ZeroHour
Krebs on Securitypublished ()ingested

Patch Tuesday, November 2019 Edition

criticalVulnerability exploited in the wildimportance 60CVE-2019-1429CVE-2019-1457CVE-2019-13720

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-13720
Use-After-Free in Google Chrome WebAudio Allows Heap Corruption (Actively Exploited)

CVE-2019-13720 is a use-after-free (CWE-416) in the WebAudio component of Google Chrome that exists in all releases prior to 78.0.3904.87. A remote attacker can trigger the flaw by luring a user to a crafted HTML page, corrupting the heap when the browser processes audio through the freed memory. Successful exploitation can lead to remote code execution with high impact on confidentiality, integrity, and availability, and a public proof-of-concept for Chrome 78.0.3904.70 is available. The flaw affects desktop and mobile users running vulnerable Chrome builds as well as the Chromium package shipped for openSUSE Leap. Exploitation is confirmed in the wild: Google fixed it as an actively exploited issue in November 2019, it was used in the Operation WizardOpium attacks, and it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-23.

Do: Upgrade Google Chrome to 78.0.3904.87 or later (check the current version via the browser's About/Help page) and update the Chromium package on openSUSE Leap using the distribution's update channels. Because this flaw is triggered via a crafted web page and there are no reliable configuration workarounds, prioritizing browser patching across all endpoints is the key mitigation. Defenders should also review whether any user activity coincided with the Operation WizardOpium campaign, as this bug was chained in active attacks.

8.873% KEV PoC
  • google chrome all versions prior to 78.0.3904.87 (vulnerable builds include 78.0.3904.70 and earlier)
  • opensuse leap
masshundreds of millions to billions of Chrome installations worldwide (Chrome is the dominant web browser)
CVE-2019-1429
Memory corruption RCE in Microsoft Internet Explorer scripting engine

CVE-2019-1429 is a memory corruption flaw (use-after-free/out-of-bounds write, CWE-416/CWE-787) in the way the Internet Explorer scripting engine handles objects in memory, allowing remote code execution. It is triggered remotely by convincing a user to view attacker-controlled web content — for example, a malicious website opened in Internet Explorer or an application embedding the IE engine — requiring no privileges but user interaction (CVSS 3.1 AV:N/AC:H/PR:N/UI:R). A successful exploit runs attacker code with the privileges of the logged-in user, enabling malware installation, data theft, and account compromise. Users of Internet Explorer on Windows are affected, since IE is present by default across Windows installations. The flaw was actively exploited as a zero-day at its November 2019 disclosure (associated with the Magnitude exploit kit per related coverage), carries a public proof-of-concept, and is listed in CISA's Known Exploited Vulnerabilities catalog.

Do: Apply the November 2019 Microsoft security updates (Internet Explorer cumulative updates) per Microsoft's instructions, as required by the CISA KEV listing. Until patched, avoid browsing untrusted or attacker-influenced websites with Internet Explorer and consider directing users to Microsoft Edge instead of legacy IE. Given active in-the-wild use, prioritize this patch in your deployment schedule and verify IE cumulative updates are installed on all Windows endpoints.

7.577% KEV PoC
  • Microsoft Internet Explorer
masshundreds of millions of Windows users (IE ships by default with Windows, and exploit kit delivery puts at least exposed users at broad scale)
CVE-2019-1457
A security feature bypass vulnerability exists in Microsoft Office software by not enforcing macro settings on an Excel document, aka 'Microsoft Office Excel Se

A security feature bypass vulnerability exists in Microsoft Office software by not enforcing macro settings on an Excel document, aka 'Microsoft Office Excel Security Feature Bypass'.

NVD description · AI analysis pending
7.83%
  • microsoft office
Full article838 words · extracted from krebsonsecurity.com · click to collapse

Microsoft today released updates to plug security holes in its software, including patches to fix at least 74 weaknesses in various flavors of Windows and programs that run on top of it. The November updates include patches for a zero-day flaw in Internet Explorer that is currently being exploited in the wild, as well as a sneaky bug in certain versions of Office for Mac that bypasses security protections and was detailed publicly prior to today’s patches.

