Microsoft's January 2019 Patch Fixes 51 Security Vulnerabilities Threat Alert
Total Page:16
File Type:pdf, Size:1020Kb
Microsoft's January 2019 Patch Fixes 51 Security Vulnerabilities Threat Alert Overview Microsoft released the January 2019 security patch on Tuesday that fixes 51 vulnerabilities ranging from simple spoofing attacks to remote code execution in various products, including .NET Framework, Adobe Flash Player, Android App, ASP.NET, Internet Explorer, Microsoft Edge, Microsoft Exchange Server, Microsoft JET Database Engine, Microsoft Office, Microsoft Office SharePoint, Microsoft Scripting Engine, Microsoft Windows, Microsoft XML, Servicing Stack Updates, Visual Studio, Windows COM, Windows DHCP Client, Windows Hyper-V, Windows Kernel, and Windows Subsystem for Linux. Details can be found in the following table. Product CVE ID CVE Title Severity Level .NET Framework .NET Framework CVE-2019-0545 Information Disclosure Important Vulnerability © NSFOCUS 2018 https://www.nsfocusglobal.com Adobe Flash Player ADV190001 January 2019 Adobe Flash Update Unknown Skype for Android Privilege Android App CVE-2019-0622 Moderate Escalation Vulnerability ASP.NET Core Denial-of-Service ASP.NET CVE-2019-0548 Important Vulnerability ASP.NET Core Denial-of-Service ASP.NET CVE-2019-0564 Important Vulnerability MSHTML Engine Remote Code Internet Explorer CVE-2019-0541 Important Execution Vulnerability Microsoft Edge Memory Microsoft Edge CVE-2019-0565 Critical Corruption Vulnerability Microsoft Edge Privilege Microsoft Edge CVE-2019-0566 Important Escalation Vulnerability Microsoft Exchange Memory Microsoft Exchange Server CVE-2019-0586 Important Corruption Vulnerability © NSFOCUS 2018 https://www.nsfocusglobal.com Microsoft Exchange Microsoft Exchange Server CVE-2019-0588 Information Disclosure Important Vulnerability Jet Database Engine Remote Code Microsoft JET Database Engine CVE-2019-0538 Important Execution Vulnerability Jet Database Engine Remote Code Microsoft JET Database Engine CVE-2019-0575 Important Execution Vulnerability Jet Database Engine Remote Code Microsoft JET Database Engine CVE-2019-0576 Important Execution Vulnerability Jet Database Engine Remote Code Microsoft JET Database Engine CVE-2019-0577 Important Execution Vulnerability Jet Database Engine Remote Code Microsoft JET Database Engine CVE-2019-0578 Important Execution Vulnerability Jet Database Engine Remote Code Microsoft JET Database Engine CVE-2019-0579 Important Execution Vulnerability © NSFOCUS 2018 https://www.nsfocusglobal.com Jet Database Engine Remote Code Microsoft JET Database Engine CVE-2019-0580 Important Execution Vulnerability Jet Database Engine Remote Code Microsoft JET Database Engine CVE-2019-0581 Important Execution Vulnerability Jet Database Engine Remote Code Microsoft JET Database Engine CVE-2019-0582 Important Execution Vulnerability Jet Database Engine Remote Code Microsoft JET Database Engine CVE-2019-0583 Important Execution Vulnerability Jet Database Engine Remote Code Microsoft JET Database Engine CVE-2019-0584 Important Execution Vulnerability Microsoft Word Remote Code Microsoft Office CVE-2019-0585 Important Execution Vulnerability Microsoft Outlook Microsoft Office CVE-2019-0559 Information Disclosure Important Vulnerability © NSFOCUS 2018 https://www.nsfocusglobal.com Microsoft Office Microsoft Office CVE-2019-0560 Information Disclosure Important Vulnerability Microsoft Word Microsoft Office CVE-2019-0561 Information Disclosure Important Vulnerability Microsoft Office SharePoint XSS Microsoft Office SharePoint CVE-2019-0556 Important Vulnerability Microsoft Office SharePoint XSS Microsoft Office SharePoint CVE-2019-0557 Important Vulnerability Microsoft Office SharePoint XSS Microsoft Office SharePoint CVE-2019-0558 Important Vulnerability Microsoft SharePoint Privilege Microsoft Office SharePoint CVE-2019-0562 Important Escalation Vulnerability Chakra Scripting Engine Memory Microsoft Scripting Engine CVE-2019-0539 Critical Corruption Vulnerability © NSFOCUS 2018 https://www.nsfocusglobal.com Chakra Scripting Engine Memory Microsoft Scripting Engine CVE-2019-0567 Critical Corruption Vulnerability Chakra Scripting Engine Memory Microsoft Scripting Engine CVE-2019-0568 Critical Corruption Vulnerability Microsoft Windows Privilege Microsoft Windows CVE-2019-0543 Important Escalation Vulnerability Windows Runtime Privilege Microsoft Windows CVE-2019-0570 Important Escalation Vulnerability Windows Data Sharing Service Microsoft Windows CVE-2019-0571 Important Privilege Escalation Vulnerability Windows Data Sharing Service Microsoft Windows CVE-2019-0572 Important Privilege Escalation Vulnerability Windows Data Sharing Service Microsoft Windows CVE-2019-0573 Important Privilege Escalation Vulnerability © NSFOCUS 2018 https://www.nsfocusglobal.com Windows Data Sharing Service