Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

3/23/2020
05:40 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Microsoft Publishes Advisory for Windows Zero-Day

There is no available patch for the vulnerabilities, which Microsoft says exist in all supported versions of Windows.

Microsoft today posted an advisory to inform users of active attacks targeting unpatched flaws in Adobe Type Manager Library. The vulnerabilities affect all supported versions of Windows.

Two remote code execution vulnerabilities exist in Microsoft Windows when the Adobe Type Manager Library improperly handles a specially crafted multimaster font called Adobe Type 1 PostScript format, Microsoft explains in the advisory. The company is aware of "limited targeted attacks" that could leverage the unpatched vulnerabilities, which the company ranked as Critical.

There are several ways an attacker could successfully take advantage of these flaws. For example, they could convince a user to open a specially crafted document or view it in the Windows Preview pane. Opening or viewing the file would let the attacker remotely run malicious code on the target machine. While the Windows Preview pane could be an attack vector, Microsoft says Outlook Preview Pane is not an attack vector for these vulnerabilities.

"For systems running supported versions of Windows 10, a successful attack could only result in code execution within an AppContainer sandbox context with limited privileges and capabilities," officials explain of the potential effects on supported Windows 10 machines.

Microsoft is working on a fix for the vulnerabilities. The company usually releases patches on the second Tuesday of each month, a schedule it says allows for both quality assurance and IT planning. It has been known to issue out-of-band patches for urgent vulnerabilities as needed. Microsoft did not provide details on when a patch for these vulnerabilities will be released. 

In the meantime, its advisory offers workarounds for companies vulnerable to these attacks. For example, admins can disable the Preview and Details panes in Windows Explorer to prevent the automatic display of OTF fonts in Windows Explorer. This prevents malicious files from being views in Windows Explorer, Microsoft says, but it does not block a local authenticated user from running a specially crafted program to exploit the flaw.

Another workaround involves disabling the WebClient service, which helps protect against potential exploits by blocking the most likely remote attack vector via the Web Distributed Authoring and Versioning (WebDAV) client service. With this workaround, it would still be possible for attackers to cause the system to run programs on the target machine or local area network; however, users will be asked for confirmation before opening malicious programs.

Microsoft provides guidance for completing these workarounds and others, as well as how to undo them, for different affected versions of Windows in its advisory on the vulnerabilities.

To protect against the attacks that exploit these flaws, Synopsys senior security strategist Jonathan Knudsen emphasizes the importance of not clicking links or attachments in unexpected emails:

"You should never, ever, ever click on links in emails or open documents whose origin is uncertain," he says. "The attack that exploits this vulnerability depends on tricking users into opening specially crafted malicious documents. Every time you are tempted to click a link or open an attachment, take a moment and think about what you're doing."

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's featured story: "Security Lessons We've Learned (So Far) from COVID-19."

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 4/7/2020
The Coronavirus & Cybersecurity: 3 Areas of Exploitation
Robert R. Ackerman Jr., Founder & Managing Director, Allegis Capital,  4/7/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-21038
PUBLISHED: 2020-04-08
An issue was discovered on Samsung mobile devices with N(7.x) software. The Secure Folder app's startup logic allows authentication bypass. The Samsung ID is SVE-2018-11628 (December 2018).
CVE-2018-21039
PUBLISHED: 2020-04-08
An issue was discovered on Samsung mobile devices with N(7.0) software. With the Location permission for the compass feature in Quick Tools (aka QuickTools), an attacker can bypass the lockscreen. The Samsung ID is SVE-2018-12053 (December 2018).
CVE-2018-21040
PUBLISHED: 2020-04-08
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 9810 chipsets) software. There is a race condition with a resultant use-after-free in the g2d driver. The Samsung ID is SVE-2018-12959 (December 2018).
CVE-2018-21041
PUBLISHED: 2020-04-08
An issue was discovered on Samsung mobile devices with O(8.x) software. Access to Gallery in the Secure Folder can occur without authentication. The Samsung ID is SVE-2018-13057 (December 2018).
CVE-2020-11000
PUBLISHED: 2020-04-08
GreenBrowser before version 1.2 has a vulnerability where apps that rely on URL Parsing to verify that a given URL is pointing to a trust server may be susceptible to many different ways to get URL parsing and verification wrong, which allows an attacker to circumvent the access control. This proble...