ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-0106
+1 in the same advisory: …0204
Microsoft Excel 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to execute arbitrary code or

Microsoft Excel 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

NVD description · AI analysis pending
7.8
group max
28%
  • microsoft outlook
CVE-2017-0155
The Graphics component in the kernel in Microsoft Windows Vista SP2;

The Graphics component in the kernel in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Graphics Elevation of Privilege Vulnerability."

NVD description · AI analysis pending
7.02%
  • microsoft windows 7
  • microsoft windows server 2008
  • microsoft windows vista
CVE-2017-0166
An elevation of privilege vulnerability exists in Windows when LDAP request buffer lengths are improperly calculated.

An elevation of privilege vulnerability exists in Windows when LDAP request buffer lengths are improperly calculated. In a remote attack scenario, an attacker could exploit this vulnerability by running a specially crafted application to send malicious traffic to a Domain Controller, aka "LDAP Elevation of Privilege Vulnerability."

NVD description · AI analysis pending
8.1
group max
6%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2017-0160
Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system to execute malicious code, aka ".NET Remo

Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system to execute malicious code, aka ".NET Remote Code Execution Vulnerability."

NVD description · AI analysis pending
7.818%
  • microsoft .net framework
CVE-2017-0194
Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, and Office Compatibility Pack SP2 allow remote attackers to obtain sensitive information from process memory

Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, and Office Compatibility Pack SP2 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."

NVD description · AI analysis pending
5.526%
  • microsoft excel
  • microsoft office compatibility pack
CVE-2017-0197
Microsoft OneNote 2007 SP3 and Microsoft OneNote 2010 SP2 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office DLL Loa

Microsoft OneNote 2007 SP3 and Microsoft OneNote 2010 SP2 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office DLL Loading Vulnerability."

NVD description · AI analysis pending
7.819%
  • microsoft onenote
CVE-2017-0199
Remote Code Execution in Microsoft Office and WordPad via crafted document files

CVE-2017-0199 is a remote code execution vulnerability in Microsoft Office and WordPad that stems from improper parsing of specially crafted files. Attackers trigger it by getting a user to open a malicious document, after which attacker-controlled code executes with the privileges of the logged-in user. Anyone running the affected Microsoft Office or WordPad software is exposed, and CISA notes the flaw has been leveraged in ransomware campaigns; no CVSS score is available in the source data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and EPSS assigns a 99.9% probability of exploitation within 30 days (100th percentile), indicating active, ongoing exploitation.

Do: Apply Microsoft's security updates for Office and Windows per vendor instructions, as required by CISA's KEV catalog; the flaw was publicly reported as fixed in Microsoft's April 2017 security updates. Until patched, treat unsolicited Office documents and email attachments as high-risk, since exploitation requires a user to open a crafted file. Verify that all Office and WordPad installations across the estate—especially endpoints that handle untrusted documents—have received the update.

7.8100% KEV ransomware PoC ×6
  • Microsoft Office
  • Microsoft WordPad
masshundreds of millions of Office installations worldwide (exact count unknown)
CVE-2017-0205
+1 in the same advisory: …0200
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory.

A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user, aka "Microsoft Edge Memory Corruption Vulnerability."

NVD description · AI analysis pending
7.524%
  • microsoft edge
CVE-2017-0210
+2 in the same advisory: …0202 …0201
Cross-Domain Privilege Escalation in Microsoft Internet Explorer

CVE-2017-0210 is a privilege elevation flaw caused by Internet Explorer failing to properly enforce cross-domain policies, breaking the isolation between security zones/domains in the browser. It is triggered when a user views malicious or attacker-controlled web content in Internet Explorer, allowing content from one domain to reach resources that should be restricted to another domain or zone. Successful exploitation lets an attacker access information across those boundaries and gain elevated privileges within the browser context, which is commonly chained with other flaws for fuller compromise. Any user running affected versions of Internet Explorer on Windows is affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-24), indicating known exploitation in the wild, with a 22.3% EPSS probability of exploitation in the next 30 days (98th percentile).

Do: Apply Microsoft security updates per vendor instructions (the latest cumulative Internet Explorer security updates on all supported Windows versions still in use), since CISA's required action is to apply updates. Audit your environment for systems still launching IE or embedded WebBrowser/IE-based content, restrict or retire IE usage, and migrate users to a supported modern browser (e.g., Edge, using IE mode only for legacy intranet apps) to reduce exposure.

