Microsoft’s November 2019 Patch contains updates for 74 CVEs, 13 of which are rated critical. This month’s release covers 16 remote code execution (RCE) vulnerabilities and 27 elevation of privilege (EoP) flaws across a variety of products. Additionally, Microsoft has patched an increased number of vulnerabilities in Hyper-V, a number of which were denial of service (DoS) flaws. The following is a breakdown of the most important CVEs from this month’s release.
“This month’s Patch release contains updates for nearly 75 CVEs. One of the vulnerabilities, CVE-2019-1429, was first exploited in the wild as a zero day and could enable an attacker to execute arbitrary code under the same privileges of the current user. If the user has administrative rights, an attacker would be able to perform a variety of actions, such as creating a new account with full user rights, installing programs, and viewing, changing or deleting data. An attacker would need to convince a user to visit a website containing the exploit code using Internet Explorer in order to exploit the flaw.” said Satnam Narang, Senior Research Engineer at Tenable.
He added, “CVE-2019-1457, which was publicly disclosed at the end of October, is a security feature bypass in Microsoft Office for Mac due to improper enforcement of macro settings in Excel documents. An attacker would need to create a specially crafted Excel document using the SYLK (SYmbolic LinK) file format and convince a user to open such a file using a vulnerable version of Microsoft Office for Mac. Successful exploitation would allow an attacker to execute arbitrary code on the victim’s system.”
CVE-2019-1429 | Scripting Engine Memory Corruption Vulnerability
CVE-2019-1429 is a critical flaw in Internet Explorer, which Microsoft notes as being exploited in the wild. This RCE exists due to a flaw in the way the scripting engine handles objects in memory in Internet Explorer. An attacker who is able to exploit this vulnerability could gain the same rights as the current user. Exploitation is somewhat mitigated in that an attacker would need to entice a user to visit a crafted web site or embed an ActiveX control marked “safe for initialization” in an application or Microsoft Office document.
CVE-2019-0721, CVE-2019-1397, CVE-2019-1398, CVE-2019-1399 | Hyper-V Remote Code Execution Vulnerabilities
CVE-2019-0721, CVE-2019-1397, CVE-2019-1398, and CVE-2019-1399 are RCE vulnerabilities in Windows Hyper-V. An attacker could run malicious code on a guest operating system that could cause the Windows Hyper-V host to execute arbitrary code. An attacker would need to gain access to a virtual machine (VM) through other means on the vulnerable host, but once access is obtained, an attacker could escape the VM sandbox and pivot to other VMs on the same host.
CVE-2019-1457 | Microsoft Office Excel Security Feature Bypass
CVE-2019-1457 is a security feature bypass vulnerability in Microsoft Office for Mac caused by a failure to enforce macro settings in an Excel document. This flaw was publicly disclosed on October 30 by Outflank, an IT Security firm focused on red teaming and security testing. The Outflank blog post details attack scenarios using the SYLK file format to include XLM macros into SYLK files. Because SYLK files do not open in Protected View, an end-user opening a specially crafted file would receive no warning or prompt from Excel about opening the file and would have none of the protection offered by the Protected View security feature. Additionally, if Office for Mac has been configured to use the “Disable all macros without notification” feature, XLM macros in SYLK files can be executed without prompting the user, thereby allowing a remote attacker to execute arbitrary code with the privileges of the user opening the specially crafted file.
CVE-2019-0712, CVE-2019-1310, CVE-2019-1309, CVE-2019-1399, and CVE-2019-1399 | Hyper-V Denial of Service Vulnerabilities
CVE-2019-0712, CVE-2019-1310, CVE-2019-1309, and CVE-2019-1399 are denial of service (DoS) vulnerabilities within Windows Hyper-V. An attacker who has the toolsets to exploit this vulnerability could consume the resources of a target server and cause it to crash. Attackers need a privileged account on the guest operating system, running as a VM to exploit this vulnerability.
CVE-2019-16863 | Microsoft Guidance for Vulnerability in Trusted Platform Module (TPM)
As part of the November updates, Microsoft released the security advisory ADV190024 to discuss CVE-2019-16863. In certain Trusted Platform Module (TPM) chipsets, a vulnerability exists which weakens key confidentiality protection for the Elliptic Curve Digital Signature Algorithm (ECDSA). While this flaw is not in Windows and does not exist in a specific application, it was important enough that Microsoft released this advisory. Administrators are encouraged to contact their TPM manufacturer for firmware updates as well as verify additional mitigation steps that may be required beyond a firmware update. At the time this blog was published, Microsoft notes that there does not appear to be any evidence of an exploit in the wild and that the issue was reported through coordinated disclosure.
If you have an interesting article / experience / case study to share, please get in touch with us at firstname.lastname@example.org