Patch Tuesday Lowdown, July 2019 Edition
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-0785 | A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server, aka 'Win A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'. NVD description · AI analysis pending | 9.8 | 50% |
| — | ||
| CVE-2019-0865 | A denial of service vulnerability exists when SymCrypt improperly handles a specially crafted digital signature.An attacker could exploit the vulnerability by c A denial of service vulnerability exists when SymCrypt improperly handles a specially crafted digital signature.An attacker could exploit the vulnerability by creating a specially crafted connection or message.The security update addresses the vulnerability by correcting the way SymCrypt handles digital signatures., aka 'SymCrypt Denial of Service Vulnerability'. NVD description · AI analysis pending | 7.5 | 5% |
| — | ||
| CVE-2019-0880 | Local Privilege Escalation in Microsoft Windows splwow64.exe (CVE-2019-0880) CVE-2019-0880 is a local elevation of privilege (EoP) flaw in how splwow64.exe — the 64-bit Windows process used to let 32-bit applications print — handles certain calls. An attacker who can already execute low-privileged code on an affected system can trigger the flaw with no user interaction and gain elevated privileges, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8, AV:L/PR:L/UI:N). The affected list covers most of the Windows fleet of the era: Windows 10 versions 1507 through 1903, Windows 8.1, Windows RT 8.1, and Windows Server 2012, 2016, and version 1903. Microsoft shipped the fix in the July 2019 security updates, which related coverage tied to two actively exploited Windows zero-days, and CISA formally added the flaw to its Known Exploited Vulnerabilities catalog on 2022-05-23, confirming in-the-wild exploitation (ransomware association unknown). EPSS currently rates the 30-day exploitation probability at 2.3% (82nd percentile), so unpatched systems remain a realistic target. Do: Apply the Microsoft security updates released in July 2019, or any later cumulative updates, to all affected Windows 10, Windows 8.1, Windows RT 8.1, and Windows Server systems, per the CISA KEV required action. Because exploitation requires local low-privileged code execution, prioritize shared and multi-user systems such as RDS/terminal servers, shared workstations, and kiosks. Verify remediation against the KEV entry added 2022-05-23; no public PoC is known, and no ransomware association has been established. | 7.8 | 2% | KEV |
| masshundreds of millions of Windows PCs and servers (Windows 10 alone had 800M+ active devices by 2019) | |
| CVE-2019-0887 | A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attacker abuses clipboard A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'. NVD description · AI analysis pending | 8.0 | 71% |
| — | ||
| CVE-2019-1132 | Local Privilege Escalation in Microsoft Win32k on Windows 7 and Server 2008 CVE-2019-1132 is an elevation of privilege flaw in the Windows kernel-mode Win32k component, which fails to properly handle objects in memory. It is triggered locally: an attacker who can already run low-privileged code on a target machine exploits the faulty object handling to execute code in the kernel with SYSTEM privileges, with no user interaction required. A successful exploit yields full control of the host, making this a typical second stage chained behind a remote code execution bug or a malware foothold. Only Windows 7 and Windows Server 2008 systems missing the vendor fix are affected. Exploitation is confirmed in the wild — CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-15 — though no public proof-of-concept is known and ransomware involvement is unknown; EPSS puts 30-day exploitation odds around 10% (95th percentile). Do: Apply the July 2019 (or later, including final pre-EOL) Win32k security updates for Windows 7 and Windows Server 2008, prioritizing hosts on the CISA KEV remediation timeline; since both platforms are past end of support, plan migration to a supported Windows release. As interim mitigation, restrict untrusted local code execution, and verify patch status of win32k across your estate using patch-management inventory, as exploited-in-the-wild KEV status makes unpatched legacy hosts high-priority targets. | 7.8 | 10% | KEV |
| masswell over 1 million systems |
Full article629 words · extracted from krebsonsecurity.com · click to collapse
Microsoft today released software updates to plug almost 80 security holes in its Windows operating systems and related software. Among them are fixes for two zero-day flaws that are actively being exploited in the wild, and patches to quash four other bugs that were publicly detailed prior to today, potentially giving attackers a head start in working out how to use them for nefarious purposes.
Zero-days and publicly disclosed flaws aside for the moment, probably the single most severe vulnerability addressed in this month’s patch batch (at least for enterprises) once again resides in the component of Windows responsible for automatically assigning Internet addresses to host computers — a function called the “Windows DHCP server.”
The DHCP weakness (CVE-2019-0785) exists in most supported versions of Windows server, from Windows Server 2012 through Server 2019.
Microsoft said an unauthenticated attacker could use the DHCP flaw to seize total, remote control over vulnerable systems simply by sending a specially crafted data packet to a Windows computer. For those keeping count, this is the fifth time this year that Redmond has addressed such a critical flaw in the Windows DHCP client.
All told, only 15 of the 77 flaws fixed today earned Microsoft’s most dire “critical” rating, a label assigned to flaws that malware or miscreants could exploit to commandeer computers with little or no help from users. It should be noted that 11 of the 15 critical flaws are present in or are a key component of the browsers built into Windows — namely, Edge and Internet Exploder Explorer.
One of the zero-day flaws — CVE-2019-1132 — affects Windows 7 and Server 2008 systems. The other — CVE-2019-0880 — is present in Windows 8.1, Server 2012 and later operating systems. Both would allow an attacker to take complete control over an affected system, although each is what’s known as an “elevation of privilege” vulnerability, meaning an attacker would already need to have some level of access to the targeted system.
CVE-2019-0865 is a denial-of-service bug in a Microsoft open-source cryptographic library that could be used to tie up system resources on an affected Windows 8 computer. It was publicly disclosed a month ago by Google’s Project Zero bug-hunting operation after Microsoft reportedly failed to address it within Project Zero’s stated 90-day disclosure deadline.
The other flaw publicly detailed prior to today is CVE-2019-0887, which is a remote code execution flaw in the Remote Desktop Services (RDP) component of Windows. However, this bug also would require an attacker to already have compromised a target system.
Mercifully, there do not appear to be any security updates for Adobe Flash Player this month.
Standard disclaimer: Patching is important, but it usually doesn’t hurt to wait a few days before Microsoft irons out any wrinkles in the fixes, which sometimes introduce stability or usability issues with Windows after updating (KrebsOnSecurity will endeavor to update this post in the event that any big issues with these patches emerge).
As such, it’s a good idea to get in the habit of backing up your system — or at the very least your data — before applying any updates. The thing is, newer versions of Windows (e.g. Windows 10+) by default will go ahead and decide for you when that should be done (often this is in the middle of the night). But that setting can be changed.
If you experience any problems installing any of the patches this month, please feel free to leave a comment about it below; there’s a better-than-even chance that other readers have experienced the same and may even chime in with some helpful advice and tips.
Further reading:
Tenable [full disclosure: Tenable is an advertiser on this blog].
Text extracted automatically; images, tables and formatting may be missing. Original: https://krebsonsecurity.com/2019/07/patch-tuesday-lowdown-july-2019-edition/