July 2019 Patch Tuesday: Microsoft plugs two actively exploited zero-days
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-15664 | In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange attack with Directory Traversal, giving In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange attack with Directory Traversal, giving attackers arbitrary read-write access to the host filesystem with root privileges, because daemon/archive.go does not do archive operations on a frozen filesystem (or from within a chroot). NVD description · AI analysis pending | 7.5 | 3% | PoC ×2 |
| — | |
| CVE-2019-0865 | A denial of service vulnerability exists when SymCrypt improperly handles a specially crafted digital signature.An attacker could exploit the vulnerability by c A denial of service vulnerability exists when SymCrypt improperly handles a specially crafted digital signature.An attacker could exploit the vulnerability by creating a specially crafted connection or message.The security update addresses the vulnerability by correcting the way SymCrypt handles digital signatures., aka 'SymCrypt Denial of Service Vulnerability'. NVD description · AI analysis pending | 7.5 | 5% |
| — | ||
| CVE-2019-0880 | Local Privilege Escalation in Microsoft Windows splwow64.exe (CVE-2019-0880) CVE-2019-0880 is a local elevation of privilege (EoP) flaw in how splwow64.exe — the 64-bit Windows process used to let 32-bit applications print — handles certain calls. An attacker who can already execute low-privileged code on an affected system can trigger the flaw with no user interaction and gain elevated privileges, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8, AV:L/PR:L/UI:N). The affected list covers most of the Windows fleet of the era: Windows 10 versions 1507 through 1903, Windows 8.1, Windows RT 8.1, and Windows Server 2012, 2016, and version 1903. Microsoft shipped the fix in the July 2019 security updates, which related coverage tied to two actively exploited Windows zero-days, and CISA formally added the flaw to its Known Exploited Vulnerabilities catalog on 2022-05-23, confirming in-the-wild exploitation (ransomware association unknown). EPSS currently rates the 30-day exploitation probability at 2.3% (82nd percentile), so unpatched systems remain a realistic target. Do: Apply the Microsoft security updates released in July 2019, or any later cumulative updates, to all affected Windows 10, Windows 8.1, Windows RT 8.1, and Windows Server systems, per the CISA KEV required action. Because exploitation requires local low-privileged code execution, prioritize shared and multi-user systems such as RDS/terminal servers, shared workstations, and kiosks. Verify remediation against the KEV entry added 2022-05-23; no public PoC is known, and no ransomware association has been established. | 7.8 | 2% | KEV |
| masshundreds of millions of Windows PCs and servers (Windows 10 alone had 800M+ active devices by 2019) | |
| CVE-2019-0887 | A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attacker abuses clipboard A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'. NVD description · AI analysis pending | 8.0 | 71% |
| — | ||
| CVE-2019-1068 | Remote Code Execution in Microsoft SQL Server 2016 and 2017 CVE-2019-1068 is a remote code execution vulnerability in Microsoft SQL Server caused by improper handling of the processing of internal functions (CWE-20, improper input validation). An attacker who can reach SQL Server over the network with low-privileged credentials can trigger the flawed code path and execute arbitrary code, gaining high confidentiality, integrity, and availability impact on the database host. Any organization running affected Microsoft SQL Server versions — including SQL Server 2016 and SQL Server 2017 — is affected. The flaw carries a high EPSS score (52.8% probability of exploitation within 30 days, 99th percentile) and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-26, with headlines reporting it being exploited in active attacks. No public proof-of-concept is known, but the in-the-wild exploitation documented by CISA makes patching urgent; the fix shipped in Microsoft's July 2019 Patch Tuesday security updates. Do: Apply Microsoft's July 2019 security updates (cumulative updates) for SQL Server 2016 and SQL Server 2017 as directed in the vendor advisory, and inventory all SQL Server instances — especially those reachable on TCP 1433 from the internet — prioritizing exposed or low-privilege-accessible instances. Given the KEV listing, CISA's BOD 26-04 requires patching per vendor instructions (or discontinuing use if mitigation is unavailable) on a prioritized timeline; restrict network access to SQL Server and confirm no unexpected low-privileged accounts or unusual process activity on database hosts as a triage check. | 8.8 | 53% | KEV |
| massmillions of SQL Server deployments worldwide, with roughly 1M+ instances exposed on TCP 1433 in public internet scans | |
| CVE-2019-1072 | A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server an A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability'. NVD description · AI analysis pending | 9.8 | 12% |
| — | ||
| CVE-2019-1132 | Local Privilege Escalation in Microsoft Win32k on Windows 7 and Server 2008 CVE-2019-1132 is an elevation of privilege flaw in the Windows kernel-mode Win32k component, which fails to properly handle objects in memory. It is triggered locally: an attacker who can already run low-privileged code on a target machine exploits the faulty object handling to execute code in the kernel with SYSTEM privileges, with no user interaction required. A successful exploit yields full control of the host, making this a typical second stage chained behind a remote code execution bug or a malware foothold. Only Windows 7 and Windows Server 2008 systems missing the vendor fix are affected. Exploitation is confirmed in the wild — CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-15 — though no public proof-of-concept is known and ransomware involvement is unknown; EPSS puts 30-day exploitation odds around 10% (95th percentile). Do: Apply the July 2019 (or later, including final pre-EOL) Win32k security updates for Windows 7 and Windows Server 2008, prioritizing hosts on the CISA KEV remediation timeline; since both platforms are past end of support, plan migration to a supported Windows release. As interim mitigation, restrict untrusted local code execution, and verify patch status of win32k across your estate using patch-management inventory, as exploited-in-the-wild KEV status makes unpatched legacy hosts high-priority targets. | 7.8 | 10% | KEV |
| masswell over 1 million systems |
Full article611 words · extracted from helpnetsecurity.com · click to collapse
For July 2019 Patch Tuesday, Microsoft has pushed out patches for 78 CVE-numbered vulnerabilities (15 of them critical) and Adobe for three, but none of them in its most widely used software.

