ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-0088
Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to execute arbitrary code on the host OS via a crafted a

Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to execute arbitrary code on the host OS via a crafted application, aka "Hyper-V Remote Code Execution Vulnerability."

NVD description · AI analysis pending
9.38%
  • microsoft windows 10
  • microsoft windows 8.1
  • microsoft windows server 2012
CVE-2016-0127
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office Compatibility Pack SP3, Word Viewer, Word Automation Services o

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

NVD description · AI analysis pending
7.820%
  • microsoft office
  • microsoft office compatibility pack
  • microsoft office web apps server
  • +1 more
CVE-2016-0145
+1 in the same advisory: …0148
The font library in Microsoft Windows Vista SP2;

The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold and 1511; Office 2007 SP3 and 2010 SP2; Word Viewer; .NET Framework 3.0 SP2, 3.5, and 3.5.1; Skype for Business 2016; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; and Live Meeting 2007 Console allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Graphics Memory Corruption Vulnerability."

NVD description · AI analysis pending
8.8
group max
43%
  • microsoft .net framework
  • microsoft live meeting
  • microsoft lync
  • +1 more
CVE-2016-0153
OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 allows r

OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 allows remote attackers to execute arbitrary code via a crafted file, aka "Windows OLE Remote Code Execution Vulnerability."

NVD description · AI analysis pending
7.821%
  • microsoft windows 7
  • microsoft windows 8.1
  • microsoft windows rt 8.1
  • +1 more
Full article730 words · extracted from blog.talosintelligence.com · click to collapse

Tuesday, April 12, 2016 16:12


Bulletins MS16-037 through MS16-040 and bulletins MS16-042, MS16-050 are rated as critical in this month's release.

MS16-037 is related to six vulnerabilities in Internet Explorer. The most severe vulnerabilities allow an attacker to craft a website that executes arbitrary code on the victim's device due to the memory corruption vulnerabilities in the browser. The attacker would be limited to executing code with same administrative rights as the current user, but with many users having full administrator rights, an attacker could use this to take full control of a device. To exploit the vulnerability the attacker must get the victim to view attacker controlled content. Previously, this has not proved a major limitation for attackers. Attackers have proved adept at sending spam messages, compromising legitimate websites and abusing web advertising networks to redirect users to malicious websites.


MS16-038 addresses five additional remote code execution vulnerabilities in Microsoft's Edge browser, and one vulnerability common to IE and Edge, which is also described in MS16-037. The most severe of these vulnerabilities also allow attacker to execute arbitrary code on a victim's device due to memory corruption vulnerabilities. Attackers could craft a malicious website to exploit the vulnerabilities on victim's devices as previously described.

MS16-039 addresses three important escalation of privilege vulnerabilities in the Windows Kernel mode driver, and the critical vulnerability, CVE-2016-0145 in the Windows font library which allows remote code execution. Vulnerabilities in embedded fonts have previously been found and patched, notably the remote code vulnerability of July 2015 disclosed in the out of band update MS15-078, and the font vulnerabilities addressed in MS13-053 and MS13-054 from July 2013. Exploits in embedded fonts are a particularly useful vector for attackers since they can be included in both malicious websites and Microsoft Office documents.

Further remote code execution vulnerabilities are addressed by MS16-040 and MS16-042. XML Core Services is vulnerable to specially crafted XML code being used to execute arbitrary code, as addressed in MS16-040. Microsoft Office is vulnerable to four separate remote code execution vulnerabilities addressed in MS16-042. The only of these rated as critical rather than important is CVE-2016-0127 which is exploitable via the Preview Pane.

MS16-050 is Microsoft's response to Adobe's Security Bulletin APSB16-10, and address ten different vulnerabilities in the Adobe Flash Player on multiple versions of Windows 8.1, Windows Server 2012 and Windows 10. One of these vulnerabilities is currently being exploited by the Magnitude Exploit Kit. Helpfully, the bulletin contains instructions for disabling Flash Player by modifying the registry, and through applying a Group Policy. Administrators may wish to carefully consider the risks and benefits of using these techniques to remove Flash Player from devices for which they are responsible.

Bulletins Rated Important
Microsoft bulletins MS16-041 and bulletins MS16-044 through to MS16-049 are rated as important.

MS16-041 addresses CVE-2016-0148 within Microsoft's .NET framework. On some Microsoft operating systems this vulnerability can be used for remote code execution, but only if the attacker already has access to the local system. In some environments the vulnerability can be used to conduct a denial of service attack, other Microsoft operating systems are unaffected by this vulnerability.

MS16-044 addresses CVE-2016-0153, a remote code execution vulnerability within Microsoft OLE. Windows 10 is unaffected by this vulnerability.

MS16-045 addresses three vulnerabilities in Hyper-V. CVE-2016-0088 allows a user on a guest operating system to execute arbitrary code on the Hyper-V host. Two further vulnerabilities allow users on guest operating systems to read memory information from the Hyper-V operating system.

MS16-046 addresses a vulnerability within Windows 10 that permits an authenticated user to escalate their privileges and execute arbitrary code as an administrator. MS16-048 addresses a further escalation of privilege vulnerability in the management of process tokens in memory of the Client-Server Run-time Subsystem which allows an authenticated user to bypass security features and execute code as an administrator.

MS16-047 addresses a potential exploit where an attacker could launch a man-in-the-middle attack to downgrade the authentication of the RPC channel in order to impersonate an authenticated user. By exploiting this vulnerability in the Security Account Manager and Local Security Authority Domain Policy remote protocols the attacker could then access the Security Account Manager database.

MS16-049 addresses a denial of service attack in the HTTP 2.0 protocol stack (HTTP.sys) of Windows 10. An attacker could create a specially crafted HTTP 2.0 request that would lead vulnerable systems to become unresponsive.

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/ms-tuesday-63063210e63ef5e7e1ec3158/