More than a dozen of the flaws tackled in this month’s release are rated “critical,” meaning they involve weaknesses that could be exploited to install malware without any action on the part of the user, except for perhaps browsing to a hacked or malicious Web site or opening a booby-trapped file attachment.

Perhaps the most concerning of those critical holes is a zero-day flaw in Internet Exploder Explorer (CVE-2019-1429) that has already seen active exploitation. Today’s updates also address two other critical vulnerabilities in the same Windows component that handles various scripting languages.

Microsoft also fixed a flaw in Microsoft Office for Mac (CVE-2019-1457) that could allow attackers to bypass security protections in some versions of the program.

Macros are bits of computer code that can be embedded into Office files, and malicious macros are frequently used by malware purveyors to compromise Windows systems. Usually, this takes the form of a prompt urging the user to “enable macros” once they’ve opened a booby-trapped Office document delivered via email. Thus, Office has a feature called “disable all macros without notification.”

But Microsoft says all versions of Office still support an older type of macros that do not respect this setting, and can be used as a vector for pushing malwareWill Dormann of the CERT/CC has reported that Office 2016 and 2019 for Mac will fail to prompt the user before executing these older macro types if the “Disable all macros without notification” setting is used.

Other Windows applications or components receiving patches for critical flaws today include Microsoft Exchange and Windows Media Player. In addition, Microsoft also patched nine vulnerabilities — five of them critical — in the Windows Hyper-V, an add-on to the Windows Server OS (and Windows 10 Pro) that allows users to create and run virtual machines (other “guest” operating systems) from within Windows.

Although Adobe typically issues patches for its Flash Player browser component on Patch Tuesday, this is the second month in a row that Adobe has not released any security updates for Flash. However, Adobe today did push security fixes for a variety of its creative software suites, including Animate, Illustrator, Media Encoder and Bridge. Also, I neglected to note last month that Adobe released a critical update for Acrobat/Reader that addressed at least 67 bugs, so if you’ve got either of these products installed, please be sure they’re patched and up to date.

Finally, Google recently fixed a zero-day flaw in its Chrome Web browser (CVE-2019-13720). If you use Chrome and see an upward-facing arrow to the right of the address bar, you have an update pending; fully closing and restarting the browser should install any available updates.

Now seems like a good time to remind all you Windows 7 end users that Microsoft will cease shipping security updates after January 2020 (this end-of-life also affects Windows Server 2008 and 2008 R2). While businesses and other volume-license purchasers will have the option to pay for further fixes after that point, all other Windows 7 users who want to stick with Windows will need to consider migrating to Windows 10 soon.

Standard heads-up: Windows 10 likes to install patches all in one go and reboot your computer on its own schedule. Microsoft doesn’t make it easy for Windows 10 users to change this setting, but it is possible. For all other Windows OS users, if you’d rather be alerted to new updates when they’re available so you can choose when to install them, there’s a setting for that in Windows Update. To get there, click the Windows key on your keyboard and type “windows update” into the box that pops up.

Keep in mind that while staying up-to-date on Windows patches is a good idea, it’s important to make sure you’re updating only after you’ve backed up your important data and files. A reliable backup means you’re probably not freaking out when the odd buggy patch causes problems booting the system. So do yourself a favor and backup your files before installing any patches.

As ever, if you experience glitches or problems installing any of these patches this month, please feel free to leave a comment about it below; there’s a decent chance other readers have experienced the same and may even chime in here with some helpful tips.

Update, Nov. 13, 11:34 a.m.: An earlier version of this story misstated some of the findings from CERT/CC, and misspelled the name of the researcher. The above post has been corrected.

Text extracted automatically; images, tables and formatting may be missing. Original: https://krebsonsecurity.com/2019/11/patch-tuesday-november-2019-edition/