ENISA EUVD · EUVD-2018-1616Official EUVD mapping0 linked advisory records.
Official EUVD record ↗Canadian Centre for Cyber Security · English · AV18-030Microsoft security updatesNumber: AV18-030
Date: 13 February 2018
Purpose
The purpose of this advisory is to bring attention to recently released Microsoft Security Updates.
Assessment
This advisory covers multiple support package deployments addressing multiple vulnerabilities in various Microsoft products.
Products Affected:
Internet Explorer
Microsoft Edge
Microsoft Windows
Microsoft Office and Microsoft Office Services and Web Apps
ChakraCore
Adobe Flash
CVE References: CVE-2018-0742, CVE-2018-0755, CVE-2018-0756, CVE-2018-0757, CVE-2018-0760, CVE-2018-0761, CVE-2018-0763, CVE-2018-0771, CVE-2018-0809, CVE-2018-0810, CVE-2018-0820, CVE-2018-0821, CVE-2018-0822, CVE-2018-0823, CVE-2018-0825, CVE-2018-0826, CVE-2018-0827, CVE-2018-0828, CVE-2018-0829, CVE-2018-0830, CVE-2018-0831, CVE-2018-0832, CVE-2018-0840, CVE-2018-0841, CVE-2018-0842, CVE-2018-0843, CVE-2018-0844, CVE-2018-0846, CVE-2018-0847, CVE-2018-0860, CVE-2018-0861, CVE-2018-0864, CVE-2018-0866, CVE-2018-0869
Suggested Action
CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.
References:
https://portal.msrc.microsoft.com/en-us/security-guidance
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-087Multiples vulnérabilités dans Microsoft Windowson
Bulletin de sécurité Microsoft du 13 février 2018
https://portal.msrc.microsoft.com/fr-FR/security-guidance
Référence CVE CVE-2018-0742
https://www.cve.org/CVERecord?id=CVE-2018-0742
Référence CVE CVE-2018-0755
https://www.cve.org/CVERecord?id=CVE-2018-0755
Référence CVE CVE-2018-0756
https://www.cve.org/CVERecord?id=CVE-2018-0756
Référence CVE CVE-2018-0757
https://www.cve.org/CVERecord?id=CVE-2018-0757
Référence CVE CVE-2018-0760
https://www.cve.org/CVERecord?id=CVE-2018-0760
Référence CVE CVE-2018-0761
https://www.cve.org/CVERecord?id=CVE-2018-0761
Référence CVE CVE-2018-0809
https://www.cve.org/CVERecord?id=CVE-2018-0809
Référence CVE CVE-2018-0810
https://www.cve.org/CVERecord?id=CVE-2018-0810
Référence CVE CVE-2018-0820
https://www.cve.org/CVERecord?id=CVE-2018-0820
Référence CVE CVE-2018-0821
https://www.cve.org/CVERecord?id=CVE-2018-0821
Référence CVE CVE-2018-0822
https://www.cve.org/CVERecord?id=CVE-2018-0822
Référence CVE CVE-2018-0823
https://www.cve.org/CVERecord?id=CVE-2018-0823
Référence CVE CVE-2018-0825
https://www.cve.org/CVERecord?id=CVE-2018-0825
Référence CVE CVE-2018-0826
https://www.cve.org/CVERecord?id=CVE-2018-0826
Référence CVE CVE-2018-0827
https://www.cve.org/CVERecord?id=CVE-2018-0827
Référence CVE CVE-2018-0828
https://www.cve.org/CVERecord?id=CVE-2018-0828
Ré
Official advisory ↗JVN iPedia · Japanese · JVNDB-2018-001900複数の Microsoft Windows 製品の Windows カーネルにおける情報を公開される脆弱性Microsoft Windows 7、Windows Server 2008 および 2012 の Windows カーネルには、メモリの初期化の処理に不備があるため、情報を公開される脆弱性が存在します。 ベンダは、本脆弱性を「Windows カーネルの情報漏えいの脆弱性」として公開しています。 本脆弱性は、CVE-2018-0757 とは異なる脆弱性です。
Official advisory ↗JVN iPedia · Japanese · JVNDB-2018-001898複数の Microsoft Windows 製品の Windows カーネルにおける情報を公開される脆弱性複数の Microsoft Windows 製品の Windows カーネルには、メモリ内のオブジェクト処理に不備があるため、情報を公開される脆弱性が存在します。 ベンダは、本脆弱性を「Windows カーネルの情報漏えいの脆弱性」として公開しています。 本脆弱性は、CVE-2018-0810 とは異なる脆弱性です。
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-4837MS 2월 보안 위협에 따른 정기 보안 업데이트 권고트사의 보안 패치 적용
Windows RT 8.1 보안 업데이트
##### □ 설명
o 공격자가 특수하게 제작된 악성 응용 프로그램을 실행할 경우, 원격코드실행을 허용하는 취약점
o 관련취약점 :
- 서비스거부 취약점(CVE-2018-0833)
- 권한상승 취약점(CVE-2018-0742, CVE-2018-0820, CVE-2018-0844, CVE-2018-0846)
- 정보노출 취약점(CVE-2018-0757, CVE-2018-0829, CVE-2018-0830, CVE-2018-0832, CVE-2018-0847)
- 원격코드실행 취약점(CVE-2018-0825, CVE-2018-0842)
o 영향 : 원격코드실행
o 중요도 : 긴급
o 관련 KB번호
- 4074594
##### □ 해결책
o 영향 받는 소프트웨어를 이용하는 경우 마이크로소프트사의 보안 패치 적용
Windows Server 2012 보안 업데이트
##### □ 설명
o 공격자가 특수하게 제작된 악성 응용 프로그램을 실행할 경우, 원격코드실행을 허용하는 취약점
o 관련취약점 :
- 권한상승 취약점(CVE-2018-0742, CVE-2018-0820, CVE-2018-0844, CVE-2018-0846)
- 정보노출 취약점(CVE-2018-0757, CVE-2018-0760, CVE-2018-0810, CVE-2018-0829, CVE-2018-0830, CVE-2018-0847)
- 원격코드실행 취약점(CVE-2018-0825, CVE-2018-0842)
o 영향 : 원격코드실행
o 중요도 : 긴급
o 관련 KB번호
- 4074589, 4074593
##### □ 해결책
o 영향 받는 소프트웨어를 이용하는 경우 마이크로소프트사의 보안 패치 적용
Windows 7, Server 2008 R2 보안 업데이트
##### □ 설명
o 공격자가 특수하게 제작된 악성 응용 프로그램을 실행할 경우, 원격코드실행을 허용하는 취약점
o 관련취약점 :
- 권한상승 취약점(CVE-2018-0742, CVE-2018-0820, CVE-2018-0844, CVE-2018-0846)
- 정보노출 취약점(CVE-2018-0755, CVE-2018-0757, CVE-2018-0760, CVE-2018-0761, CVE-2018-0810, CVE-2018-0829,
CVE-2018-0830, CVE-2018-0847, CVE-2018-0855)
- 원격코드실행 취약점(CVE-2018-0825, CVE-2018-0842)
o 영향 : 원격코드실행
o 중요도 : 긴급
o 관련 KB번호
- 4074589, 4074593
##### □ 해결책
o 영향 받는 소프트웨어를 이용하
Official advisory ↗