Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

It's 2020 and a rogue ICMPv6 network packet can pwn your Microsoft Windows machine (Patch Tuesday alert)
The Register ^ | Oct 13, 2020 | Thomas Claburn

Posted on 10/13/2020 6:41:18 PM PDT by dayglored

Redmond urges folks to apply update ASAP – plus more fixes for Outlook and software from Adobe, Intel, SAP, Red Hat

Patch Tuesday Microsoft's Update Tuesday patch dump for October 2020 has delivered security patches that attempt to address 87 CVEs for a dozen Redmond products.

Nadella's security crew has identified 22 remote code execution (RCE) CVEs though the most worrisome looks like CVE-2020-16898, Windows TCP/IP RCE, which is rated 9.8 out 10 in severity. It affects Windows desktop and server systems.

According to Microsoft, the Windows TCP/IP stack doesn't properly handle ICMPv6 Router Advertisement packets. Thus someone could send a vulnerable machine a maliciously crafted IPv6 packet over the network to inject and execute code on the box, and ultimately hijack it – presumably with kernel-level privileges. Here's the worrying blurb from Redmond:

A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could gain the ability to execute code on the target server or client.

To exploit this vulnerability, an attacker would have to send specially crafted ICMPv6 Router Advertisement packets to a remote Windows computer.

The update addresses the vulnerability by correcting how the Windows TCP/IP stack handles ICMPv6 Router Advertisement packets.

Microsoft said exploitation is likely, and a workaround is available for Windows build 1709 and above. You're urged to patch this ASAP, though.

"Since the code execution occurs in the TCP/IP stack, it is assumed the attacker could execute arbitrary code with elevated privileges," said Zero Day Initiative's Dustin Childs in a summary of today's patches.

"If you’re running an IPv6 network, you know that filtering router advertisements is not a practical workaround. Microsoft also gives this bug its highest exploitability rating, so exploits are likely. You should definitely test and deploy this patch as soon as possible."

CVE-2020-16947, a Microsoft Outlook RCE, also looks like it could pose problems. Rated with a CVSS score of 8.1/10, this memory handling flaw could allow an attacker to send a user with admin rights a specially crafted file and take over the system, if the preview pane is open.

"The specific flaw exists within the parsing of HTML content in an email," explained Childs. "The issue results from the lack of proper validation of the length of user-supplied data before copying it to a fixed-length heap-based buffer."

A total of 11 flaws are designated critical, 75 rate moderate, and one is merely important. Six of them have already been publicly disclosed.

Affected applications include:

The 88th entry on Microsoft's list is an advisory for Adobe Flash Player for Windows, which along with the versions for macOS, Linux and Chrome OS, contains a critical arbitrary code execution flaw (CVE-2020-9746).

Exploitation of the vulnerability "requires an attacker to insert malicious strings in an HTTP response that is by default delivered over TLS/SSL," according to Adobe.

Users should install Adobe Flash Player 32.0.0.445 on the applicable operating system and enjoy whatever time they have left with the app – Adobe plans to stop distributing Flash Player on December 31, 2020.

Enterprise software vendor SAP also delivered parcel of patches – 15 plus six additional patches to previous patches.

The most serious of these is an OS command injection vulnerability (CVE-2020-6364) affecting SAP Solution Manager (CA Introscope Enterprise Manager) and SAP Focused Run (CA Introscope Enterprise Manager), Versions - WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7. The bug rates 10 out of 10 in severity.

Intel released one security advisory covering three vulnerabilities in the BlueZ open-source Bluetooth stack. These high severity flaws could lead to privilege escalation and information disclosure. The fixes involve a Linux kernel update.

Red Hat meanwhile issued a security advisory for the Chromium browser in various Red Hat Enterprise Linux 6 packages. It addresses 35 fixes delivered by Google last week.

On the bright side, 87 CVEs is significantly less than the 129 Microsoft addressed in September. ®


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: microsoft; patchtuesday; windows; windowspinglist; windowsupdate
Navigation: use the links below to view more comments.
first 1-2021-40 next last
It's that time again...
1 posted on 10/13/2020 6:41:18 PM PDT by dayglored
[ Post Reply | Private Reply | View Replies]

To: Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; AppyPappy; arnoldc1; ATOMIC_PUNK; bajabaja; ...
Windows 10 Update ** Patch Tuesday **... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

2 posted on 10/13/2020 6:42:25 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Microsoft has gone to shit when it decided Americans were worthless scum and brought in Indian and Communist Chinese H1Bs scabs to replace the fired Americans.


