supported Windows installed base. It is confirmed exploited in the wild: CISA added it to the KEV catalog on 2023-11-14, EPSS scores 30-day exploitation probability at 88.1% (100th percentile), though no public PoC is known.

Do: Apply Microsoft's November 2023 cumulative Windows security updates (the release containing the fix) on all affected Windows 10/11 and Windows Server systems; no configuration-based workaround is widely documented, so patching is the primary mitigation. Until patched, treat unexpected Internet Shortcut (.url) files arriving via email or chat with extra suspicion, since they can execute without the usual SmartScreen warning, and hunt for DarkGate/Mispadu indicators. Given the KEV listing and 88.1% EPSS, prioritize this fix in the current patch cycle; ransomware-associated use is reported as unknown.

8.8
group max
88% KEV
  • microsoft Windows 10 1507 (builds prior to the November 2023 security updates)
  • microsoft Windows 10 1607 (builds prior to the November 2023 security updates)
  • microsoft Windows 10 1809 (builds prior to the November 2023 security updates)
  • +9 more
mass>1 billion endpoints (effectively the entire supported Windows 10/11/Server installed base at the time of disclosure)
CVE-2023-36397
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.818%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
Full article346 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini November 14, 2023

Patch Tuesday security updates for November 2023 fixed three vulnerabilities actively exploited in the wild.

Microsoft Patch Tuesday security updates for November 2023 addressed 63 new vulnerabilities in Microsoft Windows and Windows Components; Exchange Server; Office and Office Components; ASP.NET and .NET Framework; Azure; Mariner; Microsoft Edge (Chromium-based), Visual Studio, and Windows Hyper-V.

Three vulnerabilities addressed by the IT giant are are rated Critical, 56 are rated Important, and four are rated Moderate in severity.

Three of these vulnerabilities are actively exploited in attacks in the wild:

–       CVE-2023-36033 – Windows DWM Core Library Elevation of Privilege Vulnerability
An attacker can trigger this vulnerability to elevate privileges through the Windows Desktop Manager (DWM). An attacker can exploit the flaw to gain SYSTEM privileges and chaining this issue with a remote code execution bug can compromise a system.

–       CVE-2023-36036 – Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
An attacker can exploit this flaw to gain SYSTEM privileges. “This driver is used for managing and facilitating the operations of cloud-stored files. It’s loaded by default on just about every version of Windows, so it provides a broad attack surface.” reads the post published by ZDI. “Again, this bug is likely being paired with a code execution bug in attacks.”

–       CVE-2023-36025 – Windows SmartScreen Security Feature Bypass Vulnerability
An attacker can exploit this flaw to bypass Windows Defender SmartScreen checks and other prompts. This flaw can be exploited in phishing campaigns to evade user prompts that would warn recipients about opening a malicious document.

The most severe flaw addressed by Microsoft Patch Tuesday security updates for November 2023 is a Windows Pragmatic General Multicast (PGM) Remote Code Execution issue tracked as CVE-2023-36397 (CVSS 9.8). A remote, unauthenticated attacker can exploit this flaw to execute code with elevated privileges without user interaction.

The full list of vulnerabilities addressed by Microsoft for November 2023 is available here.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Microsoft Patch Tuesday security updates for November 2023)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/154175/security/microsoft-patch-tuesday-security-updates-nov-2023.html