Microsoft Patch Tuesday — Nov. 2019: Vulnerability disclosures and Snort coverage
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-12207 | Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2019-1384 | A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerability, an at A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerability, an attacker could send a specially crafted authentication request, aka 'Microsoft Windows Security Feature Bypass Vulnerability'. NVD description · AI analysis pending | 9.9 group max | 8% |
| — | ||
| CVE-2019-1020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none NVD description · AI analysis pending | — | — | — | — | ||
| CVE-2019-11135 | TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. NVD description · AI analysis pending | 6.5 | 3% |
| — | ||
| CVE-2019-1234 | A spoofing vulnerability exists when Azure Stack fails to validate certain requests, aka 'Azure Stack Spoofing Vulnerability'. A spoofing vulnerability exists when Azure Stack fails to validate certain requests, aka 'Azure Stack Spoofing Vulnerability'. NVD description · AI analysis pending | 7.5 | 75% |
| — | ||
| CVE-2019-1370 | An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Di An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'. NVD description · AI analysis pending | 5.5 | 2% |
| — | ||
| CVE-2019-1373 | A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code E A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'. NVD description · AI analysis pending | 9.8 | 21% |
| — | ||
| CVE-2019-1405 | Local Privilege Escalation in Microsoft Windows UPnP Service CVE-2019-1405 is a local privilege escalation flaw in the Microsoft Windows Universal Plug and Play (UPnP) service, caused by the service improperly allowing COM object creation. A local attacker with limited privileges, or an attacker who has already gained a low-privileged foothold (for example via another vulnerability), can trigger the flaw by creating a COM object through the UPnP service. Successful exploitation grants the attacker elevated privileges on the host, which in ransomware campaigns is used to move from a foothold to full control of the machine. All deployments of the affected Microsoft Windows products are in scope; specific version ranges are defined by Microsoft's security-update guidance rather than the alert data. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-15) with known ransomware use, and EPSS assigns it a high ~29.9% chance of exploitation in the next 30 days. Do: Apply the Windows security updates from Microsoft per vendor instructions on all endpoints, prioritizing user workstations and jump hosts where attackers gain initial footholds and escalate to SYSTEM. Because the flaw is a local escalation actively used in ransomware chains, combine patching with review of lateral-movement indicators (unusual service or COM object activity) and confirm hosts are running a cumulative update that includes the UPnP service fix. | 7.8 | 30% | KEV ransomware |
| masson the order of hundreds of millions to 1+ billion Windows devices potentially affected (Windows install base) | |
| CVE-2019-1429 +1 in the same advisory: …1390 | Memory corruption RCE in Microsoft Internet Explorer scripting engine CVE-2019-1429 is a memory corruption flaw (use-after-free/out-of-bounds write, CWE-416/CWE-787) in the way the Internet Explorer scripting engine handles objects in memory, allowing remote code execution. It is triggered remotely by convincing a user to view attacker-controlled web content — for example, a malicious website opened in Internet Explorer or an application embedding the IE engine — requiring no privileges but user interaction (CVSS 3.1 AV:N/AC:H/PR:N/UI:R). A successful exploit runs attacker code with the privileges of the logged-in user, enabling malware installation, data theft, and account compromise. Users of Internet Explorer on Windows are affected, since IE is present by default across Windows installations. The flaw was actively exploited as a zero-day at its November 2019 disclosure (associated with the Magnitude exploit kit per related coverage), carries a public proof-of-concept, and is listed in CISA's Known Exploited Vulnerabilities catalog. Do: Apply the November 2019 Microsoft security updates (Internet Explorer cumulative updates) per Microsoft's instructions, as required by the CISA KEV listing. Until patched, avoid browsing untrusted or attacker-influenced websites with Internet Explorer and consider directing users to Microsoft Edge instead of legacy IE. Given active in-the-wild use, prioritize this patch in your deployment schedule and verify IE cumulative updates are installed on all Windows endpoints. | 7.5 | 77% | KEV PoC |
| masshundreds of millions of Windows users (IE ships by default with Windows, and exploit kit delivery puts at least exposed users at broad scale) | |
| CVE-2019-1449 +1 in the same advisory: …1402 | A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components handle a specially crafted file, which could lead to a stand A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components handle a specially crafted file, which could lead to a standard user, any AppContainer sandbox, and Office LPAC Protected View to escalate privileges to SYSTEM.To exploit this bug, an attacker would have to run a specially crafted file, aka 'Microsoft Office ClickToRun Security Feature Bypass Vulnerability'. NVD description · AI analysis pending | 9.8 group max | 7% |
| — | ||
| CVE-2019-1441 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Win32k Graphics Remote Code A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Win32k Graphics Remote Code Execution Vulnerability'. NVD description · AI analysis pending | 8.8 group max | 13% |
| — | ||
| CVE-2019-1428 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Scripting Engin A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1429. NVD description · AI analysis pending | 7.5 group max | 10% |
| — | ||
| CVE-2019-1425 | An elevation of privilege vulnerability exists when Visual Studio fails to properly validate hardlinks while extracting archived files, aka 'Visual Studio Eleva An elevation of privilege vulnerability exists when Visual Studio fails to properly validate hardlinks while extracting archived files, aka 'Visual Studio Elevation of Privilege Vulnerability'. NVD description · AI analysis pending | 6.5 | 3% |
| — | ||
| CVE-2019-1442 | A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which coul A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'. NVD description · AI analysis pending | 5.5 | 2% |
| — | ||
| CVE-2019-1443 | An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint Server.An authenticat An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint Server.An authenticated attacker who successfully exploited this vulnerability could potentially leverage SharePoint functionality to obtain SMB hashes.The security update addresses the vulnerability by correcting how SharePoint checks file content., aka 'Microsoft SharePoint Information Disclosure Vulnerability'. NVD description · AI analysis pending | 6.5 | 6% |
| — | ||
| CVE-2019-1445 +1 in the same advisory: …1447 | A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoo A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1447. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2019-1448 +1 in the same advisory: …1446 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remo A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. NVD description · AI analysis pending | 7.8 group max | 30% |
| — |
Full article591 words · extracted from blog.talosintelligence.com · click to collapse
Tuesday, November 12, 2019 14:58
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing a variety of vulnerabilities in several of its products. The latest Patch Tuesday discloses 75 vulnerabilities, 13 of which are considered "critical," with the rest being deemed "important."
