Microsoft Patch Tuesday
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2016-0142 | Video Control in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute Video Control in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute arbitrary code via a crafted web page, aka "Microsoft Video Control Remote Code Execution Vulnerability." NVD description · AI analysis pending | 7.8 group max | 20% |
| — | ||
| CVE-2016-3209 | Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; Live Meeting 2007 Console; .NET Framework 3.0 SP2, 3.5, 3.5.1, 4.5.2, and 4.6; and Silverlight 5 allows remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "True Type Font Parsing Information Disclosure Vulnerability." NVD description · AI analysis pending | 5.5 | 54% |
| — | ||
| CVE-2016-7182 | The Graphics component in Microsoft Windows Vista SP2; The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Console allows attackers to execute arbitrary code via a crafted True Type font, aka "True Type Font Parsing Elevation of Privilege Vulnerability." NVD description · AI analysis pending | 9.8 group max | 30% |
| — | ||
| CVE-2016-3298 | Information Disclosure in Microsoft Internet Explorer Messaging API CVE-2016-3298 is an information disclosure flaw (CWE-200) in the Microsoft Internet Messaging API used by Internet Explorer, in which the API improperly handles objects in memory. Exploitation requires driving Internet Explorer to process attacker-influenced content so the Messaging API mishandles memory, after which the attacker can probe whether specific files exist on the victim's disk. An attacker gains only limited reconnaissance value — confirming file presence for fingerprinting — rather than code execution or direct data theft. Only systems running Microsoft Internet Explorer, as cataloged by CISA, are affected; CISA added the bug to the Known Exploited Vulnerabilities catalog on 2022-05-24, confirming exploitation in the wild, though any ransomware association is unknown. EPSS estimates a 32.8% probability of exploitation within 30 days (98th percentile), no public proof-of-concept is known, and a CVSS score has not yet been published in this dataset. Do: Apply Microsoft's security update for CVE-2016-3298 per vendor instructions, as mandated by the CISA KEV catalog (added 2022-05-24, so remediation deadlines apply to federal agencies and many regulated environments). Audit any Windows hosts where Internet Explorer is still used for interactive browsing and confirm the patch is installed; because the flaw only permits probing for file existence, residual risk after patching is low. | 6.5 | 33% | KEV |
| masshundreds of millions of Windows devices (Internet Explorer shipped as a built-in Windows component for decades) | |
| CVE-2016-3393 | Remote Code Execution in Microsoft Windows GDI/GDI+ Graphics Component CVE-2016-3393 is a remote code execution vulnerability in the Windows Graphics Device Interface (GDI/GDI+), the component that renders text, images and graphics across Windows. An attacker triggers it by getting a user to visit a crafted website or otherwise view attacker-supplied content that is rendered through GDI (the CVSS vector confirms user interaction is required), and successful exploitation yields arbitrary code execution in the context of the current user. Affected software spans essentially the entire Windows estate of the era: Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 1507/1511/1607, and Windows Server 2008 SP2 and R2 SP1 and Server 2012 and 2012 R2. The flaw was patched in Microsoft's November 2016 Patch Tuesday, which fixed five zero-days being exploited in the wild, and reporting at the time attributed exploitation of this Windows graphics zero-day to the FruityArmor APT in targeted attacks. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-25), has a high EPSS score (68.7%, 99th percentile), and no public proof-of-concept is known. Do: Apply the November 2016 Microsoft security updates for the Windows Graphics Component to every affected Windows client and server version, per vendor instructions and CISA KEV's required action. For versions past end of support (Vista, 7, 8.1, RT 8.1, Server 2008/2012), move to a supported Windows release or apply Extended Security Updates. Until patched, discourage users from visiting untrusted websites or opening untrusted documents/images, and prioritize remediation on internet-facing servers and endpoints used by high-value users, given the documented targeted-attack use by the FruityArmor APT. | 7.8 | 69% | KEV |
| mass~hundreds of millions of Windows PCs and servers at the time of disclosure (affected versions spanned nearly the entire Windows installed base); today the… | |
| CVE-2016-7193 | Memory Corruption RCE in Microsoft Word and Office Components via Crafted RTF Files Microsoft Word and several related Office components contain a memory corruption flaw (CWE-119) in their handling of Rich Text Format (RTF) documents. An attacker triggers it by persuading a user to open a specially crafted RTF file, typically delivered as an email attachment, which corrupts memory and permits arbitrary code execution in the context of the current user (CVSS 3.1: 7.8, with user interaction required). The affected footprint is unusually broad, spanning Word 2007 SP2 through Word 2016 on Windows, Word for Mac 2011 and 2016, Word Viewer, the Office Compatibility Pack, Word Automation Services in SharePoint 2010/2013, and Office Web Apps/Office Online Server. The vulnerability is listed in the CISA Known Exploited Vulnerabilities catalog (added 2022-03-03) and carries an EPSS of 57.7 percent (99th percentile), indicating active in-the-wild exploitation; Microsoft addressed it in its November 2016 security updates. Do: Apply Microsoft's security updates for every affected component per vendor instructions, which is the required action in CISA's KEV catalog. Because exploitation occurs via malicious RTF files, consider blocking or sandboxing RTF email attachments and opening them in a protected/isolated mode until patches are deployed. Audit for legacy and easily overlooked components, including Word Viewer, the Office Compatibility Pack, Office Web Apps 2010/2013, SharePoint Word Automation Services, and Office Online Server, and upgrade or decommission any that remain unpatched. | 7.8 | 58% | KEV |
| masshundreds of millions of Office/Word installations worldwide (order of magnitude 10^8) |
Full article785 words · extracted from blog.talosintelligence.com · click to collapse
Tuesday, October 11, 2016 16:57
Patch Tuesday has once again arrived! Microsoft's monthly release of security bulletins to address vulnerabilities provides fixes for 37 newly disclosed security flaws. Today's release sees a total of 10 bulletins with five of the bulletins rated critical and address vulnerabilities in Edge, Graphics Component, Internet Explorer, Video Control, and Adobe Flash Player. Four bulletins are rated important and address flaws in Office, Windows Diagnostic Hub, Windows Kernel-Mode Drivers, and Windows Registry. One bulletin is rated moderate and addresses a flaw in Microsoft Internet Messaging API.
