It's 2020 and a rogue ICMPv6 network packet can pwn your Microsoft Windows machine
- Reference: 1602619792
- News link: https://www.theregister.co.uk/2020/10/13/microsoft_patch_tuesday/
- Source link:
Nadella's security crew has identified 22 remote code execution (RCE) CVEs though the most worrisome looks like CVE-2020-16898, [1]Windows TCP/IP RCE , which is rated 9.8 out 10 in severity. It affects Windows desktop and server systems.
According to Microsoft, the Windows TCP/IP stack doesn't properly handle ICMPv6 Router Advertisement packets. Thus someone could send a vulnerable machine a maliciously crafted IPv6 packet over the network to inject and execute code on the box, and ultimately hijack it – presumably with kernel-level privileges. Here's the worrying blurb from Redmond:
A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could gain the ability to execute code on the target server or client.
To exploit this vulnerability, an attacker would have to send specially crafted ICMPv6 Router Advertisement packets to a remote Windows computer.
The update addresses the vulnerability by correcting how the Windows TCP/IP stack handles ICMPv6 Router Advertisement packets.
Microsoft said exploitation is likely, and a workaround is available for Windows build 1709 and above. You're urged to patch this ASAP, though.
"Since the code execution occurs in the TCP/IP stack, it is assumed the attacker could execute arbitrary code with elevated privileges," said Zero Day Initiative's Dustin Childs in a [2]summary of today's patches.
"If you’re running an IPv6 network, you know that filtering router advertisements is not a practical workaround. Microsoft also gives this bug its highest exploitability rating, so exploits are likely. You should definitely test and deploy this patch as soon as possible."
CVE-2020-16947, a [3]Microsoft Outlook RCE , also looks like it could pose problems. Rated with a CVSS score of 8.1/10, this memory handling flaw could allow an attacker to send a user with admin rights a specially crafted file and take over the system, if the preview pane is open.
"The specific flaw exists within the parsing of HTML content in an email," explained Childs. "The issue results from the lack of proper validation of the length of user-supplied data before copying it to a fixed-length heap-based buffer."
A total of 11 flaws are designated critical, 75 rate moderate, and one is merely important. Six of them have already been publicly disclosed.
Affected applications [4]include :
Microsoft Windows
Microsoft Office and Microsoft Office Services and Web Apps
Microsoft JET Database Engine
Azure Functions
Azure Sphere
Open Source Software
Microsoft Exchange Server
Visual Studio
PowerShellGet
Microsoft .NET Framework
Microsoft Dynamics
Microsoft Windows Codecs Library
The 88th entry on Microsoft's list is an [5]advisory for Adobe Flash Player for Windows, which along with the versions for macOS, Linux and Chrome OS, contains a critical arbitrary code execution flaw (CVE-2020-9746).
Exploitation of the vulnerability "requires an attacker to insert malicious strings in an HTTP response that is by default delivered over TLS/SSL," according to Adobe.
The seven deadly sins letting hackers hijack America's govt networks: These unpatched bugs leave systems open [6]READ MORE
Users should install Adobe Flash Player 32.0.0.445 on the applicable operating system and enjoy whatever time they have left with the app – Adobe plans to stop distributing Flash Player on December 31, 2020.
Enterprise software vendor SAP also delivered [7]parcel of patches – 15 plus six additional patches to previous patches.
The most serious of these is an OS command injection vulnerability (CVE-2020-6364) affecting SAP Solution Manager (CA Introscope Enterprise Manager) and SAP Focused Run (CA Introscope Enterprise Manager), Versions - WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7. The bug rates 10 out of 10 in severity.
Intel released [8]one security advisory covering three vulnerabilities in the BlueZ open-source Bluetooth stack. These high severity flaws could lead to privilege escalation and information disclosure. The fixes involve a Linux kernel update.
Red Hat meanwhile issued [9]a security advisory for the Chromium browser in various Red Hat Enterprise Linux 6 packages. It addresses [10]35 fixes delivered by Google last week.
On the bright side, 87 CVEs is significantly less than the 129 Microsoft addressed in September. ®
Get our [11]Tech Resources
[1] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16898
[2] https://www.zerodayinitiative.com/blog/2020/10/13/the-october-2020-security-update-review
[3] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-16947
[4] https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/2020-Oct
[5] https://helpx.adobe.com/security/products/flash-player/apsb20-58.html
[6] https://www.theregister.com/2020/10/12/cisa_fbi_warning/
[7] https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196
[8] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00435.html
[9] https://access.redhat.com/errata/RHSA-2020:4235
[10] https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
[11] https://whitepapers.theregister.com/
Re: IP6 is the second thing I turn off
It's over fifteen years since I did things with Windows. However, what I hear from people who currently administer Windows networks is that, whenever you call on Microsoft Support to help troubleshoot an issue and they discover that you've switched off IPv6, they won't be able to help you until you switch IPv6 back on. Everything is designed with a functioning IPv6 in mind and switching it off could cause weird issues. Perhaps because it's used for local discovery or localhost (:1) loop back etc.
reminds me..
reminds me of the basic packet exploits against windows systems back in the 90s, I think teardrop was one, then there was a "ping of death" and others though at the time those just caused crashes, not sure if they were able to execute code as well.
IP6 is the second thing I turn off
first is automatic updates