Microsoft Releases July 2019 Security Updates, 2 Flaws Under Active Attack
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-0880 | Local Privilege Escalation in Microsoft Windows splwow64.exe (CVE-2019-0880) CVE-2019-0880 is a local elevation of privilege (EoP) flaw in how splwow64.exe — the 64-bit Windows process used to let 32-bit applications print — handles certain calls. An attacker who can already execute low-privileged code on an affected system can trigger the flaw with no user interaction and gain elevated privileges, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8, AV:L/PR:L/UI:N). The affected list covers most of the Windows fleet of the era: Windows 10 versions 1507 through 1903, Windows 8.1, Windows RT 8.1, and Windows Server 2012, 2016, and version 1903. Microsoft shipped the fix in the July 2019 security updates, which related coverage tied to two actively exploited Windows zero-days, and CISA formally added the flaw to its Known Exploited Vulnerabilities catalog on 2022-05-23, confirming in-the-wild exploitation (ransomware association unknown). EPSS currently rates the 30-day exploitation probability at 2.3% (82nd percentile), so unpatched systems remain a realistic target. Do: Apply the Microsoft security updates released in July 2019, or any later cumulative updates, to all affected Windows 10, Windows 8.1, Windows RT 8.1, and Windows Server systems, per the CISA KEV required action. Because exploitation requires local low-privileged code execution, prioritize shared and multi-user systems such as RDS/terminal servers, shared workstations, and kiosks. Verify remediation against the KEV entry added 2022-05-23; no public PoC is known, and no ransomware association has been established. | 7.8 | 2% | KEV |
| masshundreds of millions of Windows PCs and servers (Windows 10 alone had 800M+ active devices by 2019) | |
| CVE-2019-1132 | Local Privilege Escalation in Microsoft Win32k on Windows 7 and Server 2008 CVE-2019-1132 is an elevation of privilege flaw in the Windows kernel-mode Win32k component, which fails to properly handle objects in memory. It is triggered locally: an attacker who can already run low-privileged code on a target machine exploits the faulty object handling to execute code in the kernel with SYSTEM privileges, with no user interaction required. A successful exploit yields full control of the host, making this a typical second stage chained behind a remote code execution bug or a malware foothold. Only Windows 7 and Windows Server 2008 systems missing the vendor fix are affected. Exploitation is confirmed in the wild — CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-15 — though no public proof-of-concept is known and ransomware involvement is unknown; EPSS puts 30-day exploitation odds around 10% (95th percentile). Do: Apply the July 2019 (or later, including final pre-EOL) Win32k security updates for Windows 7 and Windows Server 2008, prioritizing hosts on the CISA KEV remediation timeline; since both platforms are past end of support, plan migration to a supported Windows release. As interim mitigation, restrict untrusted local code execution, and verify patch status of win32k across your estate using patch-management inventory, as exploited-in-the-wild KEV status makes unpatched legacy hosts high-priority targets. | 7.8 | 10% | KEV |
| masswell over 1 million systems |
Full article427 words · extracted from thehackernews.com · click to collapse
Swati KhandelwalJul 09, 2019
Microsoft today released its monthly batch of software security updates for the July month to patch a total of 77 vulnerabilities, 14 are rated Critical, 62 are Important, and 1 is rated Moderate in severity.
The July 2019 security updates include patches for various supported versions of Windows operating systems and other Microsoft products, including Internet Explorer, Edge, Office, Azure DevOps, Open Source Software, .NET Framework, Azure, SQL Server, ASP.NET, Visual Studio, and Exchange Server.
Details of 6 security vulnerabilities, all rated important, were made public before a patch was released, none of which were found being exploited in the wild.
However, two new privilege escalation vulnerabilities, one affects all supported versions of the Windows operating system, and the other affects Windows 7 and Server 2008, have been reported as being actively exploited in the wild.
Both actively exploited vulnerabilities lead to elevation of privilege, one (CVE-2019-1132) of which resides in the Win32k component and could allow an attacker to run arbitrary code in kernel mode.
However, the other actively exploited vulnerability (CVE-2019-0880) resides in the way splwow64 (Thunking Spooler APIs) handles certain calls, allowing an attacker or a malicious program to elevate its privileges on an affected system from low-integrity to medium-integrity.
The publicly known flaws affect Docker runtime, SymCrypt Windows cryptographic library, Remote Desktop Services, Azure Automation, Microsoft SQL server, and Windows AppX Deployment Service (AppXSVC).
Microsoft also released updates to patch 14 critical vulnerabilities, and as expected, all of them lead to remote code execution attacks and affect Microsoft products ranging from Internet Explorer and Edge to Windows Server DHCP, Azure DevOps and Team Foundation Servers.
Some important-rated vulnerabilities also lead to remote code execution attacks, while others allow elevation of privilege, information disclosure, cross-site scripting (XSS), security feature bypass, spoofing, and denial of service attacks.
Users and system administrators are strongly advised to apply the latest Microsoft security patches as soon as possible to keep hackers and cyber criminals away from taking control of their Windows computer systems.
For installing the latest security updates, users can head on to Settings → Update & Security → Windows Update → Check for updates on their Windows computers or can install the updates manually.
For addressing problematic updates on Windows 10 devices, Microsoft also introduced a safety measure in March this year that automatically uninstalls buggy software updates installed on your system if your OS detects a startup failure.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2019/07/microsoft-security-updates.html