8.8
group max
22% KEV
  • Microsoft Internet Explorer
masstens of millions of Windows endpoints (IE shipped with all Windows versions in use during the affected period and remains present on large numbers of…
Full article685 words · extracted from blog.talosintelligence.com · click to collapse

Tuesday, April 11, 2017 23:11

It’s that time again! Today we bring you April’s Microsoft Patch Tuesday information. These fixed vulnerabilities affect Outlook, Edge, Internet Explorer, Hyper-V, .NET, and Scripting Engine.

Bulletins Rated Critical

CVE-2017-0106 outlines a vulnerability in Microsoft Word. It permits the bypass of
security features when document loading is done via Outlook attachments for
certain crafted emails. Successful exploitation of this issue may grant an
attacker remote code execution.

CVE-2017-0158 details a vulnerability caused by certain malicious HTML files with VBScript content. Successful exploitation of this issue may grant an attacker remote code execution.

CVE-2017-0160 outlines a compromised WMI server accessed over DCOM using System.Management classes or the Powershell Get-WmiObject Cmdlet, which can lead to arbitrary .NET serialization remote code execution.

CVE-2017-0199 details a remote code execution vulnerability exists in the way that Microsoft Office and WordPad parse specially crafted files. An attacker who successfully exploited this vulnerability could take control of an affected system and could then install programs; view, change, or delete data; or create new accounts with full user rights.

CVE-2017-0200 covers a remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user.

CVE-2017-0201 details a remote code execution vulnerability exists in the way that the JScript and VBScript engines render when handling objects in memory in Internet Explorer. Due to a Javascript type confusion bug which exists it is possible to corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user.

CVE-2017-0202 outlines a type confusion vulnerability that exists in Internet Explorer which results in an Out-of-Bounds read.

CVE-2017-0205 details a render format type-confusion vulnerability in Edge 11 on Windows that causes an access violation. Successful exploitation of this vulnerability could lead to arbitrary code execution.

Bulletins Rated Important

CVE-2017-0155 outlines an out-of-bounds memory write vulnerability in Windows DDI (Device Driver Interface) that affects Windows and causes a kernel crash.

CVE-2017-0156 details a NULL-dereference vulnerability was discovered in Windows. The root cause of the vulnerability is in dxgkrnl.sys, which runs in kernel mode. Successful exploitation of this vulnerability can result in EOP (Escalation-of-Privilege) in older Windows versions.

CVE-2017-0165 covers an arbitrary directory / file deletion elevation of privilege vulnerability in IEETWCollector that affects Windows 10. Successful exploitation of the vulnerability could lead to arbitrary code execution.

CVE-2017-0166 details a buffer overrun vulnerability in Microsoft LDAP implementation.

CVE-2017-0167 outlines an uninitialized memory read vulnerability in Windows kernel. Successful exploitation of the vulnerability could result in potential information leakage.

CVE-2017-0188 outlines an Integer overflow in Windows Graphics Device Interface (GDI) which causes an out-of-bounds read resulting in a kernel crash.

CVE-2017-0189 details an out-of-bounds write vulnerability in Windows DDI (Device Driver Interface) that when successfully exploited causes a kernel crash.

CVE-2017-0192 outlines an out-of-bounds read that affects the ATMFD (Adobe Type Manager Font Driver) in Windows.

CVE-2017-0194 details an out-of-bounds memory read vulnerability which exists in Excel.

CVE-2017-0197 covers a vulnerability in Microsoft Office OneNote 2007 that is vulnerable to DLL sideloading, which an attacker could leverage to gain remote code execution.

CVE-2017-0204 outlines a vulnerability was discovered in Microsoft Word which permits the bypass of security features when document loading is done via Outlook attachments for certain crafted emails. Successful exploitation of this issue may grant an attacker remote code execution.

CVE-2017-0210 details a vulnerability in Internet Explorer 11 htmlFile ActiveX control that results in a universal cross-site scripting (UXSS) condition.

CVE-2017-0211 highlights a privilege escalation vulnerability in Microsoft Windows OLE which could allow an application with limited privileges on an affected system to execute code.

Coverage
In response to these bulletin disclosures, Talos is releasing the following rules to address these vulnerabilities. Please note that additional rules may be released at a future date and current rules are subject to change pending additional vulnerability information. For the most current rule information, please refer to your Management Center or Snort.org.

Snort SIDs: 41962-41963, 41997-41998, 42148-42151, 42152-42168, 42173-42174, 42183-42190, 42199-42200, 42204-42205, and 42208-42211

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/ms-tuesday-63063210e63ef5e7e1ec314d/