

Rewterz Threat Advisory – CVE-2017-3623 – IBM AIX / Virtual I/O Server RPC Arbitrary Code Execution Vulnerability
December 17, 2018
Rewterz Threat Advisory – Phishing Attack faking an Office 365 Non-Delivery Email
December 18, 2018
Rewterz Threat Advisory – CVE-2017-3623 – IBM AIX / Virtual I/O Server RPC Arbitrary Code Execution Vulnerability
December 17, 2018
Rewterz Threat Advisory – Phishing Attack faking an Office 365 Non-Delivery Email
December 18, 2018Multiple vulnerabilities have been reported in Microsoft Windows Server 2016 and Microsoft Windows 10, which can be exploited by malicious, local users to disclose sensitive information, cause a DoS (Denial of Service), and gain escalated privileges.
IMPACT: High
PUBLISH DATE: 13th December 2018
OVERVIEW
Multiple vulnerabilities have been reported in Microsoft Windows Server 2016 and Microsoft Windows 10, which can be exploited by malicious, local users to disclose sensitive information, cause a DoS (Denial of Service), and gain escalated privileges and by malicious people to disclose sensitive information and compromise a vulnerable system.
ANALYSIS
CVE-2018-8595
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka “Windows GDI Information Disclosure Vulnerability.” This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
CVE-2018-8649
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka “Windows Denial of Service Vulnerability.” This affects Windows 10, Windows Server 2019.
CVE-2018-8477
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka “Windows Kernel Information Disclosure Vulnerability.” This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
CVE-2018-8641
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka “Win32k Elevation of Privilege Vulnerability.” This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
CVE-2018-8612
A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values, aka “Connected User Experiences and Telemetry Service Denial of Service Vulnerability.” This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers.
CVE-2018-8637
An information disclosure vulnerability exists in Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (KASLR) bypass, aka “Win32k Information Disclosure Vulnerability.” This affects Windows 10 Servers, Windows 10, Windows Server 2019.
CVE-2018-8638
An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka “DirectX Information Disclosure Vulnerability.” This affects Windows 10, Windows Server 2019.
CVE-2018-8611
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka “Windows Kernel Elevation of Privilege Vulnerability.” This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
CVE-2018-8639
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka “Win32k Elevation of Privilege Vulnerability.” This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
CVE-2018-8634
A remote code execution vulnerability exists in Windows where Microsoft text-to-speech fails to properly handle objects in the memory, aka “Microsoft Text-To-Speech Remote Code Execution Vulnerability.” This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers.
CVE-2018-8599
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file operations, aka “Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability.” This affects Microsoft Visual Studio, Windows Server 2019, Windows Server 2016, Windows 10, Windows 10 Servers.
CVE-2018-8514
An information disclosure vulnerability exists when Remote Procedure Call runtime improperly initializes objects in memory, aka “Remote Procedure Call runtime Information Disclosure Vulnerability.” This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
CVE-2018-8596
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka “Windows GDI Information Disclosure Vulnerability.” This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
CVE-2018-8626
A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they fail to properly handle requests, aka “Windows DNS Server Heap Overflow Vulnerability.” This affects Windows Server 2012 R2, Windows Server 2019, Windows Server 2016, Windows 10, Windows 10 Servers.
AFFECTED PRODUCTS
- Microsoft Windows 10
- Microsoft Windows Server 2016
MITIGATION
Apply update.
- Windows Server 2016 (KB4471321):
- Windows 10 Version 1607 for x64-based Systems (KB4471321):
- Windows Server 2016 (Server Core installation) (KB4471321):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471321
- Windows 10 Version 1607 for 32-bit Systems (KB4471321):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471321
- Windows 10 for x64-based Systems (KB4471323):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471323
- Windows 10 for 32-bit Systems (KB4471323):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471323
- Windows 10 Version 1703 for 32-bit Systems (KB4471327):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471327
- Windows 10 Version 1809 for ARM64-based Systems (KB4471332):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471332
- Windows 10 Version 1809 for x64-based Systems (KB4471332):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471332
- Windows 10 Version 1809 for 32-bit Systems (KB4471332):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471332
- Windows 10 Version 1709 for 32-bit Systems (KB4471329):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471329
- Windows 10 Version 1803 for 32-bit Systems (KB4471324):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471324
- Windows 10 Version 1709 for x64-based Systems (KB4471329):
- Windows Server, version 1709 (Server Core Installation) (KB4471329):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471329
- Windows 10 Version 1803 for x64-based Systems (KB4471324):
- Windows Server, version 1803 (Server Core Installation) (KB4471324):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471324
- Windows 10 Version 1803 for ARM64-based Systems (KB4471324):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471324
- Windows 10 Version 1709 for ARM64-based Systems (KB4471329):
https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4471329
If you think you’re the victim of a cyber-attack, immediately send an email to soc@rewterz.com.