Microsoft Launches Seven Security Updates

Last week, Microsoft released its advance notification for the December 2014 Patch Tuesday updates, followed by the deployment of seven security bulletins today, aimed at mitigating various vulnerabilities across its software products. Among these, three bulletins are categorized as ‘critical’ while the remaining four are rated ‘important’, reflecting the severity of the issues at hand.

In anticipation of this update, it is noteworthy that November 2014 saw Microsoft issuing a substantial batch of security patches, including an atypical emergency fix that addressed a serious vulnerability within the Kerberos authentication system in Windows. This flaw had reportedly been exploited by cybercriminals to compromise entire networks, showcasing the urgency for ongoing vigilance in system security.

The critical bulletins released this month target Microsoft Internet Explorer, Office, and the Windows operating system itself. Importantly, all versions of Internet Explorer are affected, with the exception of Server Core, which does not include the browser. A significant zero-day vulnerability (CVE-2014-8967) discovered in Internet Explorer by researcher Arthur Gerkis from the Zero Day Initiative poses a considerable risk. This vulnerability allows an attacker to execute arbitrary code on the affected installations but requires user interaction, such as visiting a malicious website or opening a harmful file.

The underlying issue with this flaw relates to how Internet Explorer utilizes reference counting mechanisms to manage the lifecycles of HTML elements in memory. According to the Zero Day Initiative, an attacker can manipulate an object’s reference count, causing it to be deallocated prematurely, which could lead Internet Explorer to mistakenly utilize that object thereafter. This presents a substantial opportunity for remote code execution under the context of the active process, making it imperative for users to address this vulnerability swiftly.

Furthermore, a second critical update impacts Windows Vista, Windows 7, Windows Server 2003, and Windows Server 2008. The vulnerability is rated critical for desktop versions while deemed moderate for server installations. Microsoft Office is also affected, particularly versions like Word 2007 SP3 and later, which face an additional critical remote code execution vulnerability.

Additionally, two security bulletins address important vulnerabilities concerning remote code execution in Microsoft Office Web Apps 2010 and 2013. Though rated as important, these vulnerabilities do exhibit mitigating factors that may reduce the likelihood of successful exploitation. Among the security updates, one targets an elevation of privilege issue impacting Microsoft Exchange Server versions 2007, 2010, and 2013, also rated important. The final bulletin rectifies an information disclosure vulnerability across all Windows versions, including those on Server Core.

For organizations that have automatic updates enabled, the patches will be rolled out via Windows Update, ensuring most users receive them without manual intervention. However, businesses that have disabled this feature are strongly encouraged to implement the updates as soon as possible, noting that some installations may necessitate server reboots post-application.

In order to fully grasp the security landscape surrounding these vulnerabilities, we can reference the MITRE ATT&CK framework. The tactics potentially employed by adversaries could include initial access through user interaction, exploitation of vulnerable components for remote execution, and privilege escalation where applicable. By maintaining a proactive approach and staying informed on these vulnerabilities, organizations can enhance their cyber resilience in an increasingly hostile digital environment.

Source link