
Microsoft today released security fixes for 64 vulnerabilities, along with four security advisories.
Of the bugs fixed, 17 are rated critical, 45 are important, one is moderate, and one is low. Four vulnerabilities are publicly known. Two have already been exploited. This month's updates cover Microsoft Windows, Office and Web applications, Internet Explorer, Edge, Exchange Server, ChakraCore, .NET Framework, Team Foundation Services, and the NuGet packet manager.
The vulnerabilities used in the attacks are two zero-day vulnerabilities in Windows, which are considered important and allow an attacker with access to the system to take over the system.
The first vulnerability, CVE-2019-0797, was reported by Kaspersky Lab and affects versions of Windows 8, Windows 10, and Windows Server 2012, 2016, and 2019. The second vulnerability, CVE-2019-0808, was reported by Google's Threat Analysis Group. Researchers recently discoveredthat attackers are exploiting a vulnerability in Google Chrome (CVE-2019-5786) along with the Microsoft flaw to attack systems.
This is the third consecutive month that Microsoft has issued multiple patches for the Windows Server DHCP service. It started the year by patching the RCE vulnerability CVE-2019-0547 in January. The following month, it released CVE-2019-0626 to fix a memory corruption bug in the DHCP service that could allow an attacker to execute arbitrary code on a DHCP server.
"There are three Windows DHCP Client Remote Execution Code vulnerabilities with a CVSS score of 9.8 in this month's release," noted Satnam Narang, senior researcher at Tenable, who said that the continuation of this patching trend signals an "increased attention to finding DHCP vulnerabilities.".
Now, March brings CVE-2019-0697, CVE-2019-0698, and CVE-2019-0726. Each patch addresses a flaw that could allow attackers to execute code on targeted systems. It’s worth noting that none of these vulnerabilities, which were rated critical, require user interaction. An attacker could send specially crafted DHCP responses to a client in order to exploit the flaw and gain access to the system.
Other critical bugs addressed are in the Chakra Scripting Engine, VBScript Engine, and Internet Explorer.
The day before the release of the latest set of security fixes, Microsoft announced a new Windows 10 feature that automatically restarts updates that fail due to incompatibility or new software issues. If this happens, users will see a notification that says: “We have removed some recently installed updates to help your device recover from a startup failure,” Microsoft says.
This step is only taken if any other automatic recovery proves unsuccessful.
