CVE-2018-8589
published 2018-11-14CVE-2018-8589: An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k Elevation of Privilege Vulnerability."…
PriorityP178high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-06-13
Exploited in the wild
EPSS
3.02%
85.9th percentile
An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_7 | — | — |
| microsoft | windows_7 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2 | — | — |
| microsoft | windows_server_2008_r2 | — | — |
| microsoft | windows_server_2008_r2 | — | — |
| msrc | windows_7_for_32-bit_systems_service_pack_1 | — | — |
| msrc | windows_7_for_x64-based_systems_service_pack_1 | — | — |
| msrc | windows_server_2008_for_32-bit_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_for_itanium-based_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_for_x64-based_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_r2_for_itanium-based_systems_service_pack_1 | — | — |
| msrc | windows_server_2008_r2_for_x64-based_systems_service_pack_1 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
yara↗
HEUR:Exploit.Win32.Generic
- →The exploit targets only 32-bit versions of Windows 7; detections should prioritize 32-bit win32k.sys call patterns on Windows 7 / Server 2008 / Server 2008 R2. ↗
- →The vulnerability is a race condition in win32k!xxxMoveWindow triggered via WM_NCCALCSIZE message callbacks; monitor for anomalous cross-thread window-move operations and WM_NCCALCSIZE handling in win32k. ↗
- →Exploit achieves kernel code execution by populating lParam with pointers to shellcode, which is then copied into kernel via win32k!SfnINOUTNCCALCSIZE; look for user-mode shellcode pointers being passed as lParam in WM_NCCALCSIZE messages. ↗
- →Kaspersky AEP (Automatic Exploit Prevention) and Behavioral Detection Engine proactively detected this exploit; ensure endpoint behavioral detection is enabled for win32k exploit patterns. ↗
- →Threat actors FruityArmor and SandCat are attributed to exploitation of CVE-2018-8589; SandCat also uses FinFisher/FinSpy and CHAINSHOT malware — correlate detections of these malware families with CVE-2018-8589 exploitation activity.
- ·Exploitation in the wild was limited to Windows 7 (32-bit) and Windows Server 2008/2008 R2; the exploit does not affect 64-bit Windows 7 or later OS versions based on observed in-the-wild samples. ↗
- ·At time of discovery, victim telemetry was geographically limited to the Middle East; broader targeting cannot be ruled out. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft Win32k Privilege Escalation Vulnerability
cisa·2022-05-23·CVSS 7.8
CVE-2018-8589 [HIGH] Microsoft Win32k Privilege Escalation Vulnerability
Vulnerability: Microsoft Win32k Privilege Escalation Vulnerability
Affected: Microsoft Win32k
A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-8589
Remediation Due Date: 2022-06-13
Microsoft
Windows Win32k Elevation of Privilege Vulnerability
vendor_msrc·2018-11-13·CVSS 7.8
CVE-2018-8589 [HIGH] Windows Win32k Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys.
An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control over an affected system.
The update addresses the vulnerability by correcting how Windows handles calls to Win32k.
Windows Kernel: Windows Kernel
Microsoft: Microsoft
Customer Action Requi
GHSA
GHSA-67qx-v8w9-q5x5: An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k
ghsa_unreviewed·2022-05-13
CVE-2018-8589 [HIGH] GHSA-67qx-v8w9-q5x5: An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k
An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.
VulnCheck
Microsoft Win32k Privilege Escalation Vulnerability
vulncheck·2018·CVSS 7.8
CVE-2018-8589 [HIGH] Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k Privilege Escalation Vulnerability
A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system.
Affected: Microsoft Win32k
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2018-Nov; https://securelist.com/zero-day-in-windows-kernel-transaction-manager-cve-2018-8611/89253/; https://dl.acm.org/doi/pdf/10.1145/3465481.3465758; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-06-13
No detection rules found.
No public exploits indexed.
Securelist
IT threat evolution Q1 2019
blogs_securelist·2019-05-23
IT threat evolution Q1 2019
Table of Contents
- Targeted attacks and malware campaigns
- Other malware news
Authors
- David Emm
## Targeted attacks and malware campaigns
### Go Zebrocy
Zebrocy was first observed being used as a Sofacy backdoor in 2015. However, the collection of cases where this tool has been used mean that we consider it a subset of activity in its own right. On the basis of this threat actor’s past behaviour, we predicted last year that Zebrocy would continue to innovate in its malware development. The group has developed using Delphi, AutoIT, .NET, C# and PowerShell. Since May 2018, Zebrocy has added the “Go” language to its arsenal – the first time that we have observed a well-known APT threat actor deploy malware with this compiled open-source language.
Zebrocy continues to target governm
Securelist
IT threat evolution Q1 2019
blogs_securelist·2019-05-23
IT threat evolution Q1 2019
Table of Contents
Targeted attacks and malware campaigns
Go Zebrocy
GreyEnergy overlap with Zebrocy
Chafer uses Remexi malware to spy on Iran-based diplomatic agencies
New zero-day vulnerability exploited by APT threat actors
Lazarus continues to target crypto-currency exchanges
Under the [Shadow]Hammer
Other malware news
Razy Trojan steals crypto-currency
Turning ATMs into slot machines
Pirate Matryoshka
Mirai now used to target enterprise devices
‘Collection #1’ and other data leaks
Social engineering
LockerGoga ransomware attacks
19-year-old bug in WinRAR
The internet of secure, and not so secure, things
Authors
David Emm
## Targeted attacks and malware campaigns
## Go Zebrocy
Zebrocy was first observed being used as a Sofacy backdoor in 2015. However, the collecti
Securelist
New win32k zero day: CVE-2019-0859
blogs_securelist·2019-04-15·CVSS 7.8
CVE-2019-0859 [HIGH] New win32k zero day: CVE-2019-0859
Authors
- Vasily Berdnikov
- Boris Larin
- Anton Ivanov
In March 2019, our automatic Exploit Prevention (EP) systems detected an attempt to exploit a vulnerability in the Microsoft Windows operating system. Further analysis of this event led to us discovering a zero-day vulnerability in win32k.sys. It was the fifth consecutive exploited Local Privilege Escalation vulnerability in Windows that we have discovered in recent months using our technologies. The previous ones were:
- Zero-day exploit (CVE-2018-8453) used in targeted attacks
- A new exploit for zero-day vulnerability CVE-2018-8589
- Zero-day in Windows Kernel Transaction Manager (CVE-2018-8611)
- The fourth horseman: CVE-2019-0797 vulnerability
On March 17, 2019 we reported our discovery to Microsoft; the company confirmed the
Securelist
New zero-day vulnerability CVE-2019-0859 in win32k.sys
blogs_securelist·2019-04-15·CVSS 7.8
[HIGH] New zero-day vulnerability CVE-2019-0859 in win32k.sys
Authors
Vasily Berdnikov
Boris Larin
Anton Ivanov
In March 2019, our automatic Exploit Prevention (EP) systems detected an attempt to exploit a vulnerability in the Microsoft Windows operating system. Further analysis of this event led to us discovering a zero-day vulnerability in win32k.sys. It was the fifth consecutive exploited Local Privilege Escalation vulnerability in Windows that we have discovered in recent months using our technologies. The previous ones were:
Zero-day exploit (CVE-2018-8453) used in targeted attacks
A new exploit for zero-day vulnerability CVE-2018-8589
Zero-day in Windows Kernel Transaction Manager (CVE-2018-8611)
The fourth horseman: CVE-2019-0797 vulnerability
On March 17, 2019 we reported our discovery to Microsoft; the company confirmed the vulnerab
Securelist
The fourth horseman: CVE-2019-0797 vulnerability | Securelist
blogs_securelist·2019-03-13·CVSS 7.8
CVE-2019-0797 [HIGH] The fourth horseman: CVE-2019-0797 vulnerability | Securelist
Authors
- Vasily Berdnikov
- Boris Larin
## The new zero-day in the Windows OS exploited in targeted attacks
In February 2019, our Automatic Exploit Prevention (AEP) systems detected an attempt to exploit a vulnerability in the Microsoft Windows operating system. Further analysis of this event led to us discovering a zero-day vulnerability in win32k.sys. We reported it to Microsoft on February 22, 2019. The company confirmed the vulnerability and assigned it CVE-2019-0797. Microsoft have just released a patch, crediting Kaspersky Lab researchers Vasiliy Berdnikov and Boris Larin with the discovery:
This is the fourth consecutive exploited Local Privilege Escalation vulnerability in Windows we have discovered recently using our technologies. Just like with CVE-2018-8589, we believe this
Securelist
The fourth horseman: CVE-2019-0797 vulnerability
blogs_securelist·2019-03-13·CVSS 7.8
CVE-2019-0797 [HIGH] The fourth horseman: CVE-2019-0797 vulnerability
Authors
Vasily Berdnikov
Boris Larin
## The new zero-day in the Windows OS exploited in targeted attacks
In February 2019, our Automatic Exploit Prevention (AEP) systems detected an attempt to exploit a vulnerability in the Microsoft Windows operating system. Further analysis of this event led to us discovering a zero-day vulnerability in win32k.sys. We reported it to Microsoft on February 22, 2019. The company confirmed the vulnerability and assigned it CVE-2019-0797 . Microsoft have just released a patch, crediting Kaspersky Lab researchers Vasiliy Berdnikov and Boris Larin with the discovery:
This is the fourth consecutive exploited Local Privilege Escalation vulnerability in Windows we have discovered recently using our technologies. Just like with CVE-2018-8589 , we believe this
Securelist
Zero-day in Windows Kernel Transaction Manager (CVE-2018-8611)
blogs_securelist·2018-12-12·CVSS 7.8
CVE-2018-8611 [HIGH] Zero-day in Windows Kernel Transaction Manager (CVE-2018-8611)
Authors
- Boris Larin
- Vladislav Stolyarov
- Anton Ivanov
## Executive summary
In October 2018, our AEP (Automatic Exploit Prevention) systems detected an attempt to exploit a vulnerability in the Microsoft Windows operating system. Further analysis led us to uncover a zero-day vulnerability in ntoskrnl.exe. We reported it to Microsoft on October 29, 2018. The company confirmed the vulnerability and assigned it CVE-2018-8611. Microsoft just released a patch, part of its December update, crediting Kaspersky Lab researchers Boris Larin (Oct0xor) and Igor Soumenkov (2igosha) with the discovery.
This is the third consecutive exploited Local Privilege Escalation vulnerability in Windows we discovered this autumn using our technologies. Unlike the previously reported vulnerabilities in win3
Securelist
Zero-day in Windows Kernel Transaction Manager (CVE-2018-8611)
blogs_securelist·2018-12-12·CVSS 7.8
CVE-2018-8611 [HIGH] Zero-day in Windows Kernel Transaction Manager (CVE-2018-8611)
Authors
Boris Larin
Vladislav Stolyarov
Anton Ivanov
## Executive summary
In October 2018, our AEP (Automatic Exploit Prevention) systems detected an attempt to exploit a vulnerability in the Microsoft Windows operating system. Further analysis led us to uncover a zero-day vulnerability in ntoskrnl.exe. We reported it to Microsoft on October 29, 2018. The company confirmed the vulnerability and assigned it CVE-2018-8611 . Microsoft just released a patch, part of its December update, crediting Kaspersky Lab researchers Boris Larin ( Oct0xor ) and Igor Soumenkov ( 2igosha ) with the discovery.
This is the third consecutive exploited Local Privilege Escalation vulnerability in Windows we discovered this autumn using our technologies. Unlike the previously reported vulnerabilities in win
Securelist
Kaspersky Security Bulletin 2018. Top security stories
blogs_securelist·2018-12-03
Kaspersky Security Bulletin 2018. Top security stories
Table of Contents
- Introduction
- Targeted attack campaigns
- Mobile APT campaigns
- Exploits
- Browser extensions – extending the reach of cybercriminals
- The World Cup of fraud
- Financial fraud on an industrial scale
- Ransomware – still a threat
- Asacub and banking Trojans
- Smart doesn’t mean secure
- Our data in their hands
Authors
- David Emm
- Victor Chebyshev
- Kaspersky Security Bulletin 2018. Statistics
- Kaspersky Security Bulletin 2018. Story of the year: miners
- Kaspersky Security Bulletin 2018. Threat Predictions for 2019
## Introduction
The internet is now woven into the fabric of our lives. Many people routinely bank, shop and socialize online and the internet is the lifeblood of commercial organizations. The dependence on technology of governments, businesses a
Securelist
Kaspersky Security Bulletin 2018. Top security stories
blogs_securelist·2018-12-03
Kaspersky Security Bulletin 2018. Top security stories
Table of Contents
Introduction
Targeted attack campaigns
Mobile APT campaigns
Exploits
Browser extensions – extending the reach of cybercriminals
The World Cup of fraud
Financial fraud on an industrial scale
Ransomware – still a threat
Asacub and banking Trojans
Smart doesn’t mean secure
Our data in their hands
Authors
David Emm
Victor Chebyshev
Kaspersky Security Bulletin 2018. Statistics
Kaspersky Security Bulletin 2018. Story of the year: miners
Kaspersky Security Bulletin 2018. Threat Predictions for 2019
## Introduction
The internet is now woven into the fabric of our lives. Many people routinely bank, shop and socialize online and the internet is the lifeblood of commercial organizations. The dependence on technology of governments, businesses and consumers provide
Trendmicro
Patch Tuesday Fixes Zero-Day Win32k Bug
blogs_trendmicro·2018-11-14·CVSS 7.8
CVE-2018-8589 [HIGH] Patch Tuesday Fixes Zero-Day Win32k Bug
Exploits & Vulnerabilities
# Patch Tuesday Fixes Zero-Day Win32k Bug
This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability (CVE-2018-8589) that is already being used in malicious attacks.
By: Trend Micro
2018/11/14
Read time: ( words)
Save to Folio
As the year comes to a close, updates for both Microsoft and Adobe products and services are still ongoing via Patch Tuesday. This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability that is already being used in malicious attacks. Perhaps the most notable vulnerability addressed this month is CVE-2018-8589, another Win32k Elevation of Privilege Vulnerability that is similar to October’s CVE-2018-8453, which allows an attacker to make use of specially craf
Trendmicro
Patch Tuesday Fixes Zero-Day Win32k Bug
blogs_trendmicro·2018-11-14·CVSS 7.8
CVE-2018-8589 [HIGH] Patch Tuesday Fixes Zero-Day Win32k Bug
Exploits y vulnerabilidades
## Patch Tuesday Fixes Zero-Day Win32k Bug
This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability (CVE-2018-8589) that is already being used in malicious attacks.
By: Trend Micro Nov 14, 2018 Read time: ( words)
Save to Folio
As the year comes to a close, updates for both Microsoft and Adobe products and services are still ongoing via Patch Tuesday . This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability that is already being used in malicious attacks. Perhaps the most notable vulnerability addressed this month is CVE-2018-8589 , another Win32k Elevation of Privilege Vulnerability that is similar to October ’s CVE-2018-8453 , which allows an attacker to make use of special
Securelist
A new exploit for zero-day vulnerability CVE-2018-8589
blogs_securelist·2018-11-14·CVSS 7.8
CVE-2018-8589 [HIGH] A new exploit for zero-day vulnerability CVE-2018-8589
Authors
Boris Larin
Anton Ivanov
Vladislav Stolyarov
Yesterday, Microsoft published its security bulletin, which patches a vulnerability discovered by our technologies. We reported it to Microsoft on October 17, 2018. The company confirmed the vulnerability and assigned it CVE-2018-8589.
In October 2018, our Automatic Exploit Prevention (AEP) systems detected an attempt to exploit a vulnerability in Microsoft’s Windows operating system. Further analysis revealed a zero-day vulnerability in win32k.sys. The exploit was executed by the first stage of a malware installer in order to gain the necessary privileges for persistence on the victim’s system. So far, we have detected a very limited number of attacks using this vulnerability. The victims are located in the Middle East.
Kaspersky
Trendmicro
Patch Tuesday Fixes Zero-Day Win32k Bug
blogs_trendmicro·2018-11-14·CVSS 7.8
CVE-2018-8589 [HIGH] Patch Tuesday Fixes Zero-Day Win32k Bug
Ausnutzung von Schwachstellen
## Patch Tuesday Fixes Zero-Day Win32k Bug
This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability (CVE-2018-8589) that is already being used in malicious attacks.
By: Trend Micro Nov 14, 2018 Read time: ( words)
Save to Folio
As the year comes to a close, updates for both Microsoft and Adobe products and services are still ongoing via Patch Tuesday . This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability that is already being used in malicious attacks. Perhaps the most notable vulnerability addressed this month is CVE-2018-8589 , another Win32k Elevation of Privilege Vulnerability that is similar to October ’s CVE-2018-8453 , which allows an attacker to make use of speci
Krebs
Patch Tuesday, November 2018 Edition
blogs_krebs·2018-11-14·CVSS 4.6
[MEDIUM] Patch Tuesday, November 2018 Edition
Microsoft on Tuesday released 16 software updates to fix more than 60 security holes in various flavors of Windows and other Microsoft products. Adobe also has security patches available for Flash Player , Acrobat and Reader users.
As per usual, most of the critical flaws — those that can be exploited by malware or miscreants without any help from users — reside in Microsoft’s Web browsers Edge and Internet Explorer .
This week’s patch batch addresses two flaws of particular urgency: One is a zero-day vulnerability ( CVE-2018-8589 ) that is already being exploited to compromise Windows 7 and Server 2008 systems.
The other is a publicly disclosed bug in Microsoft’s Bitlocker encryption technology ( CVE-2018-8566 ) that could allow an attacker to get access to encrypted data. One mitigati
Krebs
Patch Tuesday, November 2018 Edition
blogs_krebs·2018-11-14·CVSS 4.6
CVE-2018-8589 [MEDIUM] Patch Tuesday, November 2018 Edition
Microsoft on Tuesday released 16 software updates to fix more than 60 security holes in various flavors of Windows and other Microsoft products. Adobe also has security patches available for Flash Player, Acrobat and Reader users.
This week’s patch batch addresses two flaws of particular urgency: One is a zero-day vulnerability (CVE-2018-8589) that is already being exploited to compromise Windows 7 and Server 2008 systems.
The other is a publicly disclosed bug in Microsoft’s Bitlocker encryption technology (CVE-2018-8566) that could allow an attacker to get access to encrypted data. One mitigating factor with both security holes is that the attacker would need to be already logged in to the targeted system to exploit them.
Of course, if the target has Adobe Reader or Acrobat installed,
Securelist
A new exploit for zero-day vulnerability CVE-2018-8589
blogs_securelist·2018-11-14·CVSS 7.8
CVE-2018-8589 [HIGH] A new exploit for zero-day vulnerability CVE-2018-8589
Authors
- Boris Larin
- Anton Ivanov
- Vladislav Stolyarov
Yesterday, Microsoft published its security bulletin, which patches a vulnerability discovered by our technologies. We reported it to Microsoft on October 17, 2018. The company confirmed the vulnerability and assigned it CVE-2018-8589.
In October 2018, our Automatic Exploit Prevention (AEP) systems detected an attempt to exploit a vulnerability in Microsoft’s Windows operating system. Further analysis revealed a zero-day vulnerability in win32k.sys. The exploit was executed by the first stage of a malware installer in order to gain the necessary privileges for persistence on the victim’s system. So far, we have detected a very limited number of attacks using this vulnerability. The victims are located in the Middle East.
Kasper
Trendmicro
Patch Tuesday Fixes Zero-Day Win32k Bug
blogs_trendmicro·2018-11-14·CVSS 7.8
CVE-2018-8589 [HIGH] Patch Tuesday Fixes Zero-Day Win32k Bug
Sfruttamento vulnerabilità
## Patch Tuesday Fixes Zero-Day Win32k Bug
This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability (CVE-2018-8589) that is already being used in malicious attacks.
By: Trend Micro Nov 14, 2018 Read time: ( words)
Save to Folio
As the year comes to a close, updates for both Microsoft and Adobe products and services are still ongoing via Patch Tuesday . This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability that is already being used in malicious attacks. Perhaps the most notable vulnerability addressed this month is CVE-2018-8589 , another Win32k Elevation of Privilege Vulnerability that is similar to October ’s CVE-2018-8453 , which allows an attacker to make use of speciall
Trendmicro
Patch Tuesday Fixes Zero-Day Win32k Bug
blogs_trendmicro·2018-11-14·CVSS 7.8
CVE-2018-8589 [HIGH] Patch Tuesday Fixes Zero-Day Win32k Bug
Exploits & Vulnerabilities
## Patch Tuesday Fixes Zero-Day Win32k Bug
This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability (CVE-2018-8589) that is already being used in malicious attacks.
By: Trend Micro Nov 14, 2018 Read time: ( words)
Save to Folio
As the year comes to a close, updates for both Microsoft and Adobe products and services are still ongoing via Patch Tuesday . This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability that is already being used in malicious attacks. Perhaps the most notable vulnerability addressed this month is CVE-2018-8589 , another Win32k Elevation of Privilege Vulnerability that is similar to October ’s CVE-2018-8453 , which allows an attacker to make use of speciall
Trendmicro
Patch Tuesday Fixes Zero-Day Win32k Bug
blogs_trendmicro·2018-11-14·CVSS 7.8
CVE-2018-8589 [HIGH] Patch Tuesday Fixes Zero-Day Win32k Bug
Exploits & Vulnerabilities
## Patch Tuesday Fixes Zero-Day Win32k Bug
This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability (CVE-2018-8589) that is already being used in malicious attacks.
By: Trend Micro 2018/11/14 Read time: ( words)
Save to Folio
As the year comes to a close, updates for both Microsoft and Adobe products and services are still ongoing via Patch Tuesday . This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability that is already being used in malicious attacks. Perhaps the most notable vulnerability addressed this month is CVE-2018-8589 , another Win32k Elevation of Privilege Vulnerability that is similar to October ’s CVE-2018-8453 , which allows an attacker to make use of specially
Qualys
November 2018 Patch Tuesday – 62 Vulns, TFTP Server RCE, Adobe PoC | Qualys
blogs_qualys·2018-11-13·CVSS 9.8
[CRITICAL] November 2018 Patch Tuesday – 62 Vulns, TFTP Server RCE, Adobe PoC | Qualys
This month’s Patch Tuesday addresses 62 vulnerabilities, with 12 of them labeled as Critical. Out of the Criticals, 8 are for the Chakra Scripting Engine used by Microsoft Edge. A Remote Code Execution vulnerability in Windows Deployment Services’ TFTP server is also addressed in this release. Adobe also patched three Important vulnerabilities this month, although there is a PoC exploit available for Adobe Acrobat and Reader.
### Workstation Patches
Browser and Scripting Engine patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users. Out of the 12 Critical vulnerabilities, 10 can be exploited through browsers or opening malicio
Qualys
November 2018 Patch Tuesday – 62 Vulns, TFTP Server RCE, Adobe PoC
blogs_qualys·2018-11-13·CVSS 9.8
[CRITICAL] November 2018 Patch Tuesday – 62 Vulns, TFTP Server RCE, Adobe PoC
This month’s Patch Tuesday addresses 62 vulnerabilities, with 12 of them labeled as Critical. Out of the Criticals, 8 are for the Chakra Scripting Engine used by Microsoft Edge. A Remote Code Execution vulnerability in Windows Deployment Services’ TFTP server is also addressed in this release. Adobe also patched three Important vulnerabilities this month, although there is a PoC exploit available for Adobe Acrobat and Reader.
## Workstation Patches
Browser and Scripting Engine patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users. Out of the 12 Critical vulnerabilities, 10 can be exploited through browsers or opening maliciou
Threat Intel
SandCat
threat_intel·CVSS 7.8
CVE-2018-8589 [HIGH] SandCat
# Threat Actor: SandCat
## Description
SandCat, on the other hand, is a group that was discovered more recently by Kaspersky. One of the Windows vulnerabilities patched by Microsoft in December had been exploited by both FruityArmor and SandCat in attacks targeting the Middle East and Africa. SandCat has been using FinFisher/FinSpy spyware and CHAINSHOT, a piece of malware analyzed earlier this year by Palo Alto Networks. The group has also used the CVE-2018-8589 and CVE-2018-8611 Windows vulnerabilities in its attacks, both of which had a zero-day status when Microsoft released fixes.
Zscaler
Zscaler protects against 15 new vulnerabilities for Microsoft Windows, Internet Explorer, Microsoft Edge and ChakraCore. | Zscaler
blogs_zscaler·CVSS 5.5
[MEDIUM] Zscaler protects against 15 new vulnerabilities for Microsoft Windows, Internet Explorer, Microsoft Edge and ChakraCore. | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
http://www.securityfocus.com/bid/105796http://www.securitytracker.com/id/1042140https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8589http://www.securityfocus.com/bid/105796http://www.securitytracker.com/id/1042140https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8589https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-8589
2018-11-14
Published
2022-05-23
Added to CISA KEV
Exploited in the wild