September is upon us and with it brings the latest security patches from Microsoft and Adobe. Take a break from your regularly scheduled activities and join us as we review the details for security patches for this month.
Adobe Patches for September 2019
Adobe had a small release for September with only two patches covering a total of three CVEs in Adobe Flash and Application Manager. The update for patch fixes an Important-severity DLL hijacking bug.
Neither of these bugs are listed as being publicly known or under active attack at the time of release.
Microsoft Patches for September 2019
This month, Microsoft released security patches for 80 CVEs plus two advisories. The updates cover Microsoft Windows, Internet Explorer, Microsoft Edge, ChakraCore, Office and Microsoft Office Services and Web Apps, Skype for Business and Microsoft Lync, Visual Studio, .NET Framework, Exchange Server, Microsoft Yammer, and Team Foundation Server. Of these 80 CVEs, 17 are listed as Critical, 62 are listed as Important, and one is listed as Moderate in severity. A total of 18 of these CVEs came through the ZDI program. Two of the bugs this month are listed as publicly known at the time of release, and two other bugs are listed as under active attack.
Let’s take a closer look at some of the more interesting patches for this month, starting with the bugs under active attack:
- – Windows Common Log File System Driver Elevation of Privilege Vulnerability
The other bug under active attack this month is also a Windows LPE, this time in the Common Log File System (CLFS) Driver. Again, an attacker could use this to elevate from a regular user to one with Administrative privileges. According to Microsoft, this CVE is only being seen targeting older operating systems. This is a fine time to remind you that Windows 7 is less than six months from – Windows Update Delivery Optimization Elevation of Privilege Vulnerability
This patch corrects a rather intriguing bug in the Windows Update Delivery Optimization (WUDO) feature found in Windows 10. This component is designed to reduce network bandwidth by having PCs grab updates from other peers on a network that already have downloaded the update. A local attacker could use this vulnerability to overwrite files they would normally not have permissions to. While this clearly could lead to an LPE on the local system, it’s not clear if it could be used to impact other systems through WUDO. If you’re using this feature, definitely roll this patch out quickly or disable the feature entirely.
- through the ZDI program. For this particular case, an attacker could execute their code under the context of the SharePoint application pool identity by uploading a specially crafted SharePoint application package to an affected server. Normally, you would need to authenticate to upload such a package – unless you have enabled anonymous access. But you wouldn’t do that. Would you? We’ll also have more details about these bugs on our blog in the near future. Stay tuned…
Here’s the full list of CVEs released by Microsoft for September 2019.
CVE | Title | Severity | Public | Exploited | XI - Latest | XI - Older | Type |
Windows Elevation of Privilege Vulnerability | Important | No | Yes | 0 | 0 | EoP | |
Windows Secure Boot Security Feature Bypass Vulnerability | Important | Yes | No | 2 | 2 | SFB | |
Remote Desktop Client Remote Code Execution Vulnerability | Critical | No | No | 1 | 1 | RCE | |
VBScript Remote Code Execution Vulnerability | Critical | No | No | 2 | 2 | RCE | |
Scripting Engine Memory Corruption Vulnerability | Critical | No | No | 2 | N/A | RCE | |
Chakra Scripting Engine Memory Corruption Vulnerability | Critical | No | No | 2 | 2 | RCE | |
LNK Remote Code Execution Vulnerability | Critical | No | No | 2 | 2 | RCE | |
Remote Desktop Client Remote Code Execution Vulnerability | Critical | No | No | 1 | 1 | RCE | |
Microsoft SharePoint Remote Code Execution Vulnerability | Critical | No | No | 1 | 1 | RCE | |
Chakra Scripting Engine Memory Corruption Vulnerability | Critical | No | No | 2 | N/A | RCE | |
Windows Hyper-V Denial of Service Vulnerability | Important | No | No | N/A | 2 | DoS | |
Lync 2013 Information Disclosure Vulnerability | Important | No | No | 2 | N/A | Info | |
Windows Transaction Manager Information Disclosure Vulnerability | Important | No | No | 1 | 1 | Info | |
Rome SDK Information Disclosure Vulnerability | Important | No | No | 2 | 2 | Info | |
Microsoft Exchange Denial of Service Vulnerability | Important | No | No | 2 | 2 | DoS | |
Jet Database Engine Remote Code Execution Vulnerability | Important | No | No | 2 | 2 | RCE | |
Jet Database Engine Remote Code Execution Vulnerability | Important | No | No | 2 | 2 | RCE | |
DirectWrite Information Disclosure Vulnerability | Important | No | No | 2 | 2 | Info | |
Jet Database Engine Remote Code Execution Vulnerability | Important | No | No | 2 | 2 | RCE | |
Jet Database Engine Remote Code Execution Vulnerability | Important | No | No | 2 | 2 | RCE | |
DirectWrite Information Disclosure Vulnerability | Important | No | No | 2 | 2 | Info | |
Windows Elevation of Privilege Vulnerability | Important | No | No | 2 | 2 | EoP | |
Win32k Elevation of Privilege Vulnerability | Important | No | No | 3 | 1 | EoP | |
Microsoft SharePoint Elevation of Privilege Vulnerability | Important | No | No | 2 | 2 | EoP | |
Microsoft Office SharePoint XSS Vulnerability | Important | No | No | N/A | 2 | XSS | |
Microsoft Office Security Feature Bypass Vulnerability | Important | No | No | N/A | 2 | SFB | |
Microsoft Exchange Spoofing Vulnerability | Important | No | No | 2 | 2 | Spoof | |
Winlogon Elevation of Privilege Vulnerability | Important | No | No | 2 | 2 | EoP | |
Microsoft Windows Store Installer Elevation of Privilege Vulnerability | Important | No | No | 2 | 2 | EoP | |
Windows ALPC Elevation of Privilege Vulnerability | Important | No | No | 2 | 2 | EoP | |
Windows Kernel Information Disclosure Vulnerability | Important | No | No | 2 | 2 | Info | |
Windows Elevation of Privilege Vulnerability | Important | No | No | 2 | 2 | EoP | |
Microsoft Graphics Components Information Disclosure Vulnerability | Important | No | No | N/A | 2 | Info | |
Win32k Elevation of Privilege Vulnerability | Important | No | No | 1 | 1 | EoP | |
Windows Network Connectivity Assistant Elevation of Privilege Vulnerability | Important | No | No | 2 | 2 | EoP | |
Windows Denial of Service Vulnerability | Important | No | No | 2 | 2 | DoS | |
Microsoft Excel Remote Code Execution Vulnerability | Important | No | No | 2 | 2 | RCE | |
.NET Core Denial of Service Vulnerability | Important | No | No | 2 | 2 | DoS | |
Windows Elevation of Privilege Vulnerability | Important | No | No | 2 | 2 | EoP | |
Microsoft SharePoint Spoofing Vulnerability | Moderate | No | No | N/A | 2 | Spoof | |
Of the public patches, one was highly publicized through a and source code.
More interestingly, this is the second month in a row with patch for an LNK vulnerability. Considering the history of exploits using LNK vulnerabilities, including recent . The other is the update to the Windows Servicing Stack, which adds updates for Windows 10 version 1607, Windows Server 2016, Windows 10 version 1809, and Windows Server 2019.
Looking Ahead
The next patch Tuesday falls on October 8, and we’ll return with details and patch analysis then. Until then, happy patching and may all your reboots be smooth and clean!
SOCIAL SHARE CARD GENERATOR