CSIRT Panamá Aviso 2019-10-11 Microsoft Libera sus actualizaciones de seguridad para Octubre

CSIRT Panamá Aviso 2019-10-11 Microsoft Libera sus actualizaciones de seguridad para Octubre
Gravedad: Alta
Fecha de publicación: Octubre 11, 2019
Última revisión: Agosto 10, 2019
https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/28ef0a64-489c-e911-a994-000d3a33c573

Sistemas Afectados:
Microsoft Windows
Internet Explorer
Microsoft Edge (EdgeHTML-based)
ChakraCore
Microsoft Office and Microsoft Office Services and Web Apps
SQL Server Management Studio
Open Source Software
Microsoft Dynamics 365
Windows Update Assistant

I. Descripción
Microsoft publicó las siguientes actualizaciones de seguridad correspondientes este mes.

II. Problemas Conocidos

TagCVE IDCVE TitleSeverity
AzureCVE-2019-1372Azure App Service Remote Code Execution VulnerabilityCritical
Internet ExplorerCVE-2019-1371Internet Explorer Memory Corruption VulnerabilityImportant
Microsoft BrowsersCVE-2019-0608Microsoft Browser Spoofing VulnerabilityImportant
Microsoft BrowsersCVE-2019-1357Microsoft Browser Spoofing VulnerabilityImportant
Microsoft DevicesCVE-2019-1314Windows 10 Mobile Security Feature Bypass VulnerabilityImportant
Microsoft DynamicsCVE-2019-1375Microsoft Dynamics 365 (On-Premise) Cross Site Scripting VulnerabilityImportant
Microsoft EdgeCVE-2019-1356Microsoft Edge based on Edge HTML Information Disclosure VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-1361Microsoft Graphics Components Information Disclosure VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-1362Win32k Elevation of Privilege VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-1364Win32k Elevation of Privilege VulnerabilityImportant
Microsoft Graphics ComponentCVE-2019-1363Windows GDI Information Disclosure VulnerabilityImportant
Microsoft JET Database EngineCVE-2019-1358Jet Database Engine Remote Code Execution VulnerabilityImportant
Microsoft JET Database EngineCVE-2019-1359Jet Database Engine Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2019-1331Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2019-1327Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office SharePointCVE-2019-1330Microsoft SharePoint Elevation of Privilege VulnerabilityImportant
Microsoft Office SharePointCVE-2019-1329Microsoft SharePoint Elevation of Privilege VulnerabilityImportant
Microsoft Office SharePointCVE-2019-1328Microsoft SharePoint Spoofing VulnerabilityImportant
Microsoft Office SharePointCVE-2019-1070Microsoft Office SharePoint XSS VulnerabilityImportant
Microsoft Scripting EngineCVE-2019-1366Chakra Scripting Engine Memory Corruption VulnerabilityCritical
Microsoft Scripting EngineCVE-2019-1060MS XML Remote Code Execution VulnerabilityCritical
Microsoft Scripting EngineCVE-2019-1307Chakra Scripting Engine Memory Corruption VulnerabilityCritical
Microsoft Scripting EngineCVE-2019-1308Chakra Scripting Engine Memory Corruption VulnerabilityCritical
Microsoft Scripting EngineCVE-2019-1335Chakra Scripting Engine Memory Corruption VulnerabilityModerate
Microsoft Scripting EngineCVE-2019-1239VBScript Remote Code Execution VulnerabilityCritical
Microsoft Scripting EngineCVE-2019-1238VBScript Remote Code Execution VulnerabilityCritical
Microsoft WindowsCVE-2019-1325Windows Redirected Drive Buffering System Elevation of Privilege VulnerabilityModerate
Microsoft WindowsCVE-2019-1340Microsoft Windows Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2019-1338Windows NTLM Security Feature Bypass VulnerabilityImportant
Microsoft WindowsCVE-2019-1339Windows Error Reporting Manager Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2019-1316Microsoft Windows Setup Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2019-1342Windows Error Reporting Manager Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2019-1311Windows Imaging API Remote Code Execution VulnerabilityImportant
Microsoft WindowsCVE-2019-1344Windows Code Integrity Module Information Disclosure VulnerabilityImportant
Microsoft WindowsCVE-2019-1347Windows Denial of Service VulnerabilityImportant
Microsoft WindowsCVE-2019-1315Windows Error Reporting Manager Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2019-1346Windows Denial of Service VulnerabilityImportant
Microsoft WindowsCVE-2019-1317Microsoft Windows Denial of Service VulnerabilityImportant
Microsoft WindowsCVE-2019-1321Microsoft Windows CloudStore Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2019-1322Microsoft Windows Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2019-1341Windows Power Service Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2019-1319Windows Error Reporting Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2019-1318Microsoft Windows Transport Layer Security Spoofing VulnerabilityImportant
Microsoft WindowsCVE-2019-1320Microsoft Windows Elevation of Privilege VulnerabilityImportant
Open Source SoftwareCVE-2019-1369Open Enclave SDK Information Disclosure VulnerabilityImportant
Secure BootCVE-2019-1368Windows Secure Boot Security Feature Bypass VulnerabilityImportant
Servicing Stack UpdatesADV990001Latest Servicing Stack UpdatesCritical
SQL ServerCVE-2019-1376SQL Server Management Studio Information Disclosure VulnerabilityImportant
SQL ServerCVE-2019-1313SQL Server Management Studio Information Disclosure VulnerabilityImportant
Windows Hyper-VCVE-2019-1230Hyper-V Information Disclosure VulnerabilityImportant
Windows IISCVE-2019-1365Microsoft IIS Server Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2019-1343Windows Denial of Service VulnerabilityImportant
Windows KernelCVE-2019-1334Windows Kernel Information Disclosure VulnerabilityImportant
Windows KernelCVE-2019-1345Windows Kernel Information Disclosure VulnerabilityImportant
Windows NTLMCVE-2019-1166Windows NTLM Tampering VulnerabilityImportant
Windows RDPCVE-2019-1326Windows Remote Desktop Protocol (RDP) Denial of Service VulnerabilityImportant
Windows RDPCVE-2019-1333Remote Desktop Client Remote Code Execution VulnerabilityCritical
Windows Update StackCVE-2019-1323Microsoft Windows Update Client Elevation of Privilege VulnerabilityImportant
Windows Update StackCVE-2019-1337Windows Update Client Information Disclosure VulnerabilityImportant
Windows Update StackCVE-2019-1336Microsoft Windows Update Client Elevation of Privilege VulnerabilityImportant

III. Referencia a soluciones, herramientas e información
Actualizar utilizando Windows Update

IV. Información de contacto
CSIRT PANAMA
Computer Security Incident Response Team Autoridad Nacional para la Innovacion Gubernamental
E-Mail: info@cert.pa
Phone: +507 520-CERT (2378)
Web: https://cert.pa
Twitter: @CSIRTPanama
Facebook: http://www.facebook.com/CSIRTPanama
Key ID: 16F2B124