Thursday, April 22, 2021
  • Setup menu at Appearance » Menus and assign menu to Top Bar Navigation
Advertisement
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
No Result
View All Result
Home Internet Privacy

Latest Microsoft Update Patches New Windows 0-Day Under Active Attack

December 11, 2019
in Internet Privacy
Latest Microsoft Update Patches New Windows 0-Day Under Active Attack
585
SHARES
3.3k
VIEWS
Share on FacebookShare on Twitter

With its latest and last Patch Tuesday for 2019, Microsoft is warning billions of its users of a new Windows zero-day vulnerability that attackers are actively exploiting in the wild in combination with a Chrome exploit to take remote control over vulnerable computers.

Microsoft’s December security updates include patches for a total of 36 vulnerabilities, where 7 are critical, 27 important, 1 moderate, and one is low in severity—brief information on which you can find later in this article.

You might also like

Improve Your Cyber Security Posture by Combining State of the Art Security Tools

Update Your Chrome Browser ASAP to Patch a Week Old Public Exploit

3 Zero-Day Exploits Hit SonicWall Enterprise Email Security Appliances

Tracked as CVE-2019-1458 and rated as Important, the newly patched zero-day Win32k privilege escalation vulnerability, reported by Kaspersky, was used in Operation WizardOpium attacks to gain higher privileges on targeted systems by escaping the Chrome sandbox.

Although Google addressed the flaw in Chrome 78.0.3904.87 with the release of an emergency update last month after Kaspersky disclosed it to the tech giant, hackers are still targeting users who are using vulnerable versions of the browser.

As The Hacker News reported last month, Operation WizardOpium involved a compromised Korean-language news portal where attackers secretly planted a then-zero-day Chrome exploit to hack computers of its visitors.

According to Kaspersky researchers, the Chrome use-after-free exploit was chained together with the newly patched EoP flaw that exists in the way the Win32k component in Windows OS handles objects in memory.

Chrome use-after-free exploit

The EoP exploit works on “the latest versions of Windows 7 and even on a few builds of Windows 10” and, if successfully exploited, could allow an attacker to run arbitrary code in kernel mode.

While the researchers were not able to attribute the Operation WizardOpium attacks to any specific group of hackers, they found some similarities in the exploit code with the infamous Lazarus hacking group.

Microsoft Patch Tuesday: December 2019

The 7 critical security vulnerabilities Microsoft patched this month affect Git for Visual Studio, Hyper-V Hypervisor, and Win32k Graphics component of Windows, successful exploitation of all lead to remote code execution attacks.

The Windows Hyper-V vulnerability (CVE-2019-1471) enables a guest virtual machine to compromise the hypervisor, escaping from a guest virtual machine to the host, or escaping from one guest virtual machine to another guest virtual machine.

Git for Visual Studio contains five critical remote code execution vulnerabilities—all reside due to the way Git for Visual Studio sanitizes input—successful exploitation of which requires attackers to convince a targeted user to clone a malicious repo.

Web Application Firewall

Another notable vulnerability, tracked as CVE-2019-1462 and rated as important, resides in the PowerPoint software that can be exploited to run arbitrary code on a targeted computer by merely convincing the victim into opening a specially crafted presentation file.

This vulnerability affects Microsoft PowerPoint 2010, 2013, and 2016 as well as Microsoft Office 2016 and 2019 for Windows and Apple’s macOS operating systems.

Other vulnerabilities patched by Microsoft this month and marked as important reside in the following Microsoft products and services:

  • Windows Operating System
  • Windows Kernel
  • Windows Remote Desktop Protocol (RDP)
  • Microsoft Word
  • Microsoft Excel
  • Microsoft SQL Server Reporting Services
  • Microsoft Access software
  • Windows GDI component
  • Win32k
  • Windows Hyper-V
  • Windows Printer Service
  • Windows COM Server
  • Windows Media Player
  • Windows OLE
  • VBScript
  • Visual Studio Live Share
  • Microsoft Authentication Library for Android
  • Microsoft Defender
  • Skype for Business and Lync
  • Git for Visual Studio

Most of these vulnerabilities allow information disclosure and elevation of privilege, and some also lead to remote code execution attacks, while others allow cross-site scripting (XSS), security feature bypass, spoofing, tampering, and denial of service attacks.

