Category: Microsoft|Sep 16, 2019 | Author: Admin

Microsoft September Patch Tuesday Addresses Two Actively Exploited Zero-Day Bugs

Share on

This Tuesday, Microsoft has rolled-out its scheduled monthly updates for 80 different bugs. Notably, the September Patch Tuesday update bundle from Microsoft brings fixes for two zero-day bugs under active exploit.

Patches For Actively Exploited Zero-Day Vulnerabilities The most noteworthy fixes in Microsoft September Patch Tuesday bundle includes ones for two zero-day bugs under active exploit. These two zero-days precisely are privilege escalation bugs. While both of these attained important severity rating, they became a problem owing to their active exploitation in the wild. The first of these is an EoP in the Windows Common Log File System Driver (CVE-2019-1214). The bug existed due to improper object handling in the memory by Windows CLFS. Upon an exploit, the flaw could let an attacker execute processes with elevated user privileges. Regarding the exploit condition, Microsoft stated in their advisory,

To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted application to take control of the affected system.

Whereas, the other EoP existed in the ws2ifsl.sys (Winsock) owing to improper object handling in memory. Regarding this Windows vulnerability (CVE-2019-1215), Microsoft explained in the advisory,

An attacker who successfully exploited the vulnerability could execute code with elevated privileges. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.

Other Microsoft September Patch Tuesday Updates Apart from the two zero-days, Microsoft has also patched 79 other bugs with this update bundle. These include 17 critical vulnerabilities that could allow remote code execution upon an exploit. Of these, 4 existed in the Remote Desktop Client, 5 in the Chakra Scripting Engine, 2 in VBScript, 3 in Microsoft SharePoint, and 1 RCE bug each in Scripting Engine, .LNK file processing, and Azure DevOps Server (ADO) and Team Foundation Server (TFS). Microsoft also fixed 60 other important severity bugs in various products. These bugs, upon exploit, could result in information disclosure, spoofing, the elevation of privileges, or even remote code execution. In addition, Microsoft also patched a moderate severity spoofing vulnerability (CVE-2019-1259), in Microsoft SharePoint. In August, Microsoft addressed 93 vulnerabilities with its Patch Tuesday bundle, more than the ones addressed this month. However, the previous month’s patches did not include any actively exploited bugs. Make sure to update your systems at the earliest to stay protected from potential attacks.

Sponsored Ads:

Comments:


Password program hacked again

Category: IT|Dec 3, 2022 | Author: Admin

Update your iPhone

Category: Apple|Dec 2, 2022 | Author: Admin

Tesla gets Dolby Atmos

Category: General|Dec 1, 2022 | Author: Admin

If Twitter is kicked out by Apple and Google, Musk will make his own mobile phone

Category: IT|Nov 30, 2022 | Author: Admin

The EU is investigating TikTok

Category: IT|Nov 29, 2022 | Author: Admin

Must be scrutinized extra carefully

Category: IT|Nov 28, 2022 | Author: Admin

Important drivers launched

Category: IT|Nov 27, 2022 | Author: Admin

Soon, Apple will make the big iPhone change

Category: Apple|Nov 26, 2022 | Author: Admin

Approaching the Apple iPhone

Category: Google|Nov 25, 2022 | Author: Admin

Microsoft is making an iPhone comeback

Category: Microsoft|Nov 23, 2022 | Author: Admin

This is how the iPhone 15 Pro becomes much faster

Category: Apple|Nov 22, 2022 | Author: Admin

Apple makes iPhone more like Android (if you want)

Category: Apple|Nov 21, 2022 | Author: Admin

These countries cheat the most and this is how they do it

Category: General|Nov 20, 2022 | Author: Admin

How to set up NightScout Docker using CyberPanel Hosting panel

Category: Tutorials|Nov 19, 2022 | Author: Admin

It will soon be over and out, warns Microsoft

Category: Microsoft|Nov 18, 2022 | Author: Admin
more