
The new security updates released by Microsoft for September 2019 address 80 vulnerabilities, including two privilege escalation flaws that can be exploited by hackers to carry out attacks.
The updates cover Microsoft Windows, Internet Explorer, Microsoft Edge, ChakraCore, Office and Microsoft Office services and web applications, Skype for Business and Microsoft Lync, Visual Studio, .NET Framework, Exchange Server, Microsoft Yammer, and Team Foundation Server.
Of the vulnerabilities addressed by these updates, 17 are classified as critical, 62 are listed as important, and one is rated as moderate in severity.
The first zero-day vulnerability, discovered as CVE-2019-1214, is located in the Windows Common Log File System (CLFS) and can be exploited by a skilled attacker to carry out attacks. The vulnerability affects all supported versions of Windows.
"You are experiencing an increase in privilege escalation vulnerabilities when the Windows Common Log File System (CLFS) program does not properly handle objects in memory. An attacker who successfully exploited this vulnerability could execute processes with increased privileges," Microsoft said in an update.
“To exploit the vulnerability, an attacker would first have to log on to the system and then execute a specially crafted applicationto take control of the affected system.”
Microsoft is addressing the vulnerability by patching the way CLFS handles objects in memory.
The flaw was reported by a researcher from the Vulcan Qihoo 360 team.
The second zero-day vulnerability, CVE-2019-1215, affects Winsock (ws2ifsl.sys) and could be exploited by an informed attacker to execute privilege escalation code.
"To exploit the vulnerability, an attacker could run a specially crafted application."
Microsoft addressed the vulnerability by ensuring that ws2ifsl.sys correctly handles objects in memory.
The company also confirmed that this flaw has already been exploited by malware since 2017.
Microsoft also addressed two vulnerabilities that were publicly disclosed before the fixes were available, CVE-2019-1235 and CVE-2019-1294.
The first is a privilege escalation issue in the Windows Text Service Framework, the second is a Windows Secure Boot bypass issue.
