This alert may not be shared outside your organization, Do Not Repost or send, place on other websites, List servers, or send to others via email, including other associations or parties.  Members and Law enforcement use only. Contact us for any permissions.  To do otherwise will result in the loss of membership.

Complete Story
 

12/11/2019

VERT Threat Alert: December 2019 Patch Tuesday Analysis

Tripwire

Today’s VERT Alert addresses Microsoft’s December 2019 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-863 on Wednesday, December 11th. 

In-The-Wild & Disclosed CVEs

CVE-2019-1458

A vulnerability in Win32k is currently seeing active exploitation that could give an attacker the ability to run arbitrary code in kernel mode. Microsoft has addressed this vulnerability by correcting how Win32k handles objects in memory. The latest software releases are not impacted by this vulnerability.

Microsoft has rated this as a 4 (N/A) on the latest software release and 0 (Exploitation Detected) on older software releases on the Exploitability Index.

CVE-2019-1489

Microsoft has released a notification regarding RDP on Windows XP SP3. This is end of life software without an available update and Microsoft has indicated they have no plans to release one. There is no indication that this vulnerability has been publicly disclosed or exploited based on the exploitability index, but Microsoft has indicated that an attacker could use this vulnerability to obtain information that could be used to further compromise the user’s system.

Microsoft has rated this as a 0 (Unknown) on both the latest and older software releases on the Exploitability Index.

Read more...

Printer-Friendly Version


Resources

Alerts

The FRPA alert system distinguishes us from other groups by gathering and providing information to law enforcement, retailers AND financial institutions.

more information
Resources

Resources

Your electronic library to help in fighting financial fraud for all of our partners.

more information