12px13px15px17px
Date:11/07/19

Microsoft released Patch Tuesday security updates for July 2019

Microsoft released Patch Tuesday updates for July 2019 that address a total of 77 vulnerabilities, 14 rated as Critical, 62 as Important, and only 1 as Moderate in severity.
 
Patch Tuesday updates for July 2019 fixed security issued in numerous products of the tech giant, including Windows operating systems, Internet Explorer, Edge, Office, Azure DevOps, Open Source Software, .NET Framework, Azure, SQL Server, ASP.NET, Visual Studio, and Exchange Server.
 
All the 14 critical vulnerabilities addressed by Microsoft are remote code execution issues affecting various products, including Internet Explorer and Edge to Windows Server DHCP, Azure DevOps and Team Foundation Servers.
 
Technical details for six important security flaws were publicly disclosed before a patch was released, fortunately, there is no news of the exploitation of the flaws in the wild.
 
Microsoft also addressed two privilege escalation flaws actively exploited in the wild.
 
The first one, tracked as CVE-2019-1132, affects the Win32k component and could be exploited to run arbitrary code in kernel mode.
 
“An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.” reads the security advisory.
 
“To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.”
 
The second one, tracked as CVE-2019.0880, affects Windows 7 and Server 2008. The issue resides in the way splwow64 (Thunking Spooler APIs) handles certain calls.
 
“A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity.” reads the advisory.
 
“This vulnerability by itself does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses it in combination with another vulnerability (such as a remote code execution vulnerability or another elevation of privilege vulnerability) that is capable of leveraging the elevated privileges when code execution is attempted.”
 
Important-rated security flaws include remote code execution vulnerabilities, privilege escalation issues, information disclosure, cross-site scripting (XSS), security feature bypass, spoofing, and denial of service flaws.



Views: 54

©ictnews.az. All rights reserved.

Facebook Google Favorites.Live BobrDobr Delicious Twitter Propeller Diigo Yahoo Memori MoeMesto






24 July 2019

23 07 2019

23/07/19
Honor MagicBook Pro launched; features 16.1-inch FHD full-screen display and 8th-gen Intel processor

At the Honor 9X launch event in China, where the company announced the Honor 20 Pro Icelandic Illusion model 

23/07/19
President Trump met with tech CEOs on Monday to discuss Huawei and trade practices

President Donald Trump met with CEOs from Google, Broadcom and other technology companies on Monday 

23/07/19
Virtual Assistant shipments to exceed 2.3 billion in 2023

The market for virtual assistants (VAs) shows strong positive momentum, driven forward by a combination of 

23/07/19
WhatsApp is now available on feature phones with KaiOS

The year of 2018 saw a massive 252% growth in the demand for smart features phones in India even as the

23/07/19
FaceApp creates wave of opportunity for scammers on fake webs and YouTube

The latest hype around the FaceApp application has attracted scammers who want to make some quick profits

23/07/19
Asus’ ROG Phone II is the most spec-heavy gaming phone yet

Asus’s first ROG gaming phone was one of the most maximalist takes on the concept to date, so it’s only appropriate

23/07/19
NVIDIA Launches U.K. Technology Center to Advance AI Research

NVIDIA just launched a new technology center in the UK designed to support groundbreaking research in AI and

23/07/19
2020 iPhone could get blazing-fast display upgrade

The 2020 iPhone generation could bring substantial upgrades, including in the display department.