Microsoft November out-of-cycle patch MS14-068

Published: 2014-11-18. Last Updated: 2014-11-19 00:15:18 UTC
by Jim Clausing (Version: 1)
21 comment(s)

Microsoft November out-of-cycle patch

Note: MS14-066 was also updated today to fix some of the issues previously discussed with the introduction of the additional TLS cipher suites.  Folks running Server 2008 R2 and Server 2012 are urged to reinstall

Update (2014-11-18 19:45 UTC) - After reading Microsoft's further explanation, the ISC ratings have been adjusted.

Ref: http://blogs.technet.com/b/srd/archive/2014/11/18/additional-information-about-cve-2014-6324.aspx

Overview of the November 2014 Microsoft patches and their status.

# Affected Contra Indications - KB Known Exploits Microsoft rating(**) ISC rating(*)
clients servers
MS14-068 Vulnerability in Kerberos Could Allow Elevation of Privilege. Could allow for forging of part of Kerberos service ticket.
(ReplacesMS11-013 MS10-014 )
Microsoft Windows

CVE-2014-6324
KB 3011780 Limited targeted attacks known to be in the wild Severity:Critical
Exploitability: 1
Important Critical
We will update issues on this page for about a week or so as they evolve.
We appreciate updates
US based customers can call Microsoft for free patch related support on 1-866-PCSAFETY
(*): ISC rating
  • We use 4 levels:
    • PATCH NOW: Typically used where we see immediate danger of exploitation. Typical environments will want to deploy these patches ASAP. Workarounds are typically not accepted by users or are not possible. This rating is often used when typical deployments make it vulnerable and exploits are being used or easy to obtain or make.
    • Critical: Anything that needs little to become "interesting" for the dark side. Best approach is to test and deploy ASAP. Workarounds can give more time to test.
    • Important: Things where more testing and other measures can help.
    • Less Urt practices for servers such as not using outlook, MSIE, word etc. to do traditional office or leisure work.
    • The rating is not a risk analysis as such. It is a rating of importance of the vulnerability and the perceived or even predicted threatatches.

       

---------------
Jim Clausing, GIAC GSE #26
jclausing --at-- isc [dot] sans (dot) edu

Keywords: mspatchday
21 comment(s)

Microsoft Will Release MS14-068 Later Today

Published: 2014-11-18. Last Updated: 2014-11-18 16:24:05 UTC
by Johannes Ullrich (Version: 1)
2 comment(s)

Today, Microsoft will release MS14-068. This is one of the bulletins that was skipped in November's patch Tuesday update. 

The bulletin fixes a privilege escalation vulnerability and Microsoft rated it Critical.

It does however appear that Microsoft still has process issues with releasing updates. For example, the "Monthly Bulletin Summary" for November now only lists this one bulletin [1]. The bulletin page itself is still blank, but will likely be released around 1:30pm ET.

We will update/replace this diary once the full bulletin is released.

[1] https://technet.microsoft.com/en-us/library/security/ms14-nov.aspx

 

---
Johannes B. Ullrich, Ph.D.
STI|Twitter|LinkedIn

Keywords:
2 comment(s)
ISC StormCast for Tuesday, November 18th 2014 http://isc.sans.edu/podcastdetail.html?id=4241

Comments


Diary Archives