This month’s security update covers security issues in a variety of Microsoft services and software, including the Scripting Engine, the Windows Hyper-V hypervisor, and Win32. Cisco Talos discovered one of these vulnerabilities, CVE-2019-1448 —a remote code execution vulnerability in Microsoft Excel. For more on this bug, read our full Vulnerability Spotlight here. We are also disclosing a remote code execution vulnerability in Microsoft Media Foundation.
Talos also released a new set of SNORTⓇ rules that provide coverage for some of these vulnerabilities. For more, check out the Snort blog post here.
Critical vulnerabilities Microsoft disclosed 13 critical vulnerabilities this month, nine of which we will highlight below.
CVE-2019-0721, CVE-2019-1389, CVE-2019-1397 and CVE-2019-1398 are all vulnerabilities in Windows Hyper-V that could allow an attacker to remotely execute code on the victim machine. These bugs arise when Hyper-V on a host server improperly validates input from an authenticated user on a guest operating system. An attacker can exploit these vulnerabilities by running a specially crafted application on a guest OS. This could allow a malicious user to escape the hypervisor or a sandbox.
CVE-2019-1390 is a remote code execution vulnerability in VBScript. This vulnerability could allow an attacker to corrupt memory in a way that would enable them to execute remote code in the context of the current user. A user could trigger this vulnerability by visiting an attacker-created website while using the Internet Explorer browser, or by opening an Office document or application that contains an ActiveX control marked "safe for initialization."
CVE-2019-1426, CVE-2019-1427, CVE-2019-1428 and CVE-2019-1429 are memory corruption vulnerabilities in the Microsoft Scripting Engine that could lead to remote code execution. The bugs exist in the way the Microsoft Edge web browser handles objects in memory. A user could trigger these vulnerabilities by visiting an attacker-controlled website in Edge.
The four other critical vulnerabilities are:
Important vulnerabilities This release also contains 62 important vulnerabilities, one of which we will highlight below.
CVE-2019-1020 is a security feature bypass vulnerability in the Windows secure boot process. An attacker could run a specially crafted application to bypass secure boot and load malicious software. This security update fixes the issue by blocking vulnerable third-party bootloaders. An update also needs to be applied to Windows Defender.
The other important vulnerabilities are:
- CVE-2018-12207
- CVE-2019-0712
- CVE-2019-11135
- CVE-2019-1234
- CVE-2019-1309
- CVE-2019-1310
- CVE-2019-1324
- CVE-2019-1370
- CVE-2019-1374
- CVE-2019-1379
- CVE-2019-1380
- CVE-2019-1381
- CVE-2019-1382
- CVE-2019-1383
- CVE-2019-1384
- CVE-2019-1385
- CVE-2019-1388
- CVE-2019-1391
- CVE-2019-1392
- CVE-2019-1393
- CVE-2019-1394
- CVE-2019-1395
- CVE-2019-1396
- CVE-2019-1399
- CVE-2019-1402
- CVE-2019-1405
- CVE-2019-1406
- CVE-2019-1407
- CVE-2019-1408
- CVE-2019-1409
- CVE-2019-1411
- CVE-2019-1412
- CVE-2019-1413
- CVE-2019-1415
- CVE-2019-1416
- CVE-2019-1417
- CVE-2019-1418
- CVE-2019-1420
- CVE-2019-1422
- CVE-2019-1423
- CVE-2019-1424
- CVE-2019-1425
- CVE-2019-1432
- CVE-2019-1433
- CVE-2019-1434
- CVE-2019-1435
- CVE-2019-1436
- CVE-2019-1437
- CVE-2019-1438
- CVE-2019-1439
- CVE-2019-1440
- CVE-2019-1442
- CVE-2019-1443
- CVE-2019-1445
- CVE-2019-1446
- CVE-2019-1447
- CVE-2019-1448
- CVE-2019-1449
- CVE-2019-1456
- CVE-2019-0721
- CVE-2019-1373
Coverage In response to these vulnerability disclosures, Talos is releasing a new SNORTⓇ rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Firepower customers should use the latest update to their ruleset by updating their SRU. Open Source Snort Subscriber Rule Set customers can stay up-to-date by downloading the latest rule pack available for purchase on Snort.org.
These rules are: 46548, 46549, 52205 - 52209, 52212, 52213, 52216, 52217 - 52225, 52228 - 52234, 52239, 52240
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-nov-2019/