January 2019 Patch Tuesday – 47 Vulns, 7 Critical, Adobe Vulns
Last updated on: October 27, 2022
This month’s Patch Tuesday is medium in size, with 47 vulns covered and only 7 labeled as Critical. Twenty-six of the vulns apply to Windows Servers and Workstation operating systems. Two of the Criticals apply to Hyper-V and could lead to RCE on the host system. Microsoft also issued and out-of-band patch in December for Internet Explorer 9 through 11 due to active attacks in the wild. Last week, Adobe also released out-of-band patches for Acrobat and Reader covering two Critical vulns.
Workstation Patches
Browser and Scripting Engine patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users. Four of the 7 critical vulns are for Chakra / Microsoft Edge and should be prioritized for these types of systems.
Out-of-band IE Patch
On December 19, Microsoft issued an out-of-band patch (CVE-2018-8653) for Internet Explorer 9 through 11 due to targeted active attacks against this vulnerability that were discovered in the wild. This patch should also be prioritized to all workstation-type devices.
Hyper-V
Two of the vulns apply to Hyper-V, and could potentially lead to a VM escape. Microsoft does label these as “Exploitation Less Likely,” but Hyper-V hosts should still have these Critical patches prioritized.
Adobe Patches
Adobe released patches for Flash, but they do not contain security updates. However, security patches were released for Adobe Digital Editions and Adobe Connect, covering two Important CVEs. In addition, patches were released out-of-band last week for Acrobat and Reader, covering two Critical CVEs. These patches should be prioritized for workstation-type devices.
CVE-2019-0586 stuck out to me as it’s a RCE as System via received (not opened) email on Exchange. That’s kinda the point of Exchange so yeah not sure how that one got only an Important rating. We are patching that one right away.
CVE-2019-0547 on DHCP clients also perked my interest for workstations even if it’s Win 10 only oddly enough. Mostly for remote workers in untrusted WiFi setups but that’s getting priority as well.
Thanks for the writeup! They are always very helpful.