Patch Tuesday, September 2019 Edition
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-1215 +1 in the same advisory: …1214 | Local Privilege Escalation in Microsoft Windows Winsock Driver (ws2ifsl.sys) CVE-2019-1215 is an elevation-of-privilege vulnerability in ws2ifsl.sys, an auxiliary Winsock driver shipped with Windows, caused by improper handling of objects in memory (CWE-269). A local attacker with limited privileges can trigger the flaw via crafted requests to the driver, without user interaction, to execute code in kernel context. Successful exploitation grants elevated (SYSTEM-level) privileges, turning a low-privileged foothold into full control of the host and making the bug a useful link in ransomware attack chains. Affected systems include Windows 7, Windows 8.1, Windows RT 8.1, Windows 10 versions 1507 through 1903, and Windows Server versions 1803 and 1903. Microsoft patched the flaw in its October 2019 security updates; CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 with ransomware use known, and EPSS currently assigns a 19.3% probability of exploitation within 30 days (97th percentile). Do: Apply the Microsoft security update issued October 8, 2019 across all affected Windows 7, 8.1, RT 8.1, Windows 10 (1507-1903), and Server 1803/1903 systems, prioritizing hosts where ransomware operators could chain this local privilege escalation. Systems no longer receiving updates (Windows 7 without Extended Security Updates, Windows 10 versions past end of service) should be upgraded to a supported release. Organizations subject to CISA's KEV binding requirements must patch per the vendor instructions within the required deadline, and defenders should hunt legacy endpoints for prior exploitation given the known ransomware linkage. | 7.8 | 19% | KEV ransomware |
| masslikely hundreds of millions of devices at disclosure (the affected Windows 7/8.1 and Windows 10 1507-1903 releases dominated the global Windows PC installed… |
Full article688 words · extracted from krebsonsecurity.com · click to collapse
Microsoft today issued security updates to plug some 80 security holes in various flavors of its Windows operating systems and related software. The software giant assigned a “critical” rating to almost a quarter of those vulnerabilities, meaning they could be used by malware or miscreants to hijack vulnerable systems with little or no interaction on the part of the user.
Two of the bugs quashed in this month’s patch batch (CVE-2019-1214 and CVE-2019-1215) involve vulnerabilities in all supported versions of Windows that have already been exploited in the wild. Both are known as “privilege escalation” flaws in that they allow an attacker to assume the all-powerful administrator status on a targeted system. Exploits for these types of weaknesses are often deployed along with other attacks that don’t require administrative rights.
September also marks the fourth time this year Microsoft has fixed critical bugs in its Remote Desktop Protocol (RDP) feature, with four critical flaws being patched in the service. According to security vendor Qualys, these Remote Desktop flaws were discovered in a code review by Microsoft, and in order to exploit them an attacker would have to trick a user into connecting to a malicious or hacked RDP server.
Microsoft also fixed another critical vulnerability in the way Windows handles link files ending in “.lnk” that could be used to launch malware on a vulnerable system if a user were to open a removable drive or access a shared folder with a booby-trapped .lnk file on it.
Shortcut files — or those ending in the “.lnk” extension — are Windows files that link easy-to-recognize icons to specific executable programs, and are typically placed on the user’s Desktop or Start Menu. It’s perhaps worth noting that poisoned .lnk files were one of the four known exploits bundled with Stuxnet, a multi-million dollar cyber weapon that American and Israeli intelligence services used to derail Iran’s nuclear enrichment plans roughly a decade ago.
In last month’s Microsoft patch dispatch, I ruefully lamented the utter hose job inflicted on my Windows 10 system by the July round of security updates from Redmond. Many readers responded by saying one or another updates released by Microsoft in August similarly caused reboot loops or issues with Windows repeatedly crashing.
As there do not appear to be any patch-now-or-be-compromised-tomorrow flaws in the September patch rollup, it’s probably safe to say most Windows end-users would benefit from waiting a few days to apply these fixes.
Very often fixes released on Patch Tuesday have glitches that cause problems for an indeterminate number of Windows systems. When this happens, Microsoft then patches their patches to minimize the same problems for users who haven’t yet applied the updates, but it sometimes takes a few days for Redmond to iron out the kinks.
The trouble is, Windows 10 by default will install patches and reboot your computer whenever it likes. Here’s a tutorial on how to undo that. For all other Windows OS users, if you’d rather be alerted to new updates when they’re available so you can choose when to install them, there’s a setting for that in Windows Update.
Most importantly, please have some kind of system for backing up your files before applying any updates. You can use third-party software to do this, or just rely on the options built into Windows 10. At some level, it doesn’t matter. Just make sure you’re backing up your files, preferably following the 3-2-1 backup rule.
Finally, Adobe fixed two critical bugs in its Flash Player browser plugin, which is bundled in Microsoft’s IE/Edge and Chrome (although now hobbled by default in Chrome). Firefox forces users with the Flash add-on installed to click in order to play Flash content; instructions for disabling or removing Flash from Firefox are here. Adobe will stop supporting Flash at the end of 2020.
As always, if you experience any problems installing any of these patches this month, please feel free to leave a comment about it below; there’s a good chance other readers have experienced the same and may even chime in here with some helpful tips.
Text extracted automatically; images, tables and formatting may be missing. Original: https://krebsonsecurity.com/2019/09/patch-tuesday-september-2019-edition/