3 posted on 10/13/2020 6:44:11 PM PDT by Starcitizen (Communist China needs to be treated like the pariah country it is. Send it back to 1971)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

“network packet can pwn”

Did the headline writer misspell “pawn”?


4 posted on 10/13/2020 6:44:56 PM PDT by Larry Lucido
[ Post Reply | Private Reply | To 1 | View Replies]

To: Larry Lucido

“misspell “pawn”?”

Nah. “pwn” is gamer thing, I think. ‘You’ve been owned’


5 posted on 10/13/2020 6:48:33 PM PDT by dynachrome (The panic will end, the tyranny will not)
[ Post Reply | Private Reply | To 4 | View Replies]

To: dayglored

Wish I could understand what you’re saying.

I got hit with something on a MS update that has Locked my windows up

Where’s the fix


6 posted on 10/13/2020 6:48:39 PM PDT by thinden
[ Post Reply | Private Reply | To 2 | View Replies]

To: dayglored

Would this only affect dual-homed servers that are configured as IPv6 routers?


7 posted on 10/13/2020 6:52:03 PM PDT by Ignatz (Winner of a prestigious 1960 Y-chromosome award!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dynachrome
"Pwn" is a common (and generally intentional) misspelling of "own", meaning to take over, conquer, infiltrate, another person's or company's computer or network.
8 posted on 10/13/2020 6:52:47 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Ignatz
> Would this only affect dual-homed servers that are configured as IPv6 routers?

The way I read it, if affects all Windows clients (Windows10) and servers (Windows Server 20xx). They all come up with IPv6 enabled and preferred. You have to go out of your way to disable IPv6.

9 posted on 10/13/2020 6:54:17 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 7 | View Replies]

To: dayglored

Works for me.


10 posted on 10/13/2020 6:54:36 PM PDT by dynachrome (The panic will end, the tyranny will not)
[ Post Reply | Private Reply | To 8 | View Replies]

To: dynachrome

Ah, so it’s the “boom” or “bombshell” equivalent of blogger headlines written by folks with five-year-old mentalities.


11 posted on 10/13/2020 6:54:52 PM PDT by Larry Lucido
[ Post Reply | Private Reply | To 5 | View Replies]

To: dayglored

“The specific flaw exists within the parsing of HTML content in an email,”

So I’m not affected if html is turned off in my webmail ? Even if using admin level?

I like to delay updates a week in case problems show up in updates.


12 posted on 10/13/2020 6:55:12 PM PDT by mrsmith (US MEDIA: " Every 'White' cop is a criminal! And all the 'non-white' criminals saints!")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Larry Lucido

See #8


13 posted on 10/13/2020 6:55:45 PM PDT by dynachrome (The panic will end, the tyranny will not)
[ Post Reply | Private Reply | To 11 | View Replies]

To: Larry Lucido

I was off a bit. Though I always heard it game related when you got stomped in whatever online game you were playing.


14 posted on 10/13/2020 6:57:36 PM PDT by dynachrome (The panic will end, the tyranny will not)
[ Post Reply | Private Reply | To 4 | View Replies]

To: thinden
> I got hit with something on a MS update that has Locked my windows up Where’s the fix

That depends on what the problem is caused by, which will be hard to diagnose if it won't run.

So an appropriate question in return is: Where's your backup?

I don't mean that to sound snarky, just trying to be helpful. If you can get it running, try to roll back to a "Restore Point". If you can't get it running, restore the machine from a backup.

Personally, I do a full backup of my Windows machines just prior to applying Windows Updates. That way if I have to restore, I haven't lost much work.

15 posted on 10/13/2020 6:58:02 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 6 | View Replies]

To: dynachrome
> I was off a bit. Though I always heard it game related when you got stomped in whatever online game you were playing.

Actually, you were right, it's just that the gaming usage is a smaller part of the larger network context.

16 posted on 10/13/2020 7:00:14 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 14 | View Replies]

To: dayglored

1709? Gotta patch ‘em more than once every couple of years...


17 posted on 10/13/2020 7:03:13 PM PDT by Dead Corpse (A Psalm in napalm...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
"Patch Tuesday"

groan...

18 posted on 10/13/2020 7:06:36 PM PDT by kiryandil (Chris Wallace: Because someone has to drive the Clown Car)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dynachrome; Larry Lucido; dayglored
Though I always heard it game related when you got stomped in whatever online game you were playing.

Yes. The winner got so excited trying to ram the bayonet of defeat down the enemy's throat that he or she hit the "