Microsoft Windows CVE-2019-0574 Important Privilege Escalation Vulnerability Microsoft XmlDocument Privilege Microsoft XML CVE-2019-0555 Important Escalation Vulnerability Servicing Stack Updates ADV990001 Latest Servicing Stack Updates Critical Microsoft Visual Studio Visual Studio CVE-2019-0537 Information Disclosure Important Vulnerability Visual Studio Remote Code Visual Studio CVE-2019-0546 Moderate Execution Vulnerability Windows COM Privilege Windows COM CVE-2019-0552 Important Escalation Vulnerability Windows DHCP Client Remote Windows DHCP Client CVE-2019-0547 Critical Code Execution Vulnerability © NSFOCUS 2018 https://www.nsfocusglobal.com Windows Hyper-V Remote Code Windows Hyper-V CVE-2019-0550 Critical Execution Vulnerability Windows Hyper-V Remote Code Windows Hyper-V CVE-2019-0551 Critical Execution Vulnerability Windows Kernel Windows Kernel CVE-2019-0536 Information Disclosure Important Vulnerability Windows Kernel Windows Kernel CVE-2019-0549 Information Disclosure Important Vulnerability Windows Kernel Windows Kernel CVE-2019-0554 Information Disclosure Important Vulnerability Windows Kernel Windows Kernel CVE-2019-0569 Information Disclosure Important Vulnerability © NSFOCUS 2018 https://www.nsfocusglobal.com Windows Subsystem for Linux Windows Subsystem for Linux CVE-2019-0553 Information Disclosure Important Vulnerability Recommended Mitigation Measure Microsoft has released the January 2019 security patch to fix these issues. Please install the patch as soon as possible. Appendix ADV190001 - January 2019 Adobe Flash Update Maximum Vulnerability CVE ID Vulnerability Description Severity Rating Impact ADV190001 CVE Title: January 2019 Adobe Flash Update MITRE Unknown Unknown Description: NVD © NSFOCUS 2018 https://www.nsfocusglobal.com Maximum Vulnerability CVE ID Vulnerability Description Severity Rating Impact This update does not address any security vulnerabilities. For more information, please see APSB19-01. Note: Please disregard mentions of security or vulnerability in this advisory. These are hardcoded titles that we were unable to change for this non-security Adobe Flash update. FAQ: None Mitigations: None Workarounds: None Revision: 1.0 01/08/2019 08:00:00 Information published. Affected Software The following tables list the affected software details for the vulnerability. © NSFOCUS 2018 https://www.nsfocusglobal.com ADV190001 CVSS Score Restart Product KB Article Severity Impact Supersedence Set Required Base: N/A 4480979 Temporal: Adobe Flash Player on Windows Server 2012 Update 4471331 Yes N/A Vector: N/A Base: N/A 4480979 Temporal: Adobe Flash Player on Windows 8.1 for 32-bit systems Update 4471331 Yes N/A Vector: N/A Base: N/A 4480979 Adobe Flash Player on Windows 8.1 for x64-based Temporal: Update 4471331 Yes systems N/A Vector: N/A Base: N/A 4480979 Temporal: Adobe Flash Player on Windows Server 2012 R2 Update 4471331 Yes N/A Vector: N/A Base: N/A 4480979 Temporal: Adobe Flash Player on Windows RT 8.1 Update 4471331 Yes N/A Vector: N/A © NSFOCUS 2018 https://www.nsfocusglobal.com ADV190001 Base: N/A 4480979 Temporal: Adobe Flash Player on Windows 10 for 32-bit Systems Update 4471331 Yes N/A Vector: N/A Base: N/A 4480979 Adobe Flash Player on Windows 10 for x64-based Temporal: Update 4471331 Yes Systems N/A Vector: N/A Base: N/A 4480979 Temporal: Adobe Flash Player on Windows Server 2016 Update 4471331 Yes N/A Vector: N/A Base: N/A 4480979 Adobe Flash Player on Windows 10 Version 1607 for 32- Temporal: Update 4471331 Yes bit Systems N/A Vector: N/A Base: N/A 4480979 Adobe Flash Player on Windows 10 Version 1607 for Temporal: Update 4471331 Yes x64-based Systems N/A Vector: N/A 4480979 Adobe Flash Player on Windows 10 Version 1703 for 32- Base: N/A Update 4471331 Yes bit Systems Temporal: © NSFOCUS 2018 https://www.nsfocusglobal.com ADV190001 N/A Vector: N/A Base: N/A 4480979 Adobe Flash Player on Windows 10 Version 1703 for Temporal: Update 4471331 Yes x64-based Systems N/A Vector: N/A Base: N/A 4480979 Adobe Flash Player on Windows 10 Version 1709 for 32- Temporal: Update 4471331 Yes bit Systems N/A Vector: N/A Base: N/A 4480979 Adobe Flash Player on Windows 10 Version 1709 for Temporal: Update 4471331 Yes x64-based Systems N/A Vector: N/A Base: N/A 4480979 Adobe Flash Player on Windows 10 Version 1803 for 32- Temporal: Update 4471331 Yes bit Systems N/A Vector: N/A Base: N/A 4480979 Adobe Flash Player on Windows 10 Version 1803 for Temporal: Update 4471331 Yes x64-based Systems N/A Vector: N/A © NSFOCUS 2018 https://www.nsfocusglobal.com ADV190001 Base: N/A 4480979 Adobe Flash Player on Windows 10 Version 1803 for Temporal: Update 4471331 Yes ARM64-based Systems N/A Vector: N/A Base: N/A 4480979 Adobe Flash Player on Windows 10 Version 1809 for 32- Temporal: Update 4471331 Yes bit Systems N/A Vector: N/A Base: N/A 4480979 Adobe