Skip to main content

Microsoft Monthly Patches Address 0-Day Vulnerabilities

Microsoft have released their monthly patch rollout to address a total of 56 vulnerabilities.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Microsoft have released their monthly patch rollout to address a total of 56 vulnerabilities.

Affected platforms

The following platforms are known to be affected:

Threat details

Details have emerged around 3 standout vulnerabilities that are believed to have been used in attacks by APT groups APT28 and Turla prior to the patches being made available.

The patch addresses vulnerabilities found in internet Explorer and Edge - along with those discovered in Office, .NET Framework, Hyper-V, SMB and the core Windows Environment.

Three vulnerabilities have been identified as 0-day vulnerabilities which have been actively exploited in the wild. These include CVE-2017-0261, CVE-2017-0262, CVE-2017-0263.

CVE-2017-0261 is a remote code execution vulnerability found within Microsoft Office and relates to the way it handles Encapsulated PostScript(EPS). It was seen in a small number of targeted attacks throughout March along with the use of CVE-2017-0001, a privilege escalation vulnerability found within the Graphics Device Interface (GDI) that allowed an attacker to go from initial exploitation to complete system compromise in the same attack.

As well as the three vulnerabilities mentioned above, a further four have been identified as publicly known although no live exploitation has been observed. The four vulnerabilities consist of a critical rated remote code execution vulnerability in the Microsoft JavaScript Scripting Engine and three important vulnerabilities with a security feature bypass in Internet explorer, a spoofing vulnerability within Microsoft browser's Render SmartScreen Filter and an elevation of privilege vulnerability within Microsoft Edge.


Remediation steps

Type Step
  • Ensure all patches contained within the May 2017 Security Updates are applied at the earliest available opportunity.
  • Consider implementing a routine patching schedule on your estate.
  • As with most attacks, the initial infection requires user interaction through a malicious link or attachment hence user awareness is key to mitigating the risk of attack.


Last edited: 17 February 2020 11:34 am