ZeroHour
Security Affairspublished ()ingested @securityaffairs

Microsoft Patch Tuesday for August 2023 fixed 2 actively exploited flaws

criticalVulnerability exploited in the wildimportance 60CVE-2023-36884CVE-2023-38180CVE-2023-35385

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-35385
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.82%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2023-36884
Race Condition RCE in Microsoft Windows Search

CVE-2023-36884 is a race condition (TOCTOU) vulnerability in Microsoft Windows Search that permits remote code execution, rated 7.5 (high) on CVSS 3.1. It is triggered over the network with user interaction — for example, when a user opens or interacts with a specially crafted document that causes the vulnerable search code path to race, allowing arbitrary code execution in the context of the current user. An attacker gains code execution on the victim's Windows system, which the RomCom threat actor chained with Firefox flaws to deploy backdoors against political targets, and CISA notes known ransomware use. Virtually every supported Windows client and server release at the time is affected, spanning Windows 10 1507 through 22H2, Windows 11 21H2/22H2, and Windows Server 2008 through 2022. The flaw was actively exploited as a zero-day before being fixed in the July 2023 Patch Tuesday; it was added to the CISA KEV catalog on 2023-07-17 and carries a 98.9% EPSS score (100th percentile).

Do: Apply the July 2023 Patch Tuesday Windows security updates to all Windows 10, Windows 11, and Windows Server systems, prioritizing high-value and frequently attacked endpoints since the bug was exploited as a zero-day by RomCom and carries a KEV deadline (US civilian agencies were directed to remediate by August 1, 2023). Because exploitation requires user interaction, caution users against opening untrusted documents, and verify patch status via your patch management or vulnerability scanner against the KEV requirement. If patching is not possible, follow vendor mitigations per CISA's required action or discontinue use.

7.599% KEV ransomware
  • microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • microsoft Windows 11 21H2, 22H2
  • microsoft Windows Server 2008 as listed in the CPE data
  • +4 more
mass≈1 billion+ Windows devices (Windows 10/11 installed base) plus the enterprise Windows Server estate
CVE-2023-38180
Unauthenticated DoS in Microsoft .NET, ASP.NET Core and Visual Studio 2022

CVE-2023-38180 is a denial-of-service vulnerability in Microsoft .NET and Visual Studio 2022 caused by uncontrolled resource consumption (CWE-400). Per the CVSS vector, a remote, unauthenticated attacker can trigger it over the network with no privileges or user interaction required, causing affected applications or services to exhaust resources and become unavailable. The attacker gains only availability impact (high availability severity, no confidentiality or integrity impact), but this can take down ASP.NET Core web applications and other .NET-based services. Any organization running vulnerable .NET runtimes, ASP.NET Core applications, or Visual Studio 2022 is exposed, and Fedora also ships affected .NET packages. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-08-09, it was among the two actively exploited flaws fixed in Microsoft's August 2023 Patch Tuesday, and EPSS assigns a 14.0% 30-day exploitation probability (96th percentile).

Do: Apply the August 2023 Microsoft security updates for all affected .NET, ASP.NET Core, and Visual Studio 2022 versions listed in Microsoft's advisory, and install the updated .NET packages on Fedora; because this flaw is in CISA's KEV catalog, the required action is to apply vendor mitigations or discontinue use of the product if mitigations are unavailable. After updating, rebuild or restart .NET applications so they run on the patched runtime, and monitor internet-facing .NET services for signs of resource-exhaustion denial-of-service. No public proof-of-concept is known, but active exploitation has been reported, so patching should be treated as urgent.

7.514% KEV
  • microsoft .NET / .NET Core (including ASP.NET Core workloads)
  • microsoft ASP.NET Core
  • microsoft Visual Studio 2022
  • +1 more
masshundreds of millions of potential installations (ubiquity of the .NET runtime and ASP.NET Core in server and web deployments)
Full article586 words · extracted from securityaffairs.com · click to collapse

Microsoft Patch Tuesday security updates for August 2023 addressed 74 vulnerabilities, including two actively exploited flaws.

Microsoft Patch Tuesday security updates for August 2023 addressed 74 new vulnerabilities in multiple products including Windows and Windows Components; Edge (Chromium-Based); Exchange Server; Office and Office Components; .NET and Visual Studio; ASP.NET; Azure DevOps and HDInsights; Teams; and Windows Defender. The company also fixed 11 flaws in Chromium group for Edge (Chromium-Based) and a fix for AMD.

“This volume of fixes is the highest we’ve seen in the last few years, although it’s not unusual to see Microsoft ship a large number of patches right before the Black Hat USA conference. It will be interesting to see if the August release, which comes the day before the Black Hat briefings, will also be a large release.” reads the report published by ZDI.

Six of the flaws addressed by Microsoft are rated Critical and 67 are rated Important in severity.

Most of flaws, 23, are Remote Code Execution vulnerabilities, followed by 18 Elevation of Privilege vulnerabilities and 12 Spoofing vulnerabilities.

Two of the vulnerabilities addressed by Microsoft are actively exploited in the wild.

Microsoft has released an Office Defense in Depth update (ADV230003) to address a patch bypass of the actively exploited RCE vulnerability CVE-2023-36884.

In July, Microsoft disclosed an unpatched zero-day vulnerability in multiple Windows and Office products that has been actively exploited in the wild. The issue, tracked as CVE-2023-36884, was exploited by nation-state actors and cybercriminals to gain remote code execution via malicious Office documents.

The IT giant is investigating reports of a series of remote code execution vulnerabilities impacting Windows and Office products. The company revealed that it is aware of high-targeted attacks that attempt to exploit these issues through specially-crafted Office documents.

“An attacker could create a specially crafted Microsoft Office document that enables them to perform remote code execution in the context of the victim. However, an attacker would have to convince the victim to open the malicious file.” reads the advisory published by Microsoft. “Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This might include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs.”

Microsoft announced in a separate post, the identification of a phishing campaign conducted by the Russian cybercrime group Storm-0978 (aka DEV-0978 and RomCom) and aimed at defense and government entities in Europe and North America. The threat actors were observed exploiting the flaw CVE-2023-36884 using lures related to the Ukrainian World Congress.

“Additionally, based on attributed phishing activity, Storm-0978 has acquired exploits targeting zero-day vulnerabilities. Identified exploit activity includes abuse of CVE-2023-36884, including a remote code execution vulnerability exploited via Microsoft Word documents in June 2023, as well as abuse of vulnerabilities contributing to a security feature bypass.” reads the post.

Microsoft also addressed an actively exploited .NET and Visual Studio Denial of Service vulnerability tracked as CVE-2023-38180.

Some of the most severe vulnerabilities fixed by Microsoft are threee Microsoft Message Queuing Remote Code Execution issues tracked as CVE-2023-35385/36910/36911 (CVSS of 9.8). A remote anonymous attacker can trigger the flaws to execute malicious code on an affected server at the level of the Message Queuing service.

The full list of vulnerabilities released by Microsoft for August 2023 is available here.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Microsoft Patch Tuesday)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/149299/security/microsoft-patch-tuesday-august-2023.html