Microsoft Releases Patches for 60 Flaws—Two Under Active Attack
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-8273 | A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Server Remot A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Server Remote Code Execution Vulnerability." This affects Microsoft SQL Server. NVD description · AI analysis pending | 9.8 | 29% |
| — | ||
| CVE-2018-8302 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchang A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. NVD description · AI analysis pending | 9.8 | 26% |
| — | ||
| CVE-2018-8344 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote C A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. NVD description · AI analysis pending | 8.8 group max | 22% |
| — | ||
| CVE-2018-8373 | Memory Corruption RCE in Microsoft Internet Explorer Scripting Engine CVE-2018-8373 is an out-of-bounds write (CWE-787) in the Microsoft scripting engine's handling of objects in memory, which can corrupt memory and enable remote code execution in Internet Explorer 9, 10, and 11. It is triggered when a user is lured to an attacker-crafted web page or script in IE, with no privileges required but user interaction and relatively high attack complexity per the CVSS vector (AV:N/AC:H/UI:R). A successful attacker gains arbitrary code execution in the context of the current user, compromising that workstation's data and credentials. Any Windows system whose users browse with Internet Explorer 9, 10, or 11 was affected, and Microsoft fixed the flaw in its August 2018 Patch Tuesday release. The flaw was exploited as a zero-day in the wild at the time of patching — press coverage describes an in-the-wild VBScript zero-day blocked by endpoint protection — and it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25; EPSS places the 30-day exploitation probability at 61.9% (99th percentile). Do: Apply Microsoft's August 2018 security updates for Internet Explorer on all supported Windows versions — the required action listed in the CISA KEV — and verify patch deployment via WSUS/SCCM/Intune across end-user workstations and RDS/browsing hosts. As interim mitigation, consider Microsoft's documented workaround of disabling VBScript execution in IE via feature-control keys and steer users away from IE for web browsing. Finally, migrate any remaining IE9/10/11 usage to Microsoft Edge (using IE mode for legacy sites), since IE11 is retired and this flaw is confirmed exploited in the wild. | 7.5 | 62% | KEV |
| masshundreds of millions of Windows devices (IE9–11 shipped with Windows; IE11 present by default on Windows 7/8.1/10) | |
| CVE-2018-8397 | A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka "GDI+ Remote Code Ex A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka "GDI+ Remote Code Execution Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. NVD description · AI analysis pending | 8.8 | 68% |
| — | ||
| CVE-2018-8414 | File Path Validation RCE in Microsoft Windows Shell (Windows 10 and Server 1703–1803) Microsoft's Windows Shell improperly validates file paths in certain Windows 10 and Windows Server releases, a remote code execution flaw rooted in improper input validation (CWE-20). The flaw is triggered when the shell processes a specially crafted file path, typically requiring the victim to interact with a malicious file, as reflected in the CVSS user-interaction (UI:R) requirement. Successful exploitation lets an attacker execute arbitrary code in the context of the current user, with high impact on confidentiality, integrity, and availability. Affected products are Windows 10 versions 1703, 1709, and 1803 and Windows Server (Semi-Annual Channel) versions 1709 and 1803. The bug was patched in Microsoft's August 2018 Patch Tuesday after being reported as one of two zero-days actively exploited in attacks in the wild, was later added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25, and EPSS currently estimates a 74% probability of exploitation within 30 days. Do: Apply Microsoft's August 2018 security updates or later cumulative updates for Windows 10 1703/1709/1803 and Windows Server 1709/1803, consistent with Microsoft guidance and CISA's KEV required action; because these builds are now legacy, upgrading to a currently supported Windows release is the durable fix. Until patched, treat untrusted files and shortcuts with caution since exploitation requires user interaction. Inventory endpoints for the affected builds to confirm they are fully remediated. | 8.8 | 74% | KEV |
| mass≈ hundreds of millions of Windows 10 devices at the time of disclosure (builds 1703–1803 were then-current Windows 10 releases); today only residual legacy,… |
Full article890 words · extracted from thehackernews.com · click to collapse
The Hacker NewsAug 14, 2018
Get your update caps on.
Just a few minutes ago Microsoft released its latest monthly Patch Tuesday update for August 2018, patching a total of 60 vulnerabilities, of which 19 are rated as critical.
The updates patch flaws in Microsoft Windows, Edge Browser, Internet Explorer, Office, ChakraCore, .NET Framework, Exchange Server, Microsoft SQL Server and Visual Studio.
