CSIRT Panamá Aviso 2019-07-10 Microsoft Libera sus actualizaciones de seguridad para Julio

CSIRT Panamá Aviso 2019-07-10 Microsoft Libera sus actualizaciones de seguridad para Julio
Gravedad: Alta
Fecha de publicación: Julio 10, 2019
Última revisión: Julio 09, 2019
https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/48293f19-d662-e911-a98e-000d3a33c573

Sistemas Afectados:
Microsoft Windows
Internet Explorer
Microsoft Edge
Microsoft Office and Microsoft Office Services and Web Apps
Azure DevOps
Open Source Software
.NET Framework
Azure
SQL Server
ASP.NET
Visual Studio
Microsoft Exchange Server

I. Descripción
Microsoft publicó las siguientes actualizaciones de seguridad y de otra índole para Office en Julio de 2019.

II. Problemas Conocidos

TagCVE IDCVE TitleSeverity
.NET FrameworkCVE-2019-1083.NET Denial of Service VulnerabilityImportant
.NET FrameworkCVE-2019-1113.NET Framework Remote Code Execution VulnerabilityCritical
.NET FrameworkCVE-2019-1006WCF/WIF SAML Token Authentication Bypass VulnerabilityImportant
ASP.NETCVE-2019-1075ASP.NET Core Spoofing VulnerabilityModerate
AzureCVE-2019-0962Azure Automation Elevation of Privilege VulnerabilityImportant
Azure DevOpsCVE-2019-1076Team Foundation Server Cross-site Scripting VulnerabilityImportant
Azure DevOpsCVE-2019-1072Azure DevOps Server and Team Foundation Server Remote Code Execution VulnerabilityCritical
Internet ExplorerCVE-2019-1063Internet Explorer Memory Corruption VulnerabilityCritical
Microsoft BrowsersCVE-2019-1104Microsoft Browser Memory Corruption VulnerabilityCritical
Microsoft Exchange ServerADV190021Outlook on the web Cross-Site Scripting VulnerabilityImportant
Microsoft Exchange ServerCVE-2019-1136Microsoft Exchange Server Elevation of Privilege VulnerabilityImportant
Microsoft Exchange ServerCVE-2019-1137Microsoft Exchange Server Spoofing VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-1118DirectWrite Remote Code Execution VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-1119DirectWrite Remote Code Execution VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-1117DirectWrite Remote Code Execution VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-1127DirectWrite Remote Code Execution VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-1116Windows GDI Information Disclosure VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-1120DirectWrite Remote Code Execution VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-1124DirectWrite Remote Code Execution VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-0999DirectX Elevation of Privilege VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-1128DirectWrite Remote Code Execution VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-1121DirectWrite Remote Code Execution VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-1122DirectWrite Remote Code Execution VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-1123DirectWrite Remote Code Execution VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-1097DirectWrite Information Disclosure VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-1096Win32k Information Disclosure VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-1101Windows GDI Information Disclosure VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-1098Windows GDI Information Disclosure VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-1095Windows GDI Information Disclosure VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-1102GDI+ Remote Code Execution VulnerabilityCritical
Microsoft Graphics ComponentCVE-2019-1100Windows GDI Information Disclosure VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-1094Windows GDI Information Disclosure VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-1093DirectWrite Information Disclosure VulnerabilityImportant
Microsoft OfficeCVE-2019-1084Microsoft Exchange Information Disclosure VulnerabilityImportant
Microsoft OfficeCVE-2019-1111Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2019-1110Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2019-1109Microsoft Office Spoofing VulnerabilityImportant
