SB2019081333 - Multiple privilege escalation vulnerabilities in Microsoft Windows



SB2019081333 - Multiple privilege escalation vulnerabilities in Microsoft Windows

Published: August 13, 2019

Security Bulletin ID SB2019081333
Severity
Medium
Patch available
YES
Number of vulnerabilities 14
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 7% Low 93%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 14 secuirty vulnerabilities.


1) Buffer overflow (CVE-ID: CVE-2019-1173)

The vulnerability allows a local user to escalate privilege so the system.

The vulnerability exists due to a boundary error in the PsmServiceExtHost.dll when handling objects in memory. A local user can create a specially crafted application, trigger memory corruption and execute arbitrary code on the target system with elevated privileges.


2) Input validation error (CVE-ID: CVE-2019-1198)

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to insufficient validation of user-supplied input in SyncController.dll.

A local user can create a specially crafted application and use this vulnerability in conjunction with another issue to escalate privileges on the system.


3) Buffer overflow (CVE-ID: CVE-2019-1190)

The vulnerability allows a local user to escalate privilege so the system.

The vulnerability exists due to a boundary error in the Windows kernel image when handling objects in memory. A local user can create a specially crafted application, trigger memory corruption and execute arbitrary code on the target system with elevated privileges.


4) Buffer overflow (CVE-ID: CVE-2019-1186)

The vulnerability allows a local user to escalate privilege so the system.

The vulnerability exists due to a boundary error in the wcmsvc.dll when handling objects in memory. A local user can create a specially crafted application, trigger memory corruption and execute arbitrary code on the target system with elevated privileges.


5) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2019-1184)

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to the way Windows handles COM calls. A local user can create a malicious application, launch it on the system and potentially set certain items to run at a higher level and thereby elevate permissions.


6) Buffer overflow (CVE-ID: CVE-2019-1177)

The vulnerability allows a local user to escalate privilege so the system.

The vulnerability exists due to a boundary error in the rpcss.dll when handling objects in memory. A local user can create a specially crafted application, trigger memory corruption and execute arbitrary code on the target system with elevated privileges.


7) Buffer overflow (CVE-ID: CVE-2019-1169)

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error when processing objects in memory within the Windows kernel-mode driver Win32k.sys. A local user can create a malicious application, launch it on the system and execute arbitrary code with SYSTEM privileges.


8) Buffer overflow (CVE-ID: CVE-2019-1164)

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error when processing objects in memory within the Windows kernel. A local user can create a malicious application, launch it on the system and execute arbitrary code with SYSTEM privileges.


9) Buffer overflow (CVE-ID: CVE-2019-1159)

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error when processing objects in memory within the Windows kernel. A local user can create a malicious application, launch it on the system and execute arbitrary code with SYSTEM privileges.


10) Buffer overflow (CVE-ID: CVE-2019-1180)

The vulnerability allows a local user to escalate privilege so the system.

The vulnerability exists due to a boundary error in the wcmsvc.dll when handling objects in memory. A local user can create a specially crafted application, trigger memory corruption and execute arbitrary code on the target system with elevated privileges.


11) Buffer overflow (CVE-ID: CVE-2019-1179)

The vulnerability allows a local user to escalate privilege so the system.

The vulnerability exists due to a boundary error in the unistore.dll when handling objects in memory. A local user can create a specially crafted application, trigger memory corruption and execute arbitrary code on the target system with elevated privileges.


12) Buffer overflow (CVE-ID: CVE-2019-1178)

The vulnerability allows a local user to escalate privilege so the system.

The vulnerability exists due to a boundary error in the ssdpsrv.dll when handling objects in memory. A local user can create a specially crafted application, trigger memory corruption and execute arbitrary code on the target system with elevated privileges.


13) Buffer overflow (CVE-ID: CVE-2019-1175)

The vulnerability allows a local user to escalate privilege so the system.

The vulnerability exists due to a boundary error in the psmsrv.dll when handling objects in memory. A local user can create a specially crafted application, trigger memory corruption and execute arbitrary code on the target system with elevated privileges.


14) Buffer overflow (CVE-ID: CVE-2019-1174)

The vulnerability allows a local user to escalate privilege so the system.

The vulnerability exists due to a boundary error in the PsmServiceExtHost.dll when handling objects in memory. A local user can create a specially crafted application, trigger memory corruption and execute arbitrary code on the target system with elevated privileges.


Remediation

Install update from vendor's website.