June 2019 Patch Tuesday: A little something for everybody
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-1053 +1 in the same advisory: …0941 | An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the vulnerability could elevate privileges by escaping a sandbox. To exploit this vulnerability, an attacker would require unprivileged execution on the victim system. The security update addresses the vulnerability by correctly validating folder shortcuts. NVD description · AI analysis pending | 6.3 group max | 1% |
| — | ||
| CVE-2019-1069 | Local Privilege Escalation in Microsoft Windows Task Scheduler CVE-2019-1069 is a local elevation-of-privilege flaw in the Microsoft Windows Task Scheduler Service, which fails to correctly validate certain file operations (improper link/path resolution, CWE-59) that the service performs on behalf of running tasks. An attacker who has already gained unprivileged code execution on a target machine can trigger the vulnerable file operation so it is carried out by the Task Scheduler service with its elevated rights. Successful exploitation yields elevated privileges on the victim system, with CVSS impact rated High for confidentiality, integrity and availability, effectively giving the attacker full control of the local host. Affected products are Windows 10 versions 1507 through 1903 and Windows Server 1803, 1903, 2016 and 2019 — i.e., the Task Scheduler component in all of these builds. The flaw is exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-15 with known ransomware use, a public proof-of-concept has existed since June 2019, and EPSS estimates a ~6.1% probability of exploitation within 30 days (93rd percentile). Do: Apply Microsoft's security updates for CVE-2019-1069 (released in the June 2019 Patch Tuesday cumulative updates) or later cumulative updates on Windows 10 1507–1903 and Windows Server 1803/1903/2016/2019, per CISA's required action. Verify installed OS builds against the affected list and prioritize shared/multi-user hosts (RDS/VDI, jump servers, workstations of users who run untrusted software), since ransomware operators chain this local privilege escalation after initial access. Where patching is delayed, restrict unprivileged code execution and monitor for suspicious scheduled-task and file-operation activity by the Task Scheduler service. | 7.8 | 6% | KEV ransomware PoC |
| masshundreds of millions of Windows 10/Windows Server installations (every unpatched Windows 10 1507–1903 or Server 1803/1903/2016/2019 machine carries the… | |
| CVE-2019-7845 | Adobe Flash Player versions 32.0.0.192 and earlier, 32.0.0.192 and earlier, and 32.0.0.192 and earlier have an use after free vulnerability. Adobe Flash Player versions 32.0.0.192 and earlier, 32.0.0.192 and earlier, and 32.0.0.192 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution. NVD description · AI analysis pending | 8.8 | 6% |
| — |
Full article365 words · extracted from helpnetsecurity.com · click to collapse
For June 2019 Patch Tuesday, Microsoft has fixed a whooping 88 CVE-numbered vulnerabilities, Adobe has plugged many critical security holes in ColdFusion and Flash Player, and Intel has released security updates and mitigations for multiple products.

Adobe’s fixes
The Flash Player updates plug one but critical code execution flaw (CVE-2019-7845).
Users of the ColdFusion web application development platform are getting patches for three critical code execution bugs and should consult the offered tech notes to apply specific security configuration settings.
Finally, users of Adobe Campaign Classic on Windows and Linux are also urged to upgrade.
Microsoft’s fixes
Microsoft has addressed 88 vulnerabilities. None are currently being exploited in the wild.
Qualys Senior Director of Product Management Jimmy Graham advises administrators to prioritize scripting engine and browser patches for workstation-type systems and urges for a quick implementation of the Hyper-V patches, which fix three remote code execution flaws.
Dustin Childs, Director of Communications for Trend Micro’s Zero Day Initiative, singled out three flaws for quick patching:
- CVE-2019-1069 – an elevation of privilege flaw in Task Scheduler that has been publicly disclosed in May.
- CVE-2019-0941 – a DoS flaw affecting Microsoft IIS Server
- CVE-2019-1053 – a vulnerability in Windows Shell that could allows for a sandbox escape and which has also been previously publicly known.
Other vulnerabilities of note include:
- Two bugs in NTLM, Microsoft’s proprietary authentication protocol, which affect all Windows versions
- Four local privilege escalation zero-day vulnerabilities disclosed by SandboxEscaper in May 2019
Finally, Microsoft also:
- Delivered the Adobe Flash Player June update
- Blocked the pairing of certain BLE security keys (Google Titan and Feitian’s keys) on Windows due to a faulty implementation of the BLE pairing protocol
- Delivered an update for Microsoft Exchange Server that provides enhanced security as a defense in depth measure (no further details have been provided)
- Fixes for four DoS and code execution flaws affecting the Microsoft HoloLens device – users need to implement the firmware update.
Intel’s fixes
Intel has released fixes, advisories and mitigation advice for a number of its products, including SGX for Linux, Intel Accelerated Storage Manager, and NUS, its line of mini PCs.
CISA has direct links to each of the advisories.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2019/06/12/june-2019-patch-tuesday/