Microsoft OfficeCVE-2019-1112Microsoft Excel Information Disclosure VulnerabilityImportant
Microsoft Office SharePointCVE-2019-1134Microsoft Office SharePoint XSS VulnerabilityImportant
Microsoft Scripting EngineCVE-2019-1062Chakra Scripting Engine Memory Corruption VulnerabilityCritical
Microsoft Scripting EngineCVE-2019-1004Scripting Engine Memory Corruption VulnerabilityCritical
Microsoft Scripting EngineCVE-2019-1001Scripting Engine Memory Corruption VulnerabilityCritical
Microsoft Scripting EngineCVE-2019-1059Scripting Engine Memory Corruption VulnerabilityModerate
Microsoft Scripting EngineCVE-2019-1056Scripting Engine Memory Corruption VulnerabilityCritical
Microsoft Scripting EngineCVE-2019-1106Chakra Scripting Engine Memory Corruption VulnerabilityCritical
Microsoft Scripting EngineCVE-2019-1092Chakra Scripting Engine Memory Corruption VulnerabilityCritical
Microsoft Scripting EngineCVE-2019-1103Chakra Scripting Engine Memory Corruption VulnerabilityCritical
Microsoft Scripting EngineCVE-2019-1107Chakra Scripting Engine Memory Corruption VulnerabilityCritical
Microsoft WindowsCVE-2019-1067Windows Kernel Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2019-1074Microsoft Windows Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2019-1091Microsoft unistore.dll Information Disclosure VulnerabilityImportant
Microsoft WindowsCVE-2019-1082Microsoft Windows Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2019-0975ADFS Security Feature Bypass VulnerabilityImportant
Microsoft WindowsCVE-2019-1130Windows Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2019-1129Windows Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2019-1037Windows Error Reporting Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2019-0880Microsoft splwow64 Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2019-0865SymCrypt Denial of Service VulnerabilityImportant
Microsoft WindowsCVE-2019-0785Windows DHCP Server Remote Code Execution VulnerabilityCritical
Microsoft WindowsCVE-2019-0887Remote Desktop Services Remote Code Execution VulnerabilityImportant
Microsoft WindowsCVE-2019-0966Windows Hyper-V Denial of Service VulnerabilityImportant
Microsoft WindowsCVE-2019-1126ADFS Security Feature Bypass VulnerabilityImportant
Microsoft Windows DNSCVE-2019-1090Windows dnsrlvr.dll Elevation of Privilege VulnerabilityImportant
Microsoft Windows DNSCVE-2019-0811Windows DNS Server Denial of Service VulnerabilityImportant
Open Source SoftwareCVE-2018-15664Docker Elevation of Privilege VulnerabilityImportant
Servicing Stack UpdatesADV990001Latest Servicing Stack UpdatesCritical
SQL ServerCVE-2019-1068Microsoft SQL Server Remote Code Execution VulnerabilityImportant
Visual StudioCVE-2019-1077Visual Studio Elevation of Privilege VulnerabilityImportant
Visual StudioCVE-2019-1079Visual Studio Information Disclosure VulnerabilityImportant
Windows KernelCVE-2019-1073Windows Kernel Information Disclosure VulnerabilityImportant
Windows KernelCVE-2019-1132Win32k Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2019-1071Windows Kernel Information Disclosure VulnerabilityImportant
Windows KernelCVE-2019-1089Windows RPCSS Elevation of Privilege VulnerabilityImportant
Windows MediaCVE-2019-1086Windows Audio Service Elevation of Privilege VulnerabilityImportant
Windows MediaCVE-2019-1088Windows Audio Service Elevation of Privilege VulnerabilityImportant
Windows MediaCVE-2019-1087Windows Audio Service Elevation of Privilege VulnerabilityImportant
Windows MediaCVE-2019-1085Windows WLAN Service Elevation of Privilege VulnerabilityImportant
Windows RDPCVE-2019-1108Remote Desktop Protocol Client Information Disclosure VulnerabilityImportant
Windows ShellCVE-2019-1099Windows GDI Information Disclosure VulnerabilityImportant

III. Referencia a soluciones, herramientas e información
Actualizar utilizando Windows Update

IV. Información de contacto
CSIRT PANAMA
Computer Security Incident Response Team Autoridad Nacional para la Innovacion Gubernamental
E-Mail: info@cert.pa
Phone: +507 520-CERT (2378)
Web: https://cert.pa
Twitter: @CSIRTPanama
Facebook: http://www.facebook.com/CSIRTPanama
Key ID: 16F2B124