Adobe patches
It’s unusual to see no patches for Flash or Acrobat/Reader, but I suppose it had to happen sometimes. Instead, Adobe released patches for flaws in:
- Dreamweaver (a privilege escalation flaw in the software’s installer)
- Bridge CC (an information disclosure flaw that can be triggered via malformed SVG images)
- Experience Manager (three flaws that could lead to disclosure of sensitive information).
None of these are critical nor exploited in the wild.
Microsoft patches
Of the 78 flaws fixed, two are under active exploitation: CVE-2019-0880 and CVE-2019-1132.
The former has been flagged by Resecurity and the latter by ESET. Both can be used by attackers to elevate their privileges on target machines, but the latter apparently only works on older Windows versions (Windows 7 and Server 2008).
Other vulnerabilities of special note include:
CVE-2019-1068 – a remote code execution flaw that can be triggered by a specially crafted query sent to a vulnerable SQL server.
“This vulnerability is ranked as Important, and does require authentication. However, [it] could be chained with SQL injection to allow an attacker to completely compromise the server,” notes Jimmy Graham, Senior Director of Product Management at Qualys.
CVE-2019-0865 – a denial of service vulnerability in SymCrypt, the library used by Windows to .handle cryptographic functions on Windows.
“Using a specially-crafted digital signature, an attacker could exploit this flaw by embedding the signature in a message or as part of a secure connection request. This vulnerability was publicly disclosed in June by Google Project Zero researcher Tavis Ormandy,” says Satnam Narang, senior research engineer at Tenable.
CVE-2019-0887 – a RCE flaw in Remote Desktop Services. To exploit it, the attacker must already have compromised a system running Remote Desktop Services, and then wait for a victim system to connect to Remote Desktop Services.
“This vulnerability was first published in a blog on Reverse RDP attacks in February 2019 which included one CVE that did not receive a CVE-ID,” Narang noted.
CVE-2018-15664 – an elevation of privilege flaw in Docker runtime (and the underlying community project, Moby). Technically, no fix for it is yet available.
“There is a pull request in review to fix this vulnerability. After the fix is merged in the upstream Moby project, we will build and release a new Moby build for use with AKS. For Azure IoT Edge customers, we will make the fixed Moby packages available along with installation instructions,” Microsoft explained.
Until that happens, Microsoft recommends that customers refrain from allowing the use of the Docker copy command on their AKS clusters and Azure IoT Edge devices.
According to Graham, enterprise admins should also prioritize:
- Scripting Engine, Browser, GDI+, and .NET Framework patches for workstation-type devices (i.e., any system that is used for email or to access the internet via a browser) and multi-user servers that are used as remote desktops for users.
- The patch for CVE-2019-1072, a RCE exploitable through malicious file uploads, affecting Azure DevOps Server and Team Foundations Server.
UPDATE (July 10, 2019, 2:43 a.m. PT):
ESET has shared more information about CVE-2019-1132 and has explained why the exploit works only on older Windows versions.
“People who still use Windows 7 for 32-bit systems Service Pack 1 should consider updating to newer operating systems, since extended support of Windows 7 Service Pack 1 ends on January 14th, 2020. Which means that Windows 7 users won’t receive critical security updates. Thus, vulnerabilities like this one will stay unpatched forever,” ESET researcher Anton Cherepanov noted.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2019/07/10/july-2019-patch-tuesday/