ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Microsoft Issues Patches for Another Four Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-0001
Local Privilege Escalation in Microsoft Windows GDI

CVE-2017-0001 is a privilege escalation flaw in the Windows Graphics Device Interface (GDI) that affects Windows Vista through Windows 10 (1507, 1511, 1607) and Windows Server 2008 through 2016. It is triggered by a local attacker who runs a crafted application on an affected system, requiring only low local privileges and no user interaction. Successful exploitation grants the attacker elevated privileges, with high impact on confidentiality, integrity and availability, effectively giving full control of the host. Any organization running unpatched copies of these Windows client or server versions is affected. The flaw is listed in the CISA Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating known exploitation in the wild, though specific in-the-wild campaigns and ransomware use are not documented; EPSS estimates a 3.1% chance of exploitation in the next 30 days.

Do: Apply the January 2017 Microsoft security update or any later cumulative update for the affected Windows version, prioritizing systems listed in CISA KEV; verify installed updates confirm the GDI privilege escalation fix is present. Systems past extended support (Windows Vista, Windows 7, Windows 8.1, Server 2008/2012 without extended security updates) should receive the applicable ESU patch or be migrated, and restrict local execution of untrusted applications as an interim mitigation.

7.83% KEV
  • Microsoft Windows Vista SP2
  • Microsoft Windows Server 2008 SP2 and R2 SP1 (32-bit/x64/Itanium as shipped)
  • Microsoft Windows 7 SP1 (x86/x64)
  • +5 more
masshundreds of millions of Windows installations worldwide (any unpatched Windows Vista through 10 1607 / Server 2008 through 2016 system)
CVE-2017-0222
Memory Corruption RCE in Microsoft Internet Explorer

CVE-2017-0222 is a remote code execution flaw in Microsoft Internet Explorer caused by improper access to objects in memory (CWE-119), which can corrupt memory in a way that allows arbitrary code execution. It is triggered remotely, typically when a user is persuaded to view attacker-controlled web content in Internet Explorer. A successful attack runs code in the context of the current user, so the attacker gains that user's privileges and potentially full control of the workstation if the user has elevated rights. Anyone running affected builds of Internet Explorer is exposed, which historically means the very large base of Windows desktops that shipped with IE. Exploitation is confirmed in the wild — CISA added the CVE to its KEV catalog on 2022-02-25 — while no public proof-of-concept is known and ransomware use is unknown; EPSS estimates a 29.6% chance of exploitation in the next 30 days (98th percentile).

Do: Apply the Microsoft cumulative security update for Internet Explorer that fixes this issue (released with the April 2017 Patch Tuesday, or any later cumulative IE update) on all Windows systems that still run IE, prioritizing legacy and internet-facing machines. Because CISA's KEV listing in February 2022 shows the flaw was still being exploited years after patching, audit Windows 7/8.1 and Windows Server estates for unpatched IE and migrate users to Microsoft Edge (with IE mode if needed). As interim mitigations, restrict or disable legacy IE, warn users about opening untrusted links, and verify current IE patch levels before patching.

8.830% KEV
  • Microsoft Internet Explorer
masshundreds of millions of Windows endpoints (IE was bundled by default on Windows desktops of the era)
CVE-2017-0262
+1 in the same advisory: …0261
Memory Corruption RCE in Microsoft Office 2010, 2013, and 2016

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 fail to properly handle objects in memory, creating a remote code execution condition when the software processes a specially crafted file. Triggering the flaw requires user interaction - the CVSS vector (AV:L, UI:R) indicates an attacker must get a user to open a malicious document, typically via a phishing email or similar file-delivery channel. Successful exploitation runs arbitrary code in the context of the current user, exposing the confidentiality, integrity, and availability of everything that account can access on the endpoint (CVSS 3.1: 7.8, High). Any organization running the affected Office versions is affected; the flaw was one of several Office zero-days fixed in Microsoft's May 2017 Patch Tuesday (distinct from CVE-2017-0261 and CVE-2017-0281) and was reportedly exploited by Russian APT actors (APT28/Sofacy) around that time. Exploitation is confirmed: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-02-10, and EPSS currently rates the 30-day exploitation probability at 81% (100th percentile), so unpatched endpoints should be treated as actively targeted.

Do: Apply Microsoft's May 2017 security updates for Office 2010 SP2, Office 2013 SP1, and Office 2016, per the CISA KEV required action, and verify through asset inventory that no endpoint is running an unpatched Office build. Because exploitation requires user interaction with a crafted file, harden email and attachment handling (block or detonate Office files from untrusted sources) and brief users on unsolicited documents. Office 2010 and 2013 have since reached end of support, so migrate any remaining deployments to a currently supported Office release.

7.881% KEV
  • Microsoft Office 2010 Service Pack 2
  • Microsoft Office 2013 Service Pack 1
  • Microsoft Office 2016
masstens to hundreds of millions of endpoints (Office 2010 SP2/2013 SP1/2016 dominated desktop deployments at disclosure; current unpatched count unknown)
CVE-2017-0263
Win32k Use-After-Free Local Privilege Escalation in Windows 7 through Server 2016

CVE-2017-0263 is a use-after-free flaw (CWE-416) in the Windows kernel-mode drivers (Win32k) that allows a locally authenticated user to elevate privileges. It is triggered by running a specially crafted application that mishandles kernel memory on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 1507/1511/1607/1703, and Windows Server 2008 SP2/R2 SP1, Server 2012 Gold/R2, and Server 2016. Successful exploitation yields kernel-level privileges, effectively giving an attacker full control of the host and making it a common link in chained attacks alongside other bugs; related 2017 reporting associated the flaw with Sofacy (APT28) activity. Any unpatched Windows installation of the affected releases is affected, including long-lived legacy desktops and servers. The flaw is confirmed exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities Catalog (added 2022-02-10) — with two public PoC/exploit references and a ~10% EPSS probability of exploitation in the next 30 days (95th percentile).

