• Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Transform
      • SOC Consultancy
      •     SOC Maturity Assessment
      •     SOC Model Evaluation
      •     SOC Gap Analysis
      •     SIEM Gap Analysis
      •     SIEM Optimization
      •     SOC Content Pack
    • Train
      • Security Awareness and Training
      • Tabletop Exercise
      • Simulated Cyber Attack Exercises
    • Respond
      • Incident Response
      • Incident Analysis
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
Rewterz Threat Advisory – CVE-2019-0541 – Microsoft Internet Explorer MSHTML Engine Code Execution Vulnerability
January 10, 2019
Rewterz Threat Advisory – Microsoft Exchange Server 2010 / 2013 / 2016 / 2019 Multiple Vulnerabilities
January 10, 2019

Rewterz Threat Advisory – Microsoft Windows Server 2008 / Windows 7 Multiple Vulnerabilities

January 10, 2019

SEVERITY: Medium

 

 

ANALYSIS SUMMARY

 

 

Multiple vulnerabilities have been reported in Microsoft Windows Server 2008 and Microsoft Windows 7, which can be exploited by malicious, local users to disclose sensitive information and gain escalated privileges and by malicious people to compromise a vulnerable system.

CVE-2019-0583
CVE-2019-0538
CVE-2019-0578
CVE-2019-0579
CVE-2019-0575
CVE-2019-0577
CVE-2019-0576
CVE-2019-0582
CVE-2019-0584
CVE-2019-0581
CVE-2019-0580
Each of these is a separate remote code execution vulnerability that exists when the Windows Jet Database Engine
improperly handles objects in memory.

 

CVE-2019-0543
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests.

 

CVE-2019-0536
CVE-2019-0549
CVE-2019-0569
CVE-2019-0554
Each of these is a separate Information Disclosure vulnerability that exists when the Windows kernel improperly handles objects in memory.

 

 

IMPACT

 

 

System access
Remote code execution
Privilege escalation
Exposure of sensitive information

 

 

AFFECTED PRODUCTS

 

 

Microsoft Windows Server 2008
Microsoft Windows 7

 

 

REMEDIATION

 

 

Vendor has released updates for the following products:

  • Windows 7 for 32-bit Systems Service Pack 1 (KB4480960):
    https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4480960

 

  • Windows 7 for 32-bit Systems Service Pack 1 (KB4480970):
    https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4480970

 

  • Windows Server 2008 for Itanium-Based Systems Service Pack 2 (KB4480957):
    https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4480957
  • Windows Server 2008 for x64-based Systems Service Pack 2 (KB4480957):
  • Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) (KB4480957):
    https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4480957

 

  • Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) (KB4480957):
  • Windows Server 2008 for 32-bit Systems Service Pack 2 (KB4480957):
    https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4480957

 

  • Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1 (KB4480960):
    https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4480960

 

  • Windows 7 for x64-based Systems Service Pack 1 (KB4480960):
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) (KB4480960):
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1 (KB4480960):
    https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4480960

 

  • Windows Server 2008 for Itanium-Based Systems Service Pack 2 (KB4480968):
    https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4480968

 

  • Windows Server 2008 for x64-based Systems Service Pack 2 (KB4480968):
  • Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) (KB4480968):
    https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4480968

 

  • Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) (KB4480968):
  • Windows Server 2008 for 32-bit Systems Service Pack 2 (KB4480968):
    https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4480968

 

  • Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1 (KB4480970):
    https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4480970

 

  • Windows 7 for x64-based Systems Service Pack 1 (KB4480970):
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) (KB4480970):
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1 (KB4480970):
    https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4480970

 

  • Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) (KB955430):
  • Windows Server 2008 for 32-bit Systems Service Pack 2 (KB955430):
    https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB955430
  • Windows Server 2008 for Itanium-Based Systems Service Pack 2 (KB955430):
    https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB955430

 

  • Windows Server 2008 for x64-based Systems Service Pack 2 (KB955430):
  • Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) (KB955430):
    https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB955430

 

  • Windows 7 for x64-based Systems Service Pack 1 (KB3177467):
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) (KB3177467):
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1 (KB3177467):
    https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB3177467

 

  • Windows 7 for 32-bit Systems Service Pack 1 (KB3177467):
    https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB3177467

 

  • Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1 (KB3177467):
    https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB3177467
  • Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Respond
      • Incident Response
      • Incident Analysis
  • Transform
    • SOC Consultancy
    •     SOC Maturity Assessment
    •     SOC Model Evaluation
    •     SOC Gap Analysis
    •     SIEM Gap Analysis
    •     SIEM Optimization
    •     SOC Content Pack
  • Train
    • Security Awareness and Training
    • Tabletop Exercise
    • Simulated Cyber Attack Exercises
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
COPYRIGHT © REWTERZ. ALL RIGHTS RESERVED.