Bulletins Rated Critical The following bulletins are rated critical: MS16-118, MS16-119, MS16-120, MS16-122, MS16-127
MS16-118 and MS16-119 are this month's bulletins for Internet Explorer and Edge respectively. The Internet Explorer bulletin fixes 11 vulnerabilities while the Edge bulletin fixes 13 vulnerabilities. Seven vulnerabilities were found to affect both Edge and IE. The majority of the vulnerabilities fixed are memory corruption flaws that could lead to arbitrary code execution. Several privilege escalation and information disclosure flaws were also fixed in this month's release.
MS16-120 addresses seven vulnerabilities in the Microsoft Graphics Component. Two of the vulnerabilities, CVE-2016-3393 and CVE-2016-3396, are arbitrary code execution flaws in the GDI component and font library respectively. Exploitation of these two flaws is achievable if a user navigates to a specifically crafted website or opens a specifically crafted file that is designed to exploit these flaws. Two privilege escalation flaws, CVE-2016-3270 and CVE-2016-7182, were also addressed where a flaw in how TrueType fonts are parsed or a specifically crafted application could elevate the user's privilege to that of an administrator. The remaining three vulnerabilities (CVE-2016-3209, CVE-2016-3262, CVE-2016-3263) are information disclosure flaws that could be used circumvent ASLR.
MS16-122 addresses CVE-2016-0142, an arbitrary code execution vulnerability in Microsoft Video Control. This vulnerability manifests as a failure to properly handle objects in memory and could be exploited if a user opens a specifically crafted file or launches a malicious executable. Attack scenarios where this might occur are email-based attacks or if a user downloads a file/executable and opens it on their machine.
MS16-127 updates the embedded Adobe Flash Player in Internet Explorer and Edge and to address all the vulnerabilities fixed in APSB16-32. For more detail on what is contained in the Adobe Flash Player bulletin, please refer to the bulletin posted on Adobe's website.
Bulletins Rated Important The following bulletins are rated important: MS16-121, MS16-123, MS16-124, MS16-125
MS16-121 addresses CVE-2016-7193, an arbitrary code execution vulnerability in all supported versions of Microsoft Office. CVE-2016-7193 manifests as a memory corruption flaw due to the way Office parses and handles Rich Text Format (RTF) files. Exploitation of this vulnerability requires that a user open a specifically crafted file that is designed to exploit this flaw.
MS16-123 addresses five local privilege escalation vulnerabilities that were identified in Windows Kernel-Mode Drivers. All five vulnerabilities are exploitable via an authenticated user executing a specifically crafted binary that exploits one of these flaws and elevates the user's privilege level to that of an administrator. Four of the vulnerabilities (CVE-2016-3266, CVE-2016-3376, CVE-2016-7185, CVE-2016-7211) manifest in the kernel itself while the fifth one (CVE-216-3341) manifests in the Windows Transaction Manager.
MS16-124 addresses four local privilege escalation vulnerabilities in the Windows Kernel. All four vulnerabilities (CVE-2016-0070, CVE-2016-0073, CVE-2016-0075, CVE-2016-0079) manifest as a result of the Windows Kernel API incorrectly permitting users to retrieve sensitive Registry information that could be used to then elevate a user's privileges to that of an administrator. Exploitation of these vulnerabilities could be achieved if a specifically crafted executable is launched on the target machine.
MS16-125 addresses CVE-2016-7188, a privilege escalation vulnerability in the Windows Diagnostics Hub. CVE-2016-7188 manifests as a result of the Windows Diagnostics Hubs Standard Collector Service failing to correctly sanitize user input, resulting in the unsafe loading of a library. Exploitation of this vulnerability requires that an authenticated user launch a specifically crafted executable that exploits this vulnerability.
Bulletins Rated Moderate MS16-126 is the sole security bulletin with a moderate severity rating this month and addresses CVE-2016-3298, an information disclosure vulnerability in the Microsoft Internet Messaging API. CVE-2016-3298 manifests as a flaw in how objects in memory are handled and if exploited, could allow an adversary to test if files exist on disk. Exploitation is achievable if a user navigates to a malicious website that exploits this vulnerability.
Coverage In response to the release of these bulletins, Talos is releasing the following rules to address these vulnerabilities. Please note that additional rules may be released at a future date and current rules are subject to change pending additional vulnerability information. For the most current rule information, please refer to your FireSIGHT Management Center or Snort.org.
Snort Rules
- Microsoft Bulletins: 40364-40381, 40383-40405, 40408-40412, 40418-40428
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/ms-tuesday-63063210e63ef5e7e1ec3151/