Microsoft Patch Tuesday
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-0765 | A denial of service vulnerability exists when .NET and .NET Core improperly process XML documents, aka ".NET and .NET Core Denial of Service Vulnerability." Thi A denial of service vulnerability exists when .NET and .NET Core improperly process XML documents, aka ".NET and .NET Core Denial of Service Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.7.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.7/4.7.1, Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, Microsoft .NET Framework 4.6.2/4.7/4.7.1, .NET Core 2.0, Microsoft .NET Framework 4.7.2. NVD description · AI analysis pending | 7.5 | 8% |
| — | ||
| CVE-2018-0824 +1 in the same advisory: …8174 | Deserialization of Untrusted Data RCE in Microsoft COM for Windows CVE-2018-0824 is a deserialization of untrusted data flaw (CWE-502) in Microsoft COM for Windows: the COM subsystem fails to properly handle serialized objects, allowing a remote attacker to achieve remote code execution (CVSS 3.1: 8.8, network vector). It is triggered when the affected Windows system deserializes attacker-controlled serialized data; the CVSS vector indicates user interaction is required in typical attack scenarios. Successful exploitation yields code execution with the privileges of the user or service that handles the serialized object, compromising confidentiality, integrity, and availability on the host. The affected footprint is extremely broad, spanning Windows 7, 8.1 and RT 8.1, Windows 10 (versions 1507 through 1803), and Windows Server 2008 through 2016, including Server versions 1709 and 1803. The flaw is confirmed exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-05 — and a public PoC exists (Exploit-DB 44906), with EPSS estimating a ~73.2% probability of exploitation within 30 days. Do: Apply Microsoft's COM security updates to every in-scope Windows build, prioritizing internet-facing hosts and legacy systems (Windows 7, Windows Server 2008/2008 R2, Windows Server 2012) that commonly remain unpatched; because the flaw is on CISA's KEV list, patching is required for federal agencies under BOD 22-01. Verify patch installation via inventory rather than OS build alone, and where patching is impossible (end-of-support systems), isolate or restrict those hosts' network exposure. Ransomware use is not yet confirmed by CISA, but the high EPSS score and KEV listing warrant urgent remediation. | 8.8 group max | 73% | KEV PoC |
| masshundreds of millions of Windows devices run the affected versions (Windows 7–10 and Server 2008–2016); residual unpatched exposure plausibly in the millions | |
| CVE-2018-8164 | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privile An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8120, CVE-2018-8124, CVE-2018-8166. NVD description · AI analysis pending | 7.8 group max | 2% |
| — | ||
| CVE-2018-0953 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corr A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-0945, CVE-2018-0946, CVE-2018-0951, CVE-2018-0954, CVE-2018-0955, CVE-2018-1022, CVE-2018-8114, CVE-2018-8122, CVE-2018-8128, CVE-2018-8137, CVE-2018-8139. NVD description · AI analysis pending | 7.5 group max | 67% | PoC |
| — | |
| CVE-2018-8126 | A security feature bypass vulnerability exists when Internet Explorer fails to validate User Mode Code Integrity (UMCI) policies, aka "Internet Explorer Securit A security feature bypass vulnerability exists when Internet Explorer fails to validate User Mode Code Integrity (UMCI) policies, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11. NVD description · AI analysis pending | 8.8 group max | 6% |
| — | ||
| CVE-2018-1039 | A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to bypass Device Guard, aka ".NET Framework Device Guard Security A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to bypass Device Guard, aka ".NET Framework Device Guard Security Feature Bypass Vulnerability." This affects Microsoft .NET Framework 4.7.1, Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6.2/4.7/4.7.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1, Microsoft .NET Framework 2.0, Microsoft .NET Framework 4.6/4.6.1/4.6.2. NVD description · AI analysis pending | 7.8 | 1% |
| — | ||
| CVE-2018-4944 | Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. NVD description · AI analysis pending | 9.8 | 9% |
| — | ||
