March Patch Tuesday closes record number of vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-0149 | Memory Corruption RCE in Microsoft Internet Explorer A memory corruption flaw (CWE-119) in Microsoft Internet Explorer mishandles memory when the browser processes web content. An attacker triggers it by luring a user to a specially crafted website, corrupting browser memory in a way that permits remote code execution in the context of the current user or a crash (denial of service). Successful exploitation gives the attacker code execution under the victim's privileges, yielding a foothold in the user's environment, including elevated access if an administrator is browsing. Internet Explorer versions 9 through 11 (per vendor advisory) are affected, with residual exposure concentrated in legacy Windows 7/8.x and Windows Server estates and in the IE11 component still present on Windows 10. The flaw is confirmed exploited in the wild, having been added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-24, and EPSS estimates a ~29% probability of exploitation within 30 days (98th percentile); no public PoC is known. Do: Install Microsoft's cumulative security update for Internet Explorer (the fix shipped in the March 2017 Patch Tuesday cumulative IE updates) on legacy Windows 7/8.x/Server hosts, and ensure Windows 10 devices are fully current via cumulative Windows updates. Inventory for legacy Windows machines and servers with unpatched IE, and prioritize migration to Microsoft Edge (using IE Mode only where required) since IE11 is retired. Where IE must remain in use, harden it with attack surface reduction rules and discourage or restrict browsing of untrusted sites in IE. | 8.8 | 29% | KEV |
| masstens of millions of users (IE11 ships with/historically shipped with hundreds of millions of Windows devices, with active usage concentrated in legacy and… |
Full article259 words · extracted from helpnetsecurity.com · click to collapse
With no February Patch Tuesday, it was to be expected that Microsoft would fix a huge number of security issues in March. They didn’t disappoint: 139 unique CVEs have been resolved.

As announced before, the information was released through the company’s Security Update Guide, but they’ve also decided to publish security bulletins (a total of 18) this month, “to give customers extra time to ensure they are ready to transition their processes.”
The March security release consists of security updates a wide variety of Microsoft offerings. Of these, those for Internet Explorer, Microsoft Edge, for several issues in Windows, and Adobe Flash Player are considered of “critical” importance – one vulnerability
“Probably the most “scary” set of vulnerabilities in this update are CVE 2017-0143, CVE 2017-0144, CVE 2017-0145, CVE 2017-0146, CVE 2017-0148,” notes SANS ISC CTO Johannes Ullrich.
They are remote code execution vulnerabilities that exist in the way that the Microsoft Server Message Block 1.0 (SMBv1) server handles certain requests, and could allow unauthenticated attackers to execute arbitrary code on the target server.
“Microsoft rates the exploitability with ‘1’, indicating that it wouldn’t be terribly difficult to develop an exploit for these,” he pointed out.
The two zero-day vulnerabilities for which PoC exploit code was released last month have also been patched.
All in all, the Internet Explorer update is the most critical, as one of the fixed bugs (CVE-2017-0149) is under active attack and leads to remote code execution.
Trend Micro’s Dustin Childs offered a helpful rundown on which updates admins should prioritize.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2017/03/15/march-patch-tuesday/