Windows users and system administrators are highly advised to apply the latest security patches as soon as possible in an attempt to keep cybercriminals and hackers away from taking control of their computers.

For installing the latest Windows security updates, you can head on to Settings → Update & Security → Windows Update → Check for updates on your PC, or you can install the updates manually.


Credit: The Hacker News By: noreply@blogger.com (Swati Khandelwal)

Previous Post

Figure Technologies closes $103 million series C round to boost blockchain for lending mission

Next Post

TrickBot gang is now a malware supplier for North Korean hackers

Related Posts

Improve Your Cyber Security Posture by Combining State of the Art Security Tools
Internet Privacy

Improve Your Cyber Security Posture by Combining State of the Art Security Tools

April 21, 2021
Update Your Chrome Browser ASAP to Patch a Week Old Public Exploit
Internet Privacy

Update Your Chrome Browser ASAP to Patch a Week Old Public Exploit

April 21, 2021
3 Zero-Day Exploits Hit SonicWall Enterprise Email Security Appliances
Internet Privacy

3 Zero-Day Exploits Hit SonicWall Enterprise Email Security Appliances

April 21, 2021
120 Compromised Ad Servers Target Millions of Internet Users
Internet Privacy

120 Compromised Ad Servers Target Millions of Internet Users

April 21, 2021
Over 750,000 Users Downloaded New Billing Fraud Apps From Google Play Store
Internet Privacy

Over 750,000 Users Downloaded New Billing Fraud Apps From Google Play Store

April 21, 2021
Next Post
TrickBot gang is now a malware supplier for North Korean hackers

TrickBot gang is now a malware supplier for North Korean hackers

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

January 6, 2019
Microsoft, Google Use Artificial Intelligence to Fight Hackers

Microsoft, Google Use Artificial Intelligence to Fight Hackers

January 6, 2019

Categories

  • Artificial Intelligence
  • Big Data
  • Blockchain
  • Crypto News
  • Data Science
  • Digital Marketing
  • Internet Privacy
  • Internet Security
  • Learn to Code
  • Machine Learning
  • Marketing Technology
  • Neural Networks
  • Technology Companies

Don't miss it

Top Python Operator – Data Science Central
Data Science

Top Python Operator – Data Science Central

April 22, 2021
Machine Learning Tacks Evolution of COVID-19 Misinformation
Machine Learning

Machine Learning Tacks Evolution of COVID-19 Misinformation

April 22, 2021
How AI Is Disruptive Innovation For OCR | by Infrrd | Apr, 2021
Neural Networks

How AI Is Disruptive Innovation For OCR | by Infrrd | Apr, 2021

April 22, 2021
Instagram debuts new tool to stop abusive message salvos made through new accounts
Internet Security

Instagram debuts new tool to stop abusive message salvos made through new accounts

April 21, 2021
Improve Your Cyber Security Posture by Combining State of the Art Security Tools
Internet Privacy

Improve Your Cyber Security Posture by Combining State of the Art Security Tools

April 21, 2021
6 Ways AI is Changing The Learning And Development Landscape
Data Science

6 Ways AI is Changing The Learning And Development Landscape

April 21, 2021
NikolaNews

NikolaNews.com is an online News Portal which aims to share news about blockchain, AI, Big Data, and Data Privacy and more!

What’s New Here?

  • Top Python Operator – Data Science Central April 22, 2021
  • Machine Learning Tacks Evolution of COVID-19 Misinformation April 22, 2021
  • How AI Is Disruptive Innovation For OCR | by Infrrd | Apr, 2021 April 22, 2021
  • Instagram debuts new tool to stop abusive message salvos made through new accounts April 21, 2021

Subscribe to get more!

© 2019 NikolaNews.com - Global Tech Updates

No Result
View All Result
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News

© 2019 NikolaNews.com - Global Tech Updates