Do: Apply Microsoft security updates per vendor instructions - this Win32k bug was fixed in the April 2017 Patch Tuesday release - prioritizing hosts where untrusted or low-privileged users can execute code (terminal/VDI servers, shared workstations, jump hosts). Windows 7/8.1 and Server 2008/2012 are past end of extended support, so use Extended Security Updates or migrate where patching in place is not possible. Verify installed builds against the affected version list above and close out the CISA KEV remediation requirement promptly.

7.810% KEV PoC ×2
  • microsoft windows 10 1507 (Gold), 1511, 1607, 1703
  • microsoft windows 7 SP1
  • microsoft windows 8.1 all versions at disclosure
  • +4 more
masshundreds of millions of devices (all unpatched Windows 7/8.1/RT 8.1 and Windows 10 1507-1703 PCs, plus the dominant Windows Server releases of that era)
CVE-2017-0272
+3 in the same advisory: …0277 …0278 …0279
The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and

The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0277, CVE-2017-0278, and CVE-2017-0279.

NVD description · AI analysis pending
8.1
group max
17%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2017-0290
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wi

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 does not properly scan a specially crafted file leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability."

NVD description · AI analysis pending
7.881% PoC ×2
  • microsoft forefront security
  • microsoft malware protection engine
  • microsoft windows defender
Full article707 words · extracted from thehackernews.com · click to collapse

Swati KhandelwalMay 10, 2017

As part of this month's Patch Tuesday, Microsoft has released security patches for a total of 55 vulnerabilities across its products, including fixes for four zero-day vulnerabilities being exploited in the wild.

Just yesterday, Microsoft released an emergency out-of-band update separately to patch a remote execution bug (CVE-2017-0290) in Microsoft's Antivirus Engine that comes enabled by default on Windows 7, 8.1, RT, 10 and Server 2016 operating systems.

The vulnerability, reported by Google Project Zero researchers, could allow an attacker to take over your Windows PC with just an email, which you haven't even opened yet.

May 2017 Patch Tuesday Out of 55 vulnerabilities, 17 have been rated as critical and affect the company's main operating systems, along with other products like Office, Edge, Internet Explorer, and the malware protection engine used in most of the Microsoft's anti-malware products.

Sysadmins all over the world should prioritize the May's Patch Tuesday as it addresses four critical zero-day vulnerabilities, three of which being actively exploited by cyber-espionage groups in targeted attacks over the past few months.

3 Zero-Days Were Exploited in the Wild by Russian Cyber-Espionage Group

First Zero-Day Vulnerability (CVE-2017-0261) It affects the 32- and 64-bit versions of Microsoft Office 2010, 2013 and 2016, and resides in how Office handles Encapsulated PostScript (EPS) image files, leading to remote code execution (RCE) on the system.

This Office vulnerability could be exploited by tricking victims into opening a file containing a malformed graphics image in an email. The attack also exploits a Windows privilege escalation bug (CVE-2017-0001) that the company patched on March 14 to gain full control over the system – essentially allowing attackers to install spyware and other malware.

According to the FireEye researchers, the CVE-2017-0261 flaw has been exploited since late March by an unknown group of financially motivated hackers and by a Russian cyber espionage group called Turla, also known as Snake or Uroburos.

Second Zero-Day Vulnerability (CVE-2017-0262) — FireEye and ESET researchers believe that the APT28 hacking group, also known as Fancy Bear, or Pawn Storm, was actively using this EPS-related Microsoft Office zero-day vulnerability which leads to remote code execution on opening a malformed file.

Third Zero-Day Vulnerability (CVE-2017-0263)The third zero-day bug is an elevation of privilege (EoP) vulnerability in all supported versions of Microsoft's Windows operating system.

This vulnerability exists in the way Windows kernel-mode driver handles objects in memory, allowing attackers to run arbitrary code in kernel mode and then install malware, view, change, or delete data, and even create new accounts with full user rights.

Researchers believe that the Russian cyber-espionage group was also actively exploiting this flaw (CVE-2017-0263) along with the second zero-day vulnerability (CVE-2017-0262).

Fourth Zero-Day Vulnerability (CVE-2017-0222)Another zero-day vulnerability affects Internet Explorer 10 and 11 and resides in how Internet Explorer handles objects in memory.

Opening a malicious web page can corrupt memory to trigger remote code execution, allowing attackers to take control of an affected system. According to the tech giant, this issue was also exploited in the wild.

Patches for Other Critical Vulnerabilities This month's security updates also fix critical vulnerabilities in both Edge and Internet Explorer (IE) that could lead to remote code execution by tricking victims into visiting malicious websites or viewing specially crafted advertisements inside the browsers.

Besides this, Microsoft also addresses four critical remote code execution bugs (CVE-2017-0272, CVE-2017-0277, CVE-2017-0278, and CVE-2017-0279) in Windows SMB network file-sharing protocol, which affects Windows 7 through 10 and Windows Server 2008 through 2016.

These vulnerabilities put Windows PCs and server installations at risk of hacking if they use SMBv1, though there have been no reports of any of these flaws exploited in the wild.

As usual, Adobe Flash Players patches are also included in the security update to address 7 CVE-listed flaws in the Windows, macOS, and Linux.

Windows users are strongly advised to install the latest updates as soon as possible in order to protect themselves against the active attacks in the wild.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2017/05/patch-windows-zero-days.html