November 2019 Patch Tuesday: Actively exploited IE zero-day fixed
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-1373 | A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code E A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'. NVD description · AI analysis pending | 9.8 | 21% |
| — | ||
| CVE-2019-1429 | Memory corruption RCE in Microsoft Internet Explorer scripting engine CVE-2019-1429 is a memory corruption flaw (use-after-free/out-of-bounds write, CWE-416/CWE-787) in the way the Internet Explorer scripting engine handles objects in memory, allowing remote code execution. It is triggered remotely by convincing a user to view attacker-controlled web content — for example, a malicious website opened in Internet Explorer or an application embedding the IE engine — requiring no privileges but user interaction (CVSS 3.1 AV:N/AC:H/PR:N/UI:R). A successful exploit runs attacker code with the privileges of the logged-in user, enabling malware installation, data theft, and account compromise. Users of Internet Explorer on Windows are affected, since IE is present by default across Windows installations. The flaw was actively exploited as a zero-day at its November 2019 disclosure (associated with the Magnitude exploit kit per related coverage), carries a public proof-of-concept, and is listed in CISA's Known Exploited Vulnerabilities catalog. Do: Apply the November 2019 Microsoft security updates (Internet Explorer cumulative updates) per Microsoft's instructions, as required by the CISA KEV listing. Until patched, avoid browsing untrusted or attacker-influenced websites with Internet Explorer and consider directing users to Microsoft Edge instead of legacy IE. Given active in-the-wild use, prioritize this patch in your deployment schedule and verify IE cumulative updates are installed on all Windows endpoints. | 7.5 | 77% | KEV PoC |
| masshundreds of millions of Windows users (IE ships by default with Windows, and exploit kit delivery puts at least exposed users at broad scale) | |
| CVE-2019-1457 | A security feature bypass vulnerability exists in Microsoft Office software by not enforcing macro settings on an Excel document, aka 'Microsoft Office Excel Se A security feature bypass vulnerability exists in Microsoft Office software by not enforcing macro settings on an Excel document, aka 'Microsoft Office Excel Security Feature Bypass'. NVD description · AI analysis pending | 7.8 | 3% |
| — | ||
| CVE-2019-16863 | STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing attack because ECDSA s STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing attack because ECDSA scalar multiplication is mishandled, aka TPM-FAIL. NVD description · AI analysis pending | 5.9 | 3% |
| — |
Full article562 words · extracted from helpnetsecurity.com · click to collapse
November 2019 Patch Tuesday comes with patches for an IE zero-day exploited by attackers in the wild and four Hyper-V escapes.

Microsoft updates
Microsoft has delivered fixes for 74 vulnerabilities in various products, 13 of which are deemed to be critical. The most notable ones in this batch are:
- CVE-2019-1429, a scripting engine memory corruption vulnerability that, according to researchers of the Google Threat Analysis Group, is being exploited in attacks in the wild to achieve remote code execution
- CVE-2019-16863, a flaw effecting STMicroelectronics Trusted Platform Module (TPM) chipsets, which impacts key confidentiality in the Elliptic Curve Digital Signature Algorithm (ECDSA).
The former can be triggered in several ways.
“In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability through Internet Explorer and then convince a user to view the website. An attacker could also embed an ActiveX control marked ‘safe for initialization’ in an application or Microsoft Office document that hosts the IE rendering engine,” Microsoft explained.
“The attacker could also take advantage of compromised websites and websites that accept or host user-provided content or advertisements. These websites could contain specially crafted content that could exploit the vulnerability.”
Updating Internet Explorer should therefore be a priority, especially on workstations, as all current IE versions are affected.
CVE-2019-16863 does not affect any of Windows or a specific Microsoft application. The hole can be plugged through a TPM firmware update (more info here).
“If your system is affected and requires the installation of TPM firmware updates, you might need to re-enroll in security services you are running to remediate those affected services,” Microsoft pointed out.
Other security updates that should be prioritized are those for Hyper-V systems, as they fix four vulnerabilities that would allow a remote, authenticated user on a guest system to run arbitrary code on the host system, and those for Microsoft Exchange.
“Bugs in Exchange Server are always interesting on some level, and [CVE-2019-1373] certainly doesn’t disappoint. The patch corrects a vulnerability in the deserialization of metadata via PowerShell. To exploit this, an attacker would need to convince a user to run cmdlets via PowerShell. While this may be an unlikely scenario, it only takes one user to compromise the server. If that user has administrative privileges, they could hand over complete control to the attacker,” noted Trend Micro ZDI’s Dustin Childs.
Finally, Microsoft has also finally provided a fix for CVE-2019-1457, a vulnerability that could allow attackers to leverage XLM macros to execute arbitrary code on a vulnerable system (more info here).
As usual, SANS ISC has a helpful “at a glance” overview about all the issues fixed.
Adobe updates
Adobe has plugged critical and important security holes in Illustrator CC (vector graphics editor), Media Encoder, Animate CC (animation software) and Bridge CC (asset manager).
The Illustrator update fixes three flaws, two of which are memory corruption issues that could allow code execution. The Media Encoder update nixes 5 vulnerabilities, one of which is critical (could lead to code execution).
The Bridge and Animate updates are less critical, but users are advised to implement them as soon as they can.
The good news is that none of the vulnerabilities fixed in this latest batch of Adobe updates are under active exploitation so, for the moment, Microsoft’s updates should definitely take precedence.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2019/11/13/november-2019-patch-tuesday/