Two of these vulnerabilities patched by the tech giant is listed as publicly known and being exploited in the wild at the time of release.
According to the advisory released by Microsoft, all 19 critical-rated vulnerabilities lead to remote code execution (RCE), some of which could eventually allow attackers to take control of the affected system if exploited successfully.
Besides this, Microsoft has also addressed 39 important flaws, one moderate and one low in severity.
Here below we have listed brief details of a few critical and publically exploited important vulnerabilities:
Internet Explorer Memory Corruption Vulnerability (CVE-2018-8373)
The first vulnerability under active attack is a critical remote code execution vulnerability that was revealed by Trend Micro last month and affected all supported versions of Windows.
Internet Explorer 9, 10 and 11 are vulnerable to a memory corruption issue that could allow remote attackers to take control of the vulnerable systems just by convincing users to view a specially crafted website through Internet Explorer.
"An attacker could also embed an ActiveX control marked ‘safe for initialization’ in an application or Microsoft Office document that hosts the IE rendering engine," Microsoft says in its advisory.
Windows Shell Remote Code Execution Vulnerability (CVE-2018-8414)
The second publicly known and actively exploited flaw resides in the Windows Shell, which originates due to improper validation of file paths.
The arbitrary code can be executed on the targeted system by convincing victims into opening a specially crafted file received via an email or a web page.
Microsoft SQL Server RCE (CVE-2018-8273)
Microsoft SQL Server 2016 and 2017 are vulnerable to a buffer overflow vulnerability that could be exploited remotely by an attacker to execute arbitrary code in the context of the SQL Server Database Engine service account.
Successful exploitation of the vulnerability requires a remote attacker to submit a specially crafted query to an affected SQL server.
Windows PDF Remote Code Execution Vulnerability (CVE-2018-8350)
Windows 10 systems with Microsoft Edge set as the default browser can be compromised merely by convincing users to view a website.
Due to improper handling of the objects in the memory, Windows 10's PDF library could be exploited by a remote attacker to execute arbitrary code on the targeted system.
"The attacker could also take advantage of compromised websites or websites that accept or host user-provided content or advertisements, by adding specially crafted PDF content to such sites," Microsoft says in its advisory.
"Only Windows 10 systems with Microsoft Edge set as the default browser can be compromised simply by viewing a website."
Microsoft Exchange Memory Corruption Vulnerability (CVE-2018-8302)
This vulnerability resides in the way this software handles objects in memory, allowing a remote attacker to run arbitrary code in the context of the System user just by sending a specially crafted email to the vulnerable Exchange server.
The flaw affects Microsoft Exchange Server 2010, 2013 and 2016.
Microsoft Graphics Remote Code Execution Vulnerability (CVE-2018-8344)
Microsoft revealed that Windows font library improperly handles specially crafted embedded fonts, which could allow attackers to take control of the affected system by serving maliciously embedded fonts via a specially crafted website and document file.
This vulnerability affects Windows 10, 8.1, and 7, and Windows Server 2016 and 2012.
LNK Remote Code Execution Vulnerability (CVE-2018-8345)
This vulnerability exists in .LNK shortcut file format used by Microsoft Windows 10, 8.1, 7 and Windows Server editions.
An attacker can use malicious .LNK file and an associated malicious binary to execute arbitrary code on the targeted system. Successful exploitation of this vulnerability could allow attackers to gain the same user rights on the target Windows system as the local user.
According to the Microsoft advisory, users accounts configured with fewer user rights on the system are less impacted by this vulnerability than users who operate with administrative user rights.
GDI+ Remote Code Execution Vulnerability (CVE-2018-8397)
This RCE flaw resides in the way Windows Graphics Device Interface (GDI) handles objects in the memory, allowing an attacker to take control of the affected system if exploited successfully.
"An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights," Microsoft says in its advisory explaining the flaw.
"Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights."
The vulnerability affects Windows 7 and Windows Server 2008.
Besides this, Microsoft has also pushed security updates to patch vulnerabilities in Adobe products, details of which you can get through a separate article posted today.
Users are strongly advised to apply security patches as soon as possible to keep hackers and cybercriminals away from taking control of their computers.
For installing security updates, directly head on to Settings → Update & security → Windows Update → Check for updates, or you can install the updates manually.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2018/08/microsoft-patch-updates.html