This month’s Patch Tuesday addresses 62 vulnerabilities, with 12 of them labeled as Critical. Out of the Criticals, 8 are for the Chakra Scripting Engine used by Microsoft Edge. A Remote Code Execution vulnerability in Windows Deployment Services’ TFTP server is also addressed in this release. Adobe also patched three Important vulnerabilities this month, although there is a PoC exploit available for Adobe Acrobat and Reader.
Workstation Patches
Browser and Scripting Engine patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users. Out of the 12 Critical vulnerabilities, 10 can be exploited through browsers or opening malicious files.
Windows Deployment Services TFTP Server RCE
Microsoft’s Windows Deployment Services uses TFTP to support image deployment via PXE booting. A flaw was discovered in the TFTP server that allows Remote Code Execution on an affected device. The patch for CVE-2018-8476 should be prioritized if WDS is used in your environment.
Microsoft Dynamics 365 RCE
Web requests are not properly sanitized in version 8 of Microsoft Dynamics 365 on-prem. This vulnerability could lead to remote code execution in the context of the SQL user. Any on-prem deployments of Dynamics 365 should have CVE-2018-8609 prioritized.
Active Attacks on Win32k Privilege Escalation
Microsoft has reported that there are active attacks detected against CVE-2018-8589. The vulnerability impacts Windows 7 and Server 2008 and 2008 R2. Microsoft has ranked this patch as Important.
BitLocker
Last week, Microsoft released an advisory on using software encryption rather than hardware, which has recently been shown to be ineffective in certain implementations. In addition, an unrelated patch for BitLocker (CVE-2018-8566) was issued today. This vulnerability allows an attacker to access encrypted data if they have physical access to the system. Microsoft has ranked this patch as Important.
Adobe Patches, NTLM hash leaking, mitigations
Adobe released three patches for Flash, Acrobat/Reader, and Photoshop, all labeled Important. The vulnerability in Acrobat and Reader has publicly available PoC code and should be installed as soon as possible. This flaw can lead to the leaking of the user’s NTLM hash, which could be brute-forced to determine the user’s password. Adobe has also released a document discussing mitigations for this vulnerability, which includes enabling a feature in Windows 10 that would prevent this style of attack, by stopping NTLM SSO from being used by external resources.
Executive Summary
- Microsoft released security updates for all supported versions of Windows.
- Security updates are also available for Internet Explorer, Microsoft Edge, and other company products
- Microsoft released Windows Server 2019 today.
- The Windows 10 October 2018 Update is available again.
- Microsoft promises to do better patch-wise.
Operating System Distribution
- Windows 7: 13 vulnerabilities of which 2 are critical and 11 are important.
- Windows 8.1: 16 vulnerabilities of which 2 are critical and 14 are important.
- Windows 10 version 1607: 18 vulnerabilities of which 2 are critical and 16 are important
- Windows 10 version 1703: 16 vulnerabilities of which 1 is critical and 15 are important
- Windows 10 version 1709: 18 vulnerabilities of which 1 is critical and 17 are important
- Windows 10 version 1803: 17 vulnerabilities of which 1 is critical and 16 are important
- Windows 10 version 1809: 17 vulnerabilities of which 1 is critical and 16 are important
Windows Server products
- Windows Server 2008 R2: 13 vulnerabilities of which 3 are critical and 10 are important.
- Windows Server 2012 R2: 16 vulnerabilities of which 3 are critical and 13 are important.
- Windows Server 2016: 19 vulnerabilities of which 3 are critical and 16 are important.
- Windows Server 2019: 18 vulnerabilities of which 2 are critical and 16 are important.
Other Microsoft Products
- Internet Explorer 11: 1 vulnerability, important
- Microsoft Edge: 2 vulnerabilities, 2 critical
Known Issues
Windows 10 version 1809
- Some Win32 programs cannot be set as the default file openers under Open With or Settings > Apps > Default Apps.
Windows 10 version 1803
- Some Win32 programs cannot be set as the default file openers under Open With or Settings > Apps > Default Apps.
- Instantiation of SqlConnection can throw exceptions.
Windows 10 version 1709
- Instantiation of SqlConnection can throw exceptions.
Windows 10 version 1703
- Instantiation of SqlConnection can throw exceptions.
Windows 10 version 1607 and Windows Server 2016
- Installation and client activation of Windows Server 2019 and 1809 LTSC Key Management Service (KMS) (CSVLK) host keys do not work as expected.
- Error “The replication operation encountered a database error” after installation of the update.
- Instantiation of SqlConnection can throw exceptions.
Windows 7
Network Interface Controller may stop working. Microsoft’s solution is to update drivers.
Direct update downloads
All cumulative updates for supported versions of Windows are also provided as direct downloads from Microsoft’s Download Center site.
Windows 7 SP1 and Windows Server 2008 R2 SP
- KB4467107 — 2018-11 Security Monthly Quality Rollup for Windows 7
- KB4467106 — 2018-11 Security Only Quality Update for Windows 7
Windows 8.1 and Windows Server 2012 R2
- KB4467697— 2018-11 Security Monthly Quality Rollup for Windows 8.1
- KB4467703 — 2018-11 Security Only Quality Update for Windows 8.1
Windows 10 and Windows Server 2016 (version 1607)
- KB4467691 — 2018-11 Cumulative Update for Windows 10 Version 1607
Windows 10 (version 1703)
- KB4467696 — 2018-11 Cumulative Update for Windows 10 Version 1703
Windows 10 (version 1709)
- KB4467686 — 2018-11 Cumulative Update for Windows 10 Version 1709
Windows 10 (version 1803)
- KB4467702 — 2018-11 Cumulative Update for Windows 10 Version 1803
Windows 10 (version 1809)
- KB4467708 — 2018-11 Cumulative Update for Windows 10 Version 1809