UPDATED 19:25 EDT / FEBRUARY 13 2018

INFRA

Update now: Microsoft flags serious Outlook flaws in ‘Patch Tuesday’ release

Microsoft Corp. has issued 50 security fixes covering vulnerabilities in Windows, Internet Explorer, Flash for IE, Edge, Office, SharePoint and ChakraCore as part of its monthly “Patch Tuesday” release today, with two critical Outlook flaws leading the pack.

The Outlook vulnerabilities (CVE-2018-0852) patched in the release allowed an attacker to execute malicious code remotely. Worse, should a targeted machine be operated in administrative mode, an attacker could use the vulnerabilities to gain control of the entire system.

Other patches include a fix for CVE-2018-0771, a security feature bypass vulnerability in the Edge web browser that could allow an attacker to host a specially crafted website designed to exploit the vulnerability.

Discussing the release, Chris Goettl, director of product management for security at Ivanti Inc. told SiliconANGLE that other standouts include CVE-2018-0825, a vulnerability in StructuredQuery that could allow Remote Code Execution.

“This is a user-targeted attack scenario that could allow the attacker to craft a file that could be used in an email or web-based attack,” Goettl explained. “This vulnerability is in the OS, though, so all systems are potentially vulnerable. The vulnerability can also be exploited through the Preview Pane, which makes this one a bit more threatening than some of the similar Office-based vulnerabilities this month.”

Goettl said that Microsoft has resolved six office vulnerabilities this month, including several that could allow remote code execution.

“These vulnerabilities could be exploited through a hosted website, via an attachment in email, etc.,” he said. “The attacker would gain equal rights as the current user, so if the user is a full administrator, the attacker would gain full control of the system. This is a good example of why privilege management is so important. It is hard to take admin rights back from a user once granted, but there are other methods to take away specific capabilities to take some of the risk out of that full administrator user as well.”

Also bundled with the release was a range of patches for Adobe Flash, which Jimmy Graham, director of product management at Qualys Inc. said need to be a priority installation.

“Adobe has released several patches, including some from last week covering Flash, Reader, Acrobat, and Adobe Experience Manager,” Graham said. “The Reader and Acrobat patches cover a whopping 41 vulnerabilities, while the Flash and Experience Manager patches each cover two. There are active exploits against the Flash vulnerabilities and should be patched immediately, followed quickly by the Reader and Acrobat patches.”

Photo: ktylerconk/Flickr

A message from John Furrier, co-founder of SiliconANGLE:

Support our open free content by sharing and engaging with our content and community.

Join theCUBE Alumni Trust Network

Where Technology Leaders Connect, Share Intelligence & Create Opportunities

11.4k+  
CUBE Alumni Network
C-level and Technical
Domain Experts
15M+ 
theCUBE
Viewers
Connect with 11,413+ industry leaders from our network of tech and business leaders forming a unique trusted network effect.

SiliconANGLE Media is a recognized leader in digital media innovation serving innovative audiences and brands, bringing together cutting-edge technology, influential content, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — such as those established in Silicon Valley and the New York Stock Exchange (NYSE) — SiliconANGLE Media operates at the intersection of media, technology, and AI. .

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a powerful ecosystem of industry-leading digital media brands, with a reach of 15+ million elite tech professionals. The company’s new, proprietary theCUBE AI Video cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.