| CVE-2018-8115 | A remote code execution vulnerability exists when the Windows Host Compute Service Shim (hcsshim) library fails to properly validate input while importing a con A remote code execution vulnerability exists when the Windows Host Compute Service Shim (hcsshim) library fails to properly validate input while importing a container image, aka "Windows Host Compute Service Shim Remote Code Execution Vulnerability." This affects Windows Host Compute. NVD description · AI analysis pending | 8.6 | 35% |
| — | ||
| CVE-2018-8119 | A spoofing vulnerability exists when the Azure IoT Device Provisioning AMQP Transport library improperly validates certificates over the AMQP protocol, aka "Azu A spoofing vulnerability exists when the Azure IoT Device Provisioning AMQP Transport library improperly validates certificates over the AMQP protocol, aka "Azure IoT SDK Spoofing Vulnerability." This affects C# SDK, C SDK, Java SDK. NVD description · AI analysis pending | 5.6 | 1% |
| — | ||
| CVE-2018-8120 | Local Privilege Escalation in Microsoft Win32k (Windows 7 / Server 2008) CVE-2018-8120 is an elevation of privilege flaw in the Microsoft Windows Win32k kernel component, which fails to properly handle objects in memory. A local attacker who already has the ability to run code with low privileges on the machine must execute a specially crafted application that triggers the faulty object handling, allowing code to run in kernel mode. Successful exploitation yields elevated (SYSTEM-level) privileges and full control of the host, and it is commonly chained with a remote code execution or browser exploit, or used by malware — including ransomware — to deepen a compromise. Only systems running Windows 7, Windows Server 2008, or Windows Server 2008 R2 with unpatched Win32k are affected. The bug was exploited as a zero-day (reportedly by the ScarCruft APT group) before being fixed in May 2018 Patch Tuesday, a public PoC is available, and it was added to CISA's Known Exploited Vulnerabilities catalog in March 2022 with known ransomware use. Do: Apply Microsoft's May 2018 security updates or later cumulative updates for Windows 7, Windows Server 2008, and Windows Server 2008 R2, prioritizing this KEV-listed flaw per the CISA required action. Systems beyond end of support that are not receiving Extended Security Updates should be migrated to a supported Windows version or isolated, since they remain permanently exposed to known APT and ransomware tooling. Review hosts for signs of local privilege escalation and ensure any RCE entry vector (browser, file format, or service exploit) is also patched, as this bug is typically used to escalate an initial foothold. | 7.0 | 73% | KEV ransomware PoC |
| mass≈ hundreds of millions of Windows 7 desktops plus widespread Windows Server 2008/2008 R2 deployments worldwide | |
| CVE-2018-8145 | An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge, Internet Explorer 10. This CVE ID is unique from CVE-2018-0943, CVE-2018-8130, CVE-2018-8133, CVE-2018-8177. NVD description · AI analysis pending | 7.5 | 67% | PoC |
| — | |
| CVE-2018-8147 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remo A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Excel. This CVE ID is unique from CVE-2018-8148, CVE-2018-8162. NVD description · AI analysis pending | 7.8 group max | 25% |
| — | ||
| CVE-2018-8149 | An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected ShareP An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8155, CVE-2018-8156, CVE-2018-8168. NVD description · AI analysis pending | 5.4 | 3% |
| — | ||
| CVE-2018-8157 | A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Re A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-2018-8158, CVE-2018-8161. NVD description · AI analysis pending | 7.8 group max | 25% |
| — | ||
| CVE-2018-8152 | An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange S An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server. NVD description · AI analysis pending | 5.4 group max | 4% |
| — | ||
| CVE-2018-8155 | An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected ShareP An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8149, CVE-2018-8156, CVE-2018-8168. NVD description · AI analysis pending | 5.4 | 3% |
| — | ||
| CVE-2018-8156 | An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected ShareP An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint, Microsoft Project Server. This CVE ID is unique from CVE-2018-8149, CVE-2018-8155, CVE-2018-8168. NVD description · AI analysis pending | 5.4 | 3% |
