Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

3/23/2020
05:40 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Microsoft Publishes Advisory for Windows Zero-Day

There is no available patch for the vulnerabilities, which Microsoft says exist in all supported versions of Windows.

Microsoft today posted an advisory to inform users of active attacks targeting unpatched flaws in Adobe Type Manager Library. The vulnerabilities affect all supported versions of Windows.

Two remote code execution vulnerabilities exist in Microsoft Windows when the Adobe Type Manager Library improperly handles a specially crafted multimaster font called Adobe Type 1 PostScript format, Microsoft explains in the advisory. The company is aware of "limited targeted attacks" that could leverage the unpatched vulnerabilities, which the company ranked as Critical.

There are several ways an attacker could successfully take advantage of these flaws. For example, they could convince a user to open a specially crafted document or view it in the Windows Preview pane. Opening or viewing the file would let the attacker remotely run malicious code on the target machine. While the Windows Preview pane could be an attack vector, Microsoft says Outlook Preview Pane is not an attack vector for these vulnerabilities.

"For systems running supported versions of Windows 10, a successful attack could only result in code execution within an AppContainer sandbox context with limited privileges and capabilities," officials explain of the potential effects on supported Windows 10 machines.

Microsoft is working on a fix for the vulnerabilities. The company usually releases patches on the second Tuesday of each month, a schedule it says allows for both quality assurance and IT planning. It has been known to issue out-of-band patches for urgent vulnerabilities as needed. Microsoft did not provide details on when a patch for these vulnerabilities will be released. 

In the meantime, its advisory offers workarounds for companies vulnerable to these attacks. For example, admins can disable the Preview and Details panes in Windows Explorer to prevent the automatic display of OTF fonts in Windows Explorer. This prevents malicious files from being views in Windows Explorer, Microsoft says, but it does not block a local authenticated user from running a specially crafted program to exploit the flaw.

Another workaround involves disabling the WebClient service, which helps protect against potential exploits by blocking the most likely remote attack vector via the Web Distributed Authoring and Versioning (WebDAV) client service. With this workaround, it would still be possible for attackers to cause the system to run programs on the target machine or local area network; however, users will be asked for confirmation before opening malicious programs.

Microsoft provides guidance for completing these workarounds and others, as well as how to undo them, for different affected versions of Windows in its advisory on the vulnerabilities.

To protect against the attacks that exploit these flaws, Synopsys senior security strategist Jonathan Knudsen emphasizes the importance of not clicking links or attachments in unexpected emails:

"You should never, ever, ever click on links in emails or open documents whose origin is uncertain," he says. "The attack that exploits this vulnerability depends on tricking users into opening specially crafted malicious documents. Every time you are tempted to click a link or open an attachment, take a moment and think about what you're doing."

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's featured story: "Security Lessons We've Learned (So Far) from COVID-19."

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
HackerOne Drops Mobile Voting App Vendor Voatz
Dark Reading Staff 3/30/2020
Limited-Time Free Offers to Secure the Enterprise Amid COVID-19
Curtis Franklin Jr., Senior Editor at Dark Reading,  3/31/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-8004
PUBLISHED: 2020-04-06
STMicroelectronics STM32F1 devices have Incorrect Access Control.
CVE-2020-7631
PUBLISHED: 2020-04-06
diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path argument.
CVE-2020-7632
PUBLISHED: 2020-04-06
node-mpv through 1.4.3 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.
CVE-2020-7633
PUBLISHED: 2020-04-06
apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri argument.
CVE-2020-7634
PUBLISHED: 2020-04-06
heroku-addonpool through 0.1.15 is vulnerable to Command Injection.