November is here and with it comes the latest in security offerings from Adobe and Microsoft. Take a break from your regularly scheduled activities and join us as we review the details for security patches for this month.
Adobe Patches for November 2018
For November, Adobe released patches covering Flash, Acrobat, and Photoshop. The also correct a single info disclosure issue. Adobe notes the proof of concept code for this CVE has been made publicly available. Rounding things out, the – Win32k Elevation of Privilege Vulnerability
Just like last month, November has a Win32K (kernel-mode drivers) elevation of privilege vulnerability listed as currently under active attack. Also like last month, this bug was reported by researchers at Kaspersky Labs, indicating this bug is being used in malware. Again, this is likely being used in targeted attacks in combination with other bugs. Malware often uses kernel elevation bugs to go from user-mode to admin-mode, allowing them full control of a target system.
- – Windows Deployment Services TFTP Server Remote Code Execution Vulnerability
This patch corrects a bug that could allow an attacker to execute code with elevated permissions through a specially crafted TFTP message. Getting elevated code execution over a network without authentication generally means wormable, but for this vulnerability, it would only be wormable to other affected TFTP servers. However, chances are your TFTP server also has other roles. Since this bug allows an attacker to take over a system, any other service – DNS, Active Directory, DHCP, etc. – could also be manipulated. If you’re running deployment services, don’t miss this patch.
- due to bad SSD encryption. Microsoft released Advisory
Windows Win32k Elevation of Privilege
Vulnerability
Important
No
Yes
BitLocker Security Feature Bypass
Vulnerability
Important
Yes
No
Microsoft Graphics Components Remote
Code Execution Vulnerability
Critical
No
No
N/A
Chakra Scripting Engine Memory
Corruption Vulnerability
Critical
No
No
N/A
Chakra Scripting Engine Memory
Corruption Vulnerability
Critical
No
No
N/A
Chakra Scripting Engine Memory
Corruption Vulnerability
Critical
No
No
N/A
Chakra Scripting Engine Memory
Corruption Vulnerability
Critical
No
No
N/A
Dynamics 365 (on-premises) version 8 Remote Code Execution Vulnerability
Critical
No
No
N/A
N/A
Team Foundation Server Cross-site
Scripting Vulnerability
Important
No
No
N/A
N/A
version 8 Cross Site Scripting Vulnerability
Important
No
No
N/A
N/A
version 8 Cross Site Scripting Vulnerability
Important
No
No
N/A
N/A
DirectX Elevation of Privilege
Vulnerability
Important
No
No
DirectX Elevation of Privilege
Vulnerability
Important
No
No
Microsoft SharePoint Elevation of
Privilege Vulnerability
Important
No
No
Windows COM Elevation of Privilege
Vulnerability
Important
No
No
Microsoft SharePoint Elevation of
Privilege Vulnerability
Important
No
No
Microsoft Edge Elevation of Privilege
Vulnerability
Important
No
No
N/A
MSRPC Information Disclosure
Vulnerability
Important
No
No
Win32k Information Disclosure
Vulnerability
Important
No
No
N/A
Windows Kernel Information Disclosure
Vulnerability
Important
No
No
Microsoft SharePoint Information
Disclosure Vulnerability
Important
No
No
PowerShell Remote Code Execution
Vulnerability
Important
No
No
Microsoft Outlook Remote Code Execution
Vulnerability
Important
No
No
Microsoft Word Remote Code Execution
Vulnerability
Important
No
No
N/A
Microsoft Excel Remote Code Execution
Vulnerability
Important
No
No
Microsoft Outlook Remote Code Execution
Vulnerability
Important
No
No
N/A
Microsoft Excel Remote Code Execution
Vulnerability
Important
No
No
Microsoft JScript Security Feature
Bypass Vulnerability
Important
No
No
Microsoft Edge Spoofing
Vulnerability
Important
No
No
N/A
Team Foundation Server Remote Code
Execution Vulnerability
Important
No
No
N/A
N/A
Microsoft Powershell Tampering
Vulnerability
Important
No
No
Microsoft Skype for Business Denial of
Service Vulnerability
Low
No
No
This month sees fewer browser-related patches than previous months, but there are still plenty of browser bugs to cover. There’s also a patch for VBScript that acts like a browser bug since it has the same exploit scenario (browse and own) as the web browsers. This one could also embed an ActiveX controls marked “safe for initialization” in an Office document and trick a user into opening it.
Remote code execution (RCE) bugs dominate this month’s release, with 24 patches for RCE bugs. Many of the RCE bugs corrected this month reside in the Office suite. Word, Excel, Project, SharePoint, and Outlook all receive patches in this release. The Outlook bugs are somewhat interesting, but none can be hit through the Preview Pane. Having an attacker rely on user interaction means defenders have to rely on user education, which is sometimes a risky bet.
Tampering is rarely seen impact, but there are two CVEs this month covering tampering vulns. The first is in .NET Core and could allow attackers to write arbitrary files on a system by sending specially crafted file to an affected system. However, attackers only have limited control over the destination for files. The other tampering bug affects PowerShell and could allow local attackers to execute unlogged code. There’s also a PowerShell RCE bug being patched. In this case, an attacker would need to send a specially crafted file to a target system.
There are also updates for the Windows graphics components, DirectX, Windows kernel, the COM Aggregate Marshaler, and Advanced Local Procedure Calls (ALPC). One of the graphics-related vulnerabilities could allow code execution when viewing a specially crafted image. One of the more esoteric Windows patches corrects an elevation of privilege that could occur if you installed certain builds of Windows from media for Windows 10, version 1809 and an attacker had physical access to the target. That’s a pretty specific attack scenario.
Microsoft Dynamics also receives a fair amount of attention this month, with multiple patches delivering fixes for Microsoft Dynamics 365 (on-premises) version 8. The majority of these patches correct cross-site scripting (XSS) issues. There is also a patch for an RCE in Dynamics that could allow an attacker to execute code at the level of the SQL service account. While this won’t allow someone to completely take over a system, it does allows them to really mess with the information in a database.
Rounding out the November release is a patch for Microsoft Exchange to address an elevation of privilege bug. An attacker could use command injection to impersonate any other user on the Exchange Server. It would require a man-in-the-middle to be successful, but just imagine the hi-jinx that would ensue from sending out spoofed mail. Fortunately for Exchange admins, this bug can be rendered unexploitable just through the deletion of a registry key. That’s much less nerve wracking than a typical Exchange patch.
Finally, there are a few advisories to cover this month, as well. The aforementioned provide a list of the latest servicing stack updates for each operating system. The final advisory for November is Microsoft’s version of the previously discussed Adobe patch for Flash in Internet Explorer.
Looking Ahead
The next patch Tuesday falls on December 11, and we’ll return with details and patch analysis then. Until then, happy patching and may all your reboots be smooth and clean!
SOCIAL SHARE CARD GENERATOR