| — | ||
| CVE-2018-8173 | A remote code execution vulnerability exists in Microsoft InfoPath when the software fails to properly handle objects in memory, aka "Microsoft InfoPath Remote A remote code execution vulnerability exists in Microsoft InfoPath when the software fails to properly handle objects in memory, aka "Microsoft InfoPath Remote Code Execution Vulnerability." This affects Microsoft Infopath. NVD description · AI analysis pending | 7.8 | 20% |
| — | ||
| CVE-2018-8897 | A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are deferred by MOV SS or POP SS, as demonstrated by (for example) privilege escalation in Windows, macOS, some Xen configurations, or FreeBSD, or a Linux kernel crash. The MOV to SS and POP SS instructions inhibit interrupts (including NMIs), data breakpoints, and single step trap exceptions until the instruction boundary following the next instruction (SDM Vol. 3A; section 6.8.3). (The inhibited data breakpoints are those on memory accessed by the MOV to SS or POP to SS instruction itself.) Note that debug exceptions are not inhibited by the interrupt enable (EFLAGS.IF) system flag (SDM Vol. 3A; section 2.3). If the instruction following the MOV to SS or POP to SS instruction is an instruction like SYSCALL, SYSENTER, INT 3, etc. that transfers control to the operating system at CPL < 3, the debug exception is delivered after the transfer to CPL < 3 is complete. OS kernels may not expect this order of events and may therefore experience unexpected behavior when it occurs. NVD description · AI analysis pending | 7.8 | 19% | PoC |
| — |
Full article776 words · extracted from blog.talosintelligence.com · click to collapse
Tuesday, May 8, 2018 15:02
Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 67 new vulnerabilities, with 21 of them rated critical, 42 of them rated important, and four rated as low severity. These vulnerabilities impact Outlook, Office, Exchange, Edge, Internet Explorer and more.
In addition to the 67 vulnerabilities referenced above, Microsoft has also released a critical update advisory, ADV180008, which addresses the vulnerability CVE-2018-4944 described in the Adobe security bulletin APSB18-16.
Critical Vulnerabilities
This month, Microsoft is addressing 21 vulnerabilities that are rated as critical. Talos believes one of these is notable and requires prompt attention.
CVE-2018-8174 - Windows VBScript Engine Remote Code Execution Vulnerability.
A remote code execution vulnerability exists in the VBScript scripting engine (vbscript.dll) of Windows. This vulnerability allows an attacker to include malicious VBScript within a website or embedded within an Office file, which when executed allows an attacker to execute arbitrary code in the context of the current user. Threat actors are currently exploiting this vulnerability.
Other vulnerabilities rated as critical are listed below:
CVE-2018-0959 - Hyper-V Remote Code Execution Vulnerability
CVE-2018-0961 - Hyper-V vSMB Remote Code Execution Vulnerability
CVE-2018-8115 - Windows Host Compute Service Shim Remote Code Execution Vulnerability
CVE-2018-8178 - Microsoft Browser Memory Corruption Vulnerability
CVE-2018-0946 - Scripting Engine Memory Corruption Vulnerability
CVE-2018-0951 - Scripting Engine Memory Corruption Vulnerability
CVE-2018-0953 - Scripting Engine Memory Corruption Vulnerability
CVE-2018-0954 - Scripting Engine Memory Corruption Vulnerability
CVE-2018-0955 - Scripting Engine Memory Corruption Vulnerability
CVE-2018-8114 - Scripting Engine Memory Corruption Vulnerability
CVE-2018-8122 - Scripting Engine Memory Corruption Vulnerability
CVE-2018-8137 - Scripting Engine Memory Corruption Vulnerability
CVE-2018-0945 - Scripting Engine Memory Corruption Vulnerability
CVE-2018-1022 - Scripting Engine Memory Corruption Vulnerability
CVE-2018-8139 - Scripting Engine Memory Corruption Vulnerability
CVE-2018-8128 - Scripting Engine Memory Corruption Vulnerability
CVE-2018-8133 - Chakra Scripting Engine Memory Corruption Vulnerability
CVE-2018-0943 - Chakra Scripting Engine Memory Corruption Vulnerability
CVE-2018-8130 - Chakra Scripting Engine Memory Corruption Vulnerability
CVE-2018-8177 - Chakra Scripting Engine Memory Corruption Vulnerability
Important Vulnerabilities
This month, Microsoft is addressing 42 vulnerabilities that are rated important.
