Microsoft Patches Six Zero-Day Security Holes
krebsonsecurity.com
krebsonsecurity.com
Security warfare is fascinating to watch from the mud huts.
Yes. The NSA has disclosed hoarded zero-days to Microsoft when they have fallen into the hands of people they did not like. See the Shadow Brokers incident [1]:
> the critical vulnerabilities for four exploits previously believed to be zero-days were patched in March, exactly one month before a group called Shadow Brokers published Friday's latest installment of weapons-grade attacks
Obviously, the problem with this is that the NSA were unaware their zero-days had fallen into enemy hands until the Shadow Brokers very publicly advertised the fact that they had them.
[1]: https://arstechnica.com/information-technology/2017/04/purpo...
"The NSA did not alert Microsoft about the vulnerabilities, and held on to it for more than five years before the breach forced its hand. The agency then warned Microsoft after learning about EternalBlue's possible theft, allowing the company to prepare a software patch issued in March 2017,[19] after delaying its regular release of security patches in February 2017.[20] On Tuesday, March 14, 2017, Microsoft issued security bulletin MS17-010,[21] which detailed the flaw and announced that patches had been released for all Windows versions that were currently supported at that time
...
Many Windows users had not installed the patches when, two months later on May 12, 2017, the WannaCry ransomware attack used the EternalBlue vulnerability to spread itself"
Acknowledgements: Clément Lecigne of Google’s Threat Analysis Group
–CVE-2021-31955, an information disclosure bug in the Windows Kernel
Acknowledgements: Boris Larin (oct0xor) of Kaspersky Lab
–CVE-2021-31956, an elevation of privilege flaw in Windows NTFS
Acknowledgements: Boris Larin (oct0xor) of Kaspersky Lab
–CVE-2021-33739, an elevation of privilege flaw in the Microsoft Desktop Window Manager
Acknowledgements: Jinquan(@jq0904) with DBAPPSecurity Lieying Lab
The only one that stands out as being a real concern, but who's willing to bet it requires JS to exploit (or even if not, the attackers prefer to obfuscate it using JS)? Turning off JS by default in IE is probably the single most effective way of preventing these attacks. Even if you don't use IE, it'll greatly reduce the attack surface. I've browsed the shadier parts of the Internet for literally decades this way.
Anecdotally code execution exploits in pure HTML (that don't require JS) are exceedingly rare, so it is unlikely it doesn't use JS.
seems pretty bad...
Turning off the internet. Or your PC entirely is.
Just not visiting most of the Internet is a solid move too, JS or not.
But the only reason to use IE is for enterprise apps that probably require JavaScript to function.
And the ability to toggle JavaScript is probably locked down by Mordac the Preventer, aka group policy.
https://support.microsoft.com/en-us/windows/change-security-...
This is one of the notable features missing from Edge.
Modern browsers are not well fit for security and anonymity. Torbrowser is the only one that actually removes tracking data and the wider attack surfaces of modern browser features like webgl. However it's still not 'secure'. You still have plenty of features that come from complex codebases, such as media decoders.
https://www.catalog.update.microsoft.com/Search.aspx?q=KB500...
Is there a third party program that finds/installs the windows 7 updates?
[1] https://docs.microsoft.com/en-us/lifecycle/faq/extended-secu...
[2] https://techcommunity.microsoft.com/t5/windows-it-pro-blog/y...
[1] https://msrc.microsoft.com/update-guide/en-US/vulnerability/...
Source code here: https://gitlab.com/wsusoffline/wsusoffline
You are correct, this one wasn't caught organically through Windows Update. I had to install the KB4555449 Servicing Stack update first (https://www.catalog.update.microsoft.com/Search.aspx?q=KB455...), after which I was able to install the patch you linked. Did it on two machines (one freshly formatted, one old) and it took several minutes on each to install (longer than a typical update), and required a reboot after.
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/...
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/...
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/...
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/...
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/...
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/...
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/...
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/...
To add insult to injury, Microsoft's server refuses to honour the Accept-Encoding header, e.g., setting the value to "identity" has no effect. It returns compressed content no matter what, even when the content size is very small.
To create a simple HTML page with all the info you need, no Javascript required
sed '/^e/!s/^/url=/'<<eof|curl -K-|gzip -dc|sed 's/",/\"<br>/g;s/\\n//g' > 1.htm
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2021-33742
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2021-31955
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2021-31956
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2021-33739
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2021-31201
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2021-31199
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2021-31959
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2021-31963
eof
firefox ./1.htm tnftp instead of curl
ftp -4o'|zcat' $(printf "%s\40" $(cat<<eof
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2021-33742
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2021-31955
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2021-31956
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2021-33739
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2021-31201
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2021-31199
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2021-31959
https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2021-31963
eof
))|sed 's/",/\"<br>/g;s/\\n//g' > 1.htm;
firefox ./1.htmTo quote a comment I read on HN once, "Krebs is a security entertainer, not a security researcher."
There are some technical details that may be abstracted or analogized in less-than-accurate fashion, but I don't recall reading an article or post and thinking "gosh, that's just _wrong_"
Any of it, really.
[1] https://itwire.com/security/infosec-researchers-slam-ex-wapo...
[2] Note: This looks like the same issue as above, but it is separate; https://itwire.com/security/krebs-accused-of-doxxing-man-bas...
To his credit, he never claims to be a hands-on researcher who disassembles and analyzes malware himself. I guess that's why I scratch my head when people point to his work as substantial. He has no skin in the game, no hands on technical experience, and just reblogs more technical articles from actual experts. His only real experience is getting personally hacked and hijacked.
Also, to clarify I never questioned his journalistic integrity. I just think he's a mediocre writer. It's his style that I, personally, don't like. One thing he does that I can't wrap my head around is writing about himself in the third person. He uses phrases like "...this author..." in reference to himself. Most authors would not be injecting themselves into a journalistic piece in the first place, but to do it with such bravado is awkward for the reader. Am I supposed to be impressed that you operate a WordPress blog?