PackerIT Solutions Corp. Information Technology and Cybersecurity Solutions
Here are the highlights of this months list of patches from our friends at Microsoft. 49 patches covering vulnerabilities, seven of which are rated “critical,” 40 that are considered “important” and one that is “moderate.” This release also includes a critical security advisory for multiple bugs in Adobe Flash Player.
This month’s security update covers security issues in a variety of Microsoft’s products, including the Jet Database Engine, Office SharePoint and the Chakra Scripting Engine.
A vulnerability (CVE-2019-0547) was discovered internally by Mitch Adair of the Microsoft Windows Enterprise Security Team, that could allow an attacker to send a specially crafted DHCP response to a client in order to perform arbitrary code execution on the client.
"A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client. An attacker who successfully exploited the vulnerability could run arbitrary code on the client machine.
To exploit the vulnerability, an attacker could send a specially crafted DHCP responses to a client."
This Patch Tuesday included security updates that fix two vulnerabilities (CVE-2019-0550 & CVE-2019-0551) in Hyper-V that could allow malware on the guest to execute code on the host operating system.
"To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary code."
This is particularly scary for researchers who use Hyper-V to analyze malware samples.
Full List from Microsoft https://portal.msrc.microsoft.com/en-us/security-guidance/summary
Best breakdown I saw https://www.thezdi.com/blog/2019/1/8/the-january-2019-security-update-review