HomeSecurityMicrosoft: Patch Tuesday November 2019 fixes vulnerability in IE

Microsoft: November 2019 Patch Tuesday fixes IE vulnerability

Patch

Yesterday, Microsoft released its November 2019 Patch Tuesday. One of the most important elements of this patch is the correction of a security , specifically a vulnerability in Internet Explorer, which malicious hackers and were exploiting.

The vulnerability is called CVE-2019-1429. According to Microsoft, it allows attackers to execute code remotely because of a flaw in “the way the scripting engine handles things in memory in Internet Explorer.”

Furthermore, the vulnerability is considered serious because the fact that it is in IE's scripting engine means that it affects many things (not just the browser).

The IE scripting engine is also used within Office Suite apps to display web content in embedded iframes. Therefore, if attackers exploit the vulnerability , they could create malicious Office documents and execute malicious code on the victim's system if the user allows content such as web-based inframes to be displayed . Therefore, the issue should have been addressed in the patch anyway

Microsoft: November 2019 Patch Tuesday fixes IE vulnerability

The zero-day vulnerability in IE was already being exploited by hackers. Three companies (iDefense Labs, Resecurity, and Google) were able to identify attacks related to this vulnerability.

However, the companies did not provide many details about their findings.

Most Windows zero-day vulnerabilities are typically exploited by government hacking groups, but recently they have also been exploited by smaller groups aiming for financial gain.

What other fixes does the new patch bring?

The IE zero-day vulnerability is the most significant issue fixed by the patch. However, the new patch fixes 74 other bugs across nine Microsoft products/platforms.

An important fix concerns Excel for Mac. A few days ago, a security issue was reported regarding the “Disable all macros” setting. This allowed XLM-based macros scripts to run when users opened an Excel spreadsheet, potentially exposing them to attack.

Additionally, the patch includes advice for addressing a mysterious vulnerability present in some Trusted Platform Module (TPM) chipsets.

What vulnerabilities does the November 2019 Patch Tuesday fix? Here is the table, as provided by Microsoft:

TagsCVE IDCVE Title
Servicing Stack UpdatesADV990001Latest Servicing Stack Updates
ChipsetsADV190024Microsoft Guidance for Vulnerability in Trusted Platform Module (TPM) (TPM)
Azure StackCVE-2019-1234Azure Stack Spoofing Vulnerability
Graphic FontsCVE-2019-1456OpenType Font Parsing Remote Code Execution Vulnerability
Microsoft EdgeCVE-2019-1413Microsoft Edge Security Feature Bypass Vulnerability
Microsoft Exchange ServerCVE-2019-1373Microsoft Exchange Remote Code Execution Vulnerability
Microsoft Graphics ComponentCVE-2019-1441Win32k Graphics Remote Code Execution Vulnerability
Microsoft Graphics ComponentCVE-2019-1408Win32k Elevation of Privilege Vulnerability
Microsoft Graphics ComponentCVE-2019-1439Windows GDI Information Disclosure Vulnerability
Microsoft Graphics ComponentCVE-2019-1438Windows Graphics Component Elevation of Privilege Vulnerability
Microsoft Graphics ComponentCVE-2019-1407Windows Graphics Component Elevation of Privilege Vulnerability
Microsoft Graphics ComponentCVE-2019-1394Win32k Elevation of Privilege Vulnerability
Microsoft Graphics ComponentCVE-2019-1393Win32k Elevation of Privilege Vulnerability
Microsoft Graphics ComponentCVE-2019-1396Win32k Elevation of Privilege Vulnerability
Microsoft Graphics ComponentCVE-2019-1395Win32k Elevation of Privilege Vulnerability
Microsoft Graphics ComponentCVE-2019-1437Windows Graphics Component Elevation of Privilege Vulnerability
Microsoft Graphics ComponentCVE-2019-1432DirectWrite Information Disclosure Vulnerability
Microsoft Graphics ComponentCVE-2019-1411DirectWrite Information Disclosure Vulnerability
Microsoft Graphics ComponentCVE-2019-1440Win32k Information Disclosure Vulnerability
Microsoft Graphics ComponentCVE-2019-1419OpenType Font Parsing Remote Code Execution Vulnerability
Microsoft Graphics ComponentCVE-2019-1433Windows Graphics Component Elevation of Privilege Vulnerability
Microsoft Graphics ComponentCVE-2019-1436Win32k Information Disclosure Vulnerability
Microsoft Graphics ComponentCVE-2019-1412OpenType Font Driver Information Disclosure Vulnerability
Microsoft Graphics ComponentCVE-2019-1434Win32k Elevation of Privilege Vulnerability
Microsoft Graphics ComponentCVE-2019-1435Windows Graphics Component Elevation of Privilege Vulnerability
Microsoft JET Database EngineCVE-2019-1406Jet Database Engine Remote Code Execution Vulnerability
Microsoft OfficeCVE-2019-1445Microsoft Office Online Spoofing Vulnerability
Microsoft OfficeCVE-2019-1449Microsoft Office ClickToRun Security Feature Bypass Vulnerability
Microsoft OfficeCVE-2019-1446Microsoft Excel Information Disclosure Vulnerability
Microsoft OfficeCVE-2019-1447Microsoft Office Online Spoofing Vulnerability
Microsoft OfficeCVE-2019-1402Microsoft Office Information Disclosure Vulnerability
Microsoft OfficeCVE-2019-1448Microsoft Excel Remote Code Execution Vulnerability
Microsoft OfficeCVE-2019-1457Microsoft Office Excel Security Feature Bypass
Microsoft Office SharePointCVE-2019-1443Microsoft SharePoint Information Disclosure Vulnerability
Microsoft Office SharePointCVE-2019-1442Microsoft Office Security Feature Bypass Vulnerability
Microsoft RPCCVE-2019-1409Windows Remote Procedure Call Information Disclosure Vulnerability
Microsoft Scripting EngineCVE-2019-1426Scripting Engine Memory Corruption Vulnerability
Microsoft Scripting EngineCVE-2019-1429Scripting Engine Memory Corruption Vulnerability
Microsoft Scripting EngineCVE-2019-1427Scripting Engine Memory Corruption Vulnerability
Microsoft Scripting EngineCVE-2019-1428Scripting Engine Memory Corruption Vulnerability
Microsoft Scripting EngineCVE-2019-1390VBScript Remote Code Execution Vulnerability
Microsoft WindowsCVE-2019-1383Windows Data Sharing Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2019-1418Windows Modules Installer Service Information Disclosure Vulnerability
Microsoft WindowsCVE-2018-12207Windows Denial of Service Vulnerability
Microsoft WindowsCVE-2019-1420Windows Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2019-1417Windows Data Sharing Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2019-1415Windows Installer Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2019-1374Windows Error Reporting Information Disclosure Vulnerability
Microsoft WindowsCVE-2019-1422Windows Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2019-1423Windows Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2019-1424NetLogon Security Feature Bypass Vulnerability
Microsoft WindowsCVE-2019-1382Microsoft ActiveX Installer Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2019-1385Windows AppX Deployment Extensions Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2019-1380Microsoft splwow64 Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2019-1388Windows Certificate Dialog Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2019-1391Windows Denial of Service Vulnerability
Microsoft WindowsCVE-2019-1384Microsoft Windows Security Feature Bypass Vulnerability
Microsoft WindowsCVE-2019-1405Windows UPnP Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2019-1381Microsoft Windows Information Disclosure Vulnerability
Microsoft WindowsCVE-2019-1379Windows Data Sharing Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2019-1324Windows TCP/IP Information Disclosure Vulnerability
Open Source SoftwareCVE-2019-1370Open Enclave SDK Information Disclosure Vulnerability
Visual StudioCVE-2019-1425Visual Studio Elevation of Privilege Vulnerability
Windows Hyper-VCVE-2019-1398Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-VCVE-2019-1310Windows Hyper-V Denial of Service Vulnerability
Windows Hyper-VCVE-2019-0719Hyper-V Remote Code Execution Vulnerability
Windows Hyper-VCVE-2019-1399Windows Hyper-V Denial of Service Vulnerability
Windows Hyper-VCVE-2019-1397Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-VCVE-2019-0712Windows Hyper-V Denial of Service Vulnerability
Windows Hyper-VCVE-2019-0721Hyper-V Remote Code Execution Vulnerability
Windows Hyper-VCVE-2019-1389Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-VCVE-2019-1309Windows Hyper-V Denial of Service Vulnerability
Windows KernelCVE-2019-1392Windows Kernel Elevation of Privilege Vulnerability
Windows KernelCVE-2019-11135Windows Kernel Information Disclosure Vulnerability
Windows Media PlayerCVE-2019-1430Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Windows Subsystem for LinuxCVE-2019-1416Windows Subsystem for Linux Elevation of Privilege Vulnerability
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS