October 2018 Patch Tuesday: Microsoft fixes 49 flaws, one APT-wielded zero-day
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-8423 +1 in the same advisory: …8497 | A remote code execution vulnerability exists in the Microsoft JET Database Engine, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability." This A remote code execution vulnerability exists in the Microsoft JET Database Engine, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. NVD description · AI analysis pending | 7.8 | 32% | PoC ×2 |
| — | |
| CVE-2018-8453 | Win32k Elevation of Privilege Flaw in Windows 7-10 and Windows Server (CVE-2018-8453) CVE-2018-8453 is an elevation of privilege vulnerability in the Windows Win32k kernel component, which fails to properly handle objects in memory, including the Win32k user-callback path reachable via NtUserSetWindowFNID. An attacker who can already execute code on an affected machine can trigger the flaw to escalate privileges, gaining the equivalent of SYSTEM-level rights with high impact on confidentiality, integrity, and availability. All broadly deployed Windows releases of the era are affected, spanning Windows 7, 8.1, RT 8.1, Windows 10 (1507 through 1809), and Windows Server 2008 through 2019, so any unpatched Windows desktop or server is in scope. The flaw was exploited as a zero-day by the FruityArmor APT in targeted attacks in the Middle East, disclosed and patched in Microsoft's October 2018 Patch Tuesday, and has public proof-of-concept code. It is confirmed exploited in the wild: it sits in CISA's Known Exploited Vulnerabilities catalog (added 2022-01-21) with known ransomware use, and EPSS assigns a 70% probability of exploitation within 30 days. Do: Apply Microsoft's October 2018 (or later) cumulative security updates to all affected Windows 7/8.1/RT 8.1/Windows 10 clients and Windows Server 2008-2019 systems, per the vendor instructions required by CISA's KEV catalog. Prioritize multi-user hosts such as terminal/RDS servers and workstations where users can run untrusted code, since the attack requires local code execution with user interaction. Systems still on Windows 7/8.1 or Server 2008/2008 R2/2012 should be moved to Extended Security Updates or upgraded, and defenders should hunt for signs of FruityArmor-style activity on long-lived unpatched hosts. | 7.8 | 70% | KEV ransomware PoC ×2 |
| masshundreds of millions to ~1 billion+ Windows installations (Windows 10 alone ran on roughly 700 million active devices in 2018) | |
| CVE-2018-8531 | A remote code execution vulnerability exists in the way that Azure IoT Hub Device Client SDK using MQTT protocol accesses objects in memory, aka "Azure IoT Devi A remote code execution vulnerability exists in the way that Azure IoT Hub Device Client SDK using MQTT protocol accesses objects in memory, aka "Azure IoT Device Client SDK Memory Corruption Vulnerability." This affects Hub Device Client SDK, Azure IoT Edge. NVD description · AI analysis pending | 8.8 | 15% |
| — |
Full article548 words · extracted from helpnetsecurity.com · click to collapse
With the October 2018 Patch Tuesday release Microsoft has fixed 49 vulnerabilities, 12 of which are rated “critical.”

Previously known flaws and an actively exploited zero-day
The only zero-day in this batch is CVE-2018-8453, an elevation of privilege vulnerability affecting Windows.
Attackers must first gain access to the system, but then this vulnerability allows them to run arbitrary code in kernel mode and, ultimately, to install programs; view, change, or delete data; or create new accounts with full user rights.
The vulnerability was reported by Kaspersky Lab in August. They say that they detected a very limited number of attacks using this vulnerability against victims in the Middle East.
“During our investigation, we discovered the attackers were using a PowerShell backdoor that has previously been seen exclusively used by the FruityArmor APT. There is also an overlap in the domains used for C2 between this new set of activity and previous FruityArmor campaigns. That makes us assess with medium confidence that FruityArmor is responsible for the attacks leveraging CVE-2018-8453,” the company noted.
The three previously disclosed flaws are as follows:
- CVE-2018-8423 is a remote code execution vulnerability in the Microsoft JET database engine and can be triggered when a victim is tricked into opening a malicious JET Database Engine file.
- CVE-2018-8531 is a memory corruption vulnerability in the Azure IoT Hub Device Client SDK that can allow an attacker to execute arbitrary code in the context of the current user.
- CVE-2018-8497 is an elevation of privilege vulnerability that exists in the way that the Windows Kernel handles objects in memory.
None of these are being currently exploited in the wild.
Prioritizing patches
Animesh Jain, Product Manager, VM Signatures at Qualys, advises administrators to prioritize Browser and Scripting Engine patches for workstations (i.e., any system that is used for email or to access the internet via a browser), as most of the critical vulnerabilities this month are in the Chakra Scripting Engine, Internet Explorer, and Edge.
The Hyper-V patches should also be implemented as soon as possible, as they plug two remote code execution holes that would allow an authenticated user on a guest system to run arbitrary code on the host system.
Trend Micro Zero Day Initiatives’ Dustin Childs pointed out the patch for a vulnerability in Exchange Server that has first been discovered eight years ago. CVE-2010-3190 is a RCE bug that exists in the way that certain applications built using Microsoft Foundation Classes (MFC) handle the loading of DLL files.
“Often referred to as ‘binary planting’ or ‘DLL preloading attacks,’ this class of bugs has [previously] received close to 30 bulletins in total to fix various components. This month, Microsoft identified Exchange Server as another component that requires similar DLL preloading protections,” Childs noted.
“If you have a version of Exchange prior to Exchange Server 2016 Cumulative Update 11, you’ll also need the Visual Studio 2010 patch from MS11-025. This patch accompanies two command injection fixes impacting Exchange this month, which means another rough month of testing and patching for Exchange admins.”
As usual, Adobe followed Microsoft by releasing security updates for several of its products (Flash, Framemaker, Adobe Digital Editions, and the Adobe Technical Communications Suite) but as the Flash update doesn’t contain any security fixes, Microsoft didn’t have to incorporate any.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2018/10/10/october-2018-patch-tuesday/