CVE-2018-8120 - Win32k Elevation of Privilege Vulnerability
CVE-2018-8123 - Microsoft Edge Memory Corruption Vulnerability
CVE-2018-8124 - Win32k Elevation of Privilege Vulnerability
CVE-2018-8147 - Microsoft Excel Remote Code Execution Vulnerability
CVE-2018-8148 - Microsoft Excel Remote Code Execution Vulnerability
CVE-2018-8157 - Microsoft Office Remote Code Execution Vulnerability
CVE-2018-8158 - Microsoft Office Remote Code Execution Vulnerability
CVE-2018-8161 - Microsoft Office Remote Code Execution Vulnerability
CVE-2018-8162 - Microsoft Excel Remote Code Execution Vulnerability
CVE-2018-8164 - Win32k Elevation of Privilege Vulnerability
CVE-2018-8165 - DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2018-8166 - Win32k Elevation of Privilege Vulnerability
CVE-2018-8167 - Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2018-8179 - Microsoft Edge Memory Corruption Vulnerability
CVE-2018-0765 - .NET and .NET Core Denial of Service Vulnerability
CVE-2018-0824 - Microsoft COM for Windows Remote Code Execution Vulnerability
CVE-2018-0854 - Windows Security Feature Bypass Vulnerability
CVE-2018-0958 - Windows Security Feature Bypass Vulnerability
CVE-2018-1021 - Microsoft Edge Information Disclosure Vulnerability
CVE-2018-1025 - Microsoft Browser Information Disclosure Vulnerability
CVE-2018-1039 - .NET Framework Device Guard Security Feature Bypass Vulnerability
CVE-2018-8112 - Microsoft Edge Security Feature Bypass Vulnerability
CVE-2018-8119 - Azure IoT SDK Spoofing Vulnerability
CVE-2018-8126 - Internet Explorer Security Feature Bypass Vulnerability
CVE-2018-8127 - Windows Kernel Information Disclosure Vulnerability
CVE-2018-8129 - Windows Security Feature Bypass Vulnerability
CVE-2018-8132 - Windows Security Feature Bypass Vulnerability
CVE-2018-8134 - Windows Elevation of Privilege Vulnerability
CVE-2018-8141 - Windows Kernel Information Disclosure Vulnerability
CVE-2018-8145 - Chakra Scripting Engine Memory Corruption Vulnerability
CVE-2018-8149 - Microsoft SharePoint Elevation of Privilege Vulnerability
CVE-2018-8150 - Microsoft Outlook Security Feature Bypass Vulnerability
CVE-2018-8151 - Microsoft Exchange Memory Corruption Vulnerability
CVE-2018-8152 - Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2018-8155- Microsoft SharePoint Elevation of Privilege Vulnerability
CVE-2018-8156 - Microsoft SharePoint Elevation of Privilege Vulnerability
CVE-2018-8159 - Microsoft Exchange Elevation of Privilege Vulnerability
CVE-2018-8160 - Microsoft Outlook Information Disclosure Vulnerability
CVE-2018-8163 - Microsoft Excel Information Disclosure Vulnerability
CVE-2018-8170 - Windows Image Elevation of Privilege Vulnerability
CVE-2018-8173 - Microsoft InfoPath Remote Code Execution Vulnerability
CVE-2018-8897 - Windows Kernel Elevation of Privilege Vulnerability
Coverage
In response to these vulnerability disclosures, Talos is releasing the following Snort rules that detect attempts to exploit them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Firepower customers should use the latest update to their ruleset by updating their SRU. Open Source Snort Subscriber Rule Set customers can stay up-to-date by downloading the latest rule pack available for purchase on Snort.org.
Snort Rules:
46538 - 46539,
46544 - 46549,
46552 - 46565,
46594 - 46597,
46601 - 46604
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-may-2018/