Today’s VERT Alert addresses Microsoft’s November 2019 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-859 on Wednesday, November 13th.
In-The-Wild & Disclosed CVEs
A vulnerability in the scripting engine in Internet Explorer can lead to code execution. The attacker could corrupt memory and execute code in the context of the current user. Microsoft has indicated that this attack is currently seeing active exploitation. Impacted organizations should apply this patch as soon as possible.
Microsoft has rated this as a 0 (Exploitation Detected) on both the latest software release and on older software releases on the Exploitability Index.
This publicly disclosed, but yet to be exploited security bypass exists in Microsoft Office for Mac 2016 and 2019. Specifically, Office for Mac does not properly enforce macro settings in Excel documents allowing an attacker to embed a control in Excel worksheets that indicates a macro should be run. Victims would need to open malicious Excel documents in order to be attacked.
Microsoft has rated this as Not Applicable on both the latest software release and on older software releases on the Exploitability Index.
CVE Breakdown by Tag
While historical Microsoft Security Bulletin groupings are gone, Microsoft vulnerabilities are tagged with an identifier. This list provides a breakdown of the CVEs on a per tag basis.
CVE-2019-0712, CVE-2019-0719, CVE-2019-0721, CVE-2019-1309, CVE-2019-1310, CVE-2019-1389, CVE-2019-1397, CVE-2019-1398, CVE-2019-1399
Open Source Software
Windows Subsystem for Linux
Microsoft JET Database Engine
Windows Media Player
Microsoft Graphics Component
CVE-2019-1432, CVE-2019-1433, CVE-2019-1434, CVE-2019-1435, CVE-2019-1436, CVE-2019-1437, CVE-2019-1438, CVE-2019-1439, CVE-2019-1440, CVE-2019-1441, CVE-2019-1393, CVE-2019-1394, CVE-2019-1395, CVE-2019-1396, CVE-2019-1407, CVE-2019-1408, CVE-2019-1411, CVE-2019-1412, CVE-2019-1419
Microsoft Scripting Engine
CVE-2019-1429, CVE-2019-1390, CVE-2019-1426, CVE-2019-1427, (Read more...)
*** This is a Security Bloggers Network syndicated blog from The State of Security authored by Tyler Reguly. Read the original post at: https://www.tripwire.com/state-of-security/vert/vert-threat-alert-november-2019-patch-tuesday-analysis/