Microsoft has released its final Microsoft Patch Tuesday for 2019, informing users of a new zero-day vulnerability in Windowsthat hackers in conjunction with a Chrome exploit. The two vulnerabilities together allow attackers to gain remote control over vulnerable computers.
Microsoft's December patch includes fixes for 36 vulnerabilities. 7 of them are rated critical, 27 important, 1 moderate and the last one is slightly serious.
The new zero-day EoP vulnerability, codenamed CVE-2019-1458 and discovered by Kaspersky , has been used in the so-called Operation WizardOpium attacks , along with the Chrome exploit, and helps hackers gain more privileges on targeted systemsby bypassing the Chrome sandbox.
Kaspersky alerted the company to the Chrome exploit (which was first discovered) and Google released an emergency update (Chrome 78.0.3904.87) last month to fix the vulnerability. However, hackers are still targeting users running vulnerable versions of the browser.
According to Kaspersky researchers, the Chrome exploit was linked to the newly patched EoP bug that affects how the Win32k component in the Windows OS handles data in memory.
The EoP exploit is found in “latest versions of Windows 7 and some versions of Windows 10.” Hackers can exploit it to execute malicious code on the vulnerable system.
Researchers were unable to attribute the attacks to any specific hacking group. However, the exploit code bore some similarities to that used by the Lazarus.

Microsoft Patch Tuesday: December 2019
The 7 critical vulnerabilities, which the company is fixing with the new Microsoft Patch, affect Git for Visual Studio, Hyper-V Hypervisor, and the Win32k Graphics component of Windows. Successful exploitation of these vulnerabilities could allow hackers to execute code remotely.
Another significant vulnerability, called CVE-2019-1462, is related to PowerPoint. This vulnerability also allows arbitrary code execution on a targeted computerby convincing the victim to open a malicious PowerPoint file.
This vulnerability affects Microsoft PowerPoint versions 2010, 2013, and 2016 as well as Microsoft Office 2016 for Windows and Apple's macOS.
Other vulnerabilities, fixed by Microsoft Patch Tuesday, affect the following products and services:
- Windows Operating System
- Windows Kernel
- Windows Remote Desktop Protocol (RDP)
- Microsoft Word
- Microsoft Excel
- Microsoft SQL Server Reporting Services
- Microsoft Access software
- Windows GDI component
- Win32k
- Windows Hyper-V
- Windows Printer Service
- Windows COM Server
- Windows Media Player
- Windows OLE
- VBScript
- Visual Studio Live Share
- Microsoft Authentication Library for Android
- Microsoft Defender
- Skype for Business and Lync
- Git for Visual Studio
Most of these vulnerabilities allow leakage information and privilege escalation on vulnerable systems. Others allow remote code execution attacks, while others lead to spoofing, denial of service attacks, and security.
Windows users should install the Microsoft Patch as soon as possible to avoid any breach or attack on their computer.
