Advisory Date: 11 de декабря de 2019

  DESCRIPTION

Microsoft addresses several vulnerabilities in its December security bulletin. Trend Micro Deep Security covers the following:

  • CVE-2019-0617 - Jet Database Engine Remote Code Execution Vulnerability
    Risk Rating: Important

    This remote code execution vulnerability exists in the Windows Jet Database engine in respect to handling objects in memory. Attackers looking to exploit this vulnerability must find a way to convince a user to open a specially crafted file.


  • CVE-2019-1485 - VBScript Remote Code Execution Vulnerability
    Risk Rating: Important

    This remote code execution vulnerability exists in the improper handling of objects in memory by VBScript engine. Attackers looking to exploit this vulnerability must find a way to convince a user to access a malicious website where the exploit is hosted.


  • CVE-2019-0853 - GDI Remote Code Execution Vulnerability
    Risk Rating: Critical

    This remote code execution vulnerability exists in the improper handling of objects by the Windows Graphics Device Interface (GDI). Attackers looking to exploit this vulnerability must find a way for a user to open a website that contains the exploit, or to open a specially crafted file via file-sharing.


  • CVE-2019-1458 - Win32k Elevation of Privilege Vulnerability
    Risk Rating: Important

    This elevation of privilege vulnerability exists in the improper handling of objects by the the Win32k component in Windows. Attackers looking to exploit this vulnerability must find a way for a user to open a specially crafted application.


  • CVE-2019-1439 - Windows GDI Information Disclosure Vulnerability
    Risk Rating: Important

    This information disclosure vulnerability exists in the improper handling of objects in memory by the Windows GDI component. Attackers looking to exploit this vulnerability must find a way for a user to execute a specially crafted document.


  • CVE-2019-1117 - DirectWrite Remote Code Execution Vulnerability
    Risk Rating: Important

    This remote code execution vulnerability exists in the improper handling of objects in memory by the DirectWrite. Attackers looking to exploit this vulnerability must find a way for a user to execute a specially crafted document.


  • CVE-2019-1118 - DirectWrite Remote Code Execution Vulnerability
    Risk Rating: Important

    This remote code execution vulnerability exists in the improper handling of objects in memory by the DirectWrite. Attackers looking to exploit this vulnerability must find a way for a user to execute a specially crafted document.


  • CVE-2019-1119 - DirectWrite Remote Code Execution Vulnerability
    Risk Rating: Important

    This remote code execution vulnerability exists in the improper handling of objects in memory by the DirectWrite. Attackers looking to exploit this vulnerability must find a way for a user to execute a specially crafted document.


  • CVE-2019-0959 - Windows Common Log File System Driver Elevation of Privilege Vulnerability
    Risk Rating: Important

    This elevation of privilege vulnerability exists in the improper handling of objects in memory by the Windows Common Log File System. Attackers looking to exploit this vulnerability must find a way for a user to execute a specially crafted application.


  INFORMATION EXPOSURE

Trend Micro Deep Security shields networks through the following Deep Packet Inspection (DPI) rules. Trend Micro customers using the Vulnerability Protection are also protected from attacks using these vulnerabilities.

Vulnerability ID DPI Rule Number DPI Rule Name Release Date Vulnerability Protection Compatibility
CVE-2019-0617 1010083 Microsoft Windows Jet Database Engine Remote Code Execution Vulnerability (CVE-2019-0617) 10-Dec-19 YES
CVE-2019-1485 1010085 Microsoft Internet Explorer VBScript Remote Code Execution Vulnerability (CVE-2019-1485) 10-Dec-19 YES
CVE-2019-0853 1010086 Microsoft GDI Remote Code Execution Vulnerability (CVE-2019-0853) 10-Dec-19 YES
CVE-2019-1458 1010087 Microsoft Windows Elevation of Privilege Vulnerability (CVE-2019-1458) 10-Dec-19 YES
CVE-2019-1439 1010088 Microsoft Windows GDI Information Disclosure Vulnerability (CVE-2019-1439) 10-Dec-19 YES
CVE-2019-1117 and CVE-2019-1118 1010090 Microsoft Windows DirectWrite Remote Code Execution Vulnerability (CVE-2019-1117 and CVE-2019-1118) 10-Dec-19 YES
CVE-2019-1119 1010091 Microsoft Windows DirectWrite Remote Code Execution Vulnerability (CVE-2019-1119) 10-Dec-19 YES
CVE-2019-0959 1010092 Microsoft Windows Common Log File System Driver Elevation Of Privilege Vulnerability (CVE-2019-0959) 10-Dec-19 YES
CVE-2019-1150 1010093 Microsoft Windows Graphics Remote Code Execution Vulnerability (CVE-2019-1150) 10-Dec-19 YES