Patch Tuesday July 2012
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2012-1889 | Memory Corruption RCE in Microsoft XML Core Services Microsoft XML Core Services (MSXML) contains a memory corruption flaw (CWE-119) that can allow remote code execution when the component processes attacker-crafted content, such as a malicious web page or XML document loaded through Internet Explorer. Successful exploitation lets an attacker run arbitrary code in the security context of the logged-on user, gaining the ability to install programs, and view, change, or delete data; an admin-context victim would yield full system compromise. Any Windows system shipping the affected MSXML components is affected, which at the time of disclosure meant essentially the entire Windows installed base. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-06-08, EPSS assigns it an 83.6% probability of exploitation in the next 30 days (top percentile), and related reporting ties it to observed in-the-wild and APT activity, though public ransomware association is listed as unknown. No public proof-of-concept is cataloged, but the KEV and EPSS signals indicate active, ongoing exploitation risk. Do: Apply the vendor updates for XML Core Services released in the July 2012 Patch Tuesday on all Windows systems, prioritizing internet-facing and legacy endpoints, per the CISA KEV required action. Because exploitation is triggered via crafted web/XML content, restrict or upgrade legacy Internet Explorer usage and block untrusted web content on affected hosts. Hunt for exploitation indicators given the 2022-06-08 KEV listing and high EPSS score, and verify MSXML-related patches are present in your patch inventory. | — | 84% | KEV |
| mass≈hundreds of millions of Windows endpoints (MSXML ships as a core Windows component) |
Full article455 words · extracted from securelist.com · click to collapse
This month’s patch Tuesday brings a set of three “critical” bulletins focused on Windows/web browser component vulnerabilities and six other bulletins rated “important”. In other words, two of the critical components are considered “Windows” components, but most likely would be attacked through the web browser. Also, the top priority bulletin patches the CVE-2012-1889 vulnerability being exploited not only by attackers targeting high value targets, but common-off-the-shelf/commodity exploit packs.
Kaspersky products detect malicious web pages exploiting CVE-2012-1889 with “HEUR:Exploit.Script.Generic”. Addition of a working exploit targeting MSXML Core Services 3.0 within IE6 and IE7 XPSP3 to the Metasploit Framework on June 12th helped make this one more mainstream. While it may seem that targeting XP would limit its reach, it’s important to note that various market share surveys and reports show that Windows XP continues to take major OS market share. Interestingly, the MS12-043 Bulletin addressing this vulnerability patches MSXML Core Services 3, 4, and 6, leaving out version 5. Versions 3 and 6 ship with Windows itself. Accordingly, msxml3.dll and msxml6.dll reside in c:windowssystem32 across all supported versions of Windows, while the other versions are installed by Microsoft Office and other software.
Also patching the potential for web client-side drive-by’s, MS12-045 addresses an MDAC vulnerability, reminiscent of MS06-014, one of the longest lasting, reliable, most heavily targeted client-side vulnerabilities in Microsoft technology. It was taken advantage of for years by the Russian Business Network, purchasers of MPack, and later others, distributing Torpig and Rustock, while the nascent exploit kit market was solidifying back in 2006. It continues to be included in some of the live exploit pack control panels that we see. We’ll see how this new MDAC issue compares.
The third of the bulletins fighting “critical” rated web client side vulnerabilities fixes a couple of newer vulnerability types being targeted (“Cached Object Remote Code Execution Vulnerability – CVE-2012-1522”, “Attribute Remove Remote Code Execution Vulnerability – CVE-2012-1524”) introduced by Internet Explorer version 9 itself. Versions 6, 7 and 8 do not maintain the vulnerable code.
With that, we leave you to your regularly scheduled patching.
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/patch-tuesday-july-2012-focus-on-the-browser/33419/