ZeroHour
Security Affairspublished ()ingested @securityaffairs

Microsoft Patch Tuesday security updates for June 2019 fix 88 flaws

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-0722
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operat

A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary code. An attacker who successfully exploited the vulnerability could execute arbitrary code on the host operating system. The security update addresses the vulnerability by correcting how Hyper-V validates guest operating system user input.

NVD description · AI analysis pending
8.8
group max
5%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2019-1064
Local Privilege Escalation in Microsoft Windows AppX Deployment Service

Microsoft Windows AppX Deployment Service (AppXSVC) improperly handles hard links, creating an elevation of privilege vulnerability tracked as CVE-2019-1064 (CWE-59, link following). The flaw is triggered when a local attacker who is already able to log on to an affected system runs a specially crafted application. Successful exploitation allows the attacker to run processes in an elevated context, then install programs and view, change, or delete data, effectively taking control of the affected system. Affected products span Windows 10 versions 1607, 1703, 1709, 1803, 1809, and 1903, plus Windows Server 1709, 1803, 1903, 2016, and 2019. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-15) with known ransomware use, so it is being actively exploited in the wild.

Do: Apply Microsoft's security update for all affected Windows 10 and Windows Server builds per vendor instructions, as required by CISA's KEV catalog, and upgrade any systems on builds 1607-1903 that no longer receive updates to a supported Windows release. Because exploitation requires local logon, prioritize patching multi-user workstations, RDP-exposed servers, and systems at ransomware risk, and confirm remediation by checking that the OS build includes the AppXSVC hard-link fix.

7.87% KEV ransomware
  • microsoft Windows 10 1607
  • microsoft Windows 10 1703
  • microsoft Windows 10 1709
  • +8 more
masshundreds of millions of Windows 10 and Windows Server installations worldwide
CVE-2019-1069
Local Privilege Escalation in Microsoft Windows Task Scheduler

CVE-2019-1069 is a local elevation-of-privilege flaw in the Microsoft Windows Task Scheduler Service, which fails to correctly validate certain file operations (improper link/path resolution, CWE-59) that the service performs on behalf of running tasks. An attacker who has already gained unprivileged code execution on a target machine can trigger the vulnerable file operation so it is carried out by the Task Scheduler service with its elevated rights. Successful exploitation yields elevated privileges on the victim system, with CVSS impact rated High for confidentiality, integrity and availability, effectively giving the attacker full control of the local host. Affected products are Windows 10 versions 1507 through 1903 and Windows Server 1803, 1903, 2016 and 2019 — i.e., the Task Scheduler component in all of these builds. The flaw is exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-15 with known ransomware use, a public proof-of-concept has existed since June 2019, and EPSS estimates a ~6.1% probability of exploitation within 30 days (93rd percentile).

Do: Apply Microsoft's security updates for CVE-2019-1069 (released in the June 2019 Patch Tuesday cumulative updates) or later cumulative updates on Windows 10 1507–1903 and Windows Server 1803/1903/2016/2019, per CISA's required action. Verify installed OS builds against the affected list and prioritize shared/multi-user hosts (RDS/VDI, jump servers, workstations of users who run untrusted software), since ransomware operators chain this local privilege escalation after initial access. Where patching is delayed, restrict unprivileged code execution and monitor for suspicious scheduled-task and file-operation activity by the Task Scheduler service.

7.86% KEV ransomware PoC
  • Microsoft Windows 10 1507, 1607, 1703, 1709, 1803, 1809, 1903
  • Microsoft Windows Server 1803, 1903, 2016, 2019
masshundreds of millions of Windows 10/Windows Server installations (every unpatched Windows 10 1507–1903 or Server 1803/1903/2016/2019 machine carries the…
Full article435 words · extracted from securityaffairs.com · click to collapse

Microsoft releases Patch Tuesday security updates for June 2019 that address 88 vulnerabilities in Windows OS and other products.

Microsoft Patch Tuesday security updates for June 2019 address 88 vulnerabilities in Windows OS and other products of the tech giant (Internet Explorer, Microsoft Edge browser, Microsoft Office and Services, ChakraCore, Skype for Business, Microsoft Lync, Microsoft Exchange Server, and Azure).

21 out of 88 flaws are rated as Critical in severity, 66 as Important, and only one of them rated as Moderate in severity.

Microsoft addressed four publicly exposed privilege escalation issues rated as important. None of these vulnerabilities was exploited in attacks in the wild.

The flaws were disclosed by the researcher SandboxEscaper over the past weeks, below the list of the issue:

One of the critical vulnerabilities fixed by Microsoft is a Windows Hyper-V Remote Code Execution issue tracked as CVE-2019-0620.

“A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary code.” reads the security advisory.

“An attacker who successfully exploited the vulnerability could execute arbitrary code on the host operating system.”

Microsoft fixes a total of three critical remote code execution vulnerabilities in Windows Hyper-V (CVE-2019-0620, CVE-2019-0709, CVE-2019-0722), the Microsoft virtualization software that allows running multiple operating systems as virtual machines on Windows.

The Remote code execution flaws in the Hyper-V allow an attacker to execute arbitrary code on the host operating system just by executing a specially crafted application on a guest operating system.

Patch Tuesday security updates for June 2019 also addressed two important severity vulnerabilities, tracked as CVE-2019-1040 and CVE-2019-1019, that affect Microsoft’s NTLM authentication protocol. The flaws could be exploited by remote attackers to bypass NTLM protection mechanisms and re-enable NTLM Relay attacks.

The full list of vulnerabilities addressed by Microsoft is available here.

Experts pointed out that Microsoft failed to address a flaw in SymCrypt, a core cryptographic function library currently used by Windows. The flaw could be exploited by malicious programs trigger a denial of service condition by interrupting the encryption service for other programs.

This vulnerability was found by white hat hacker Tavis Ormandy from Google Project Zero. According to the Google 90-days disclosure policy, Ormandy today publicly released details and proof-of-concept of the vulnerability.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – Microsoft Patch Tuesday, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/86987/security/microsoft-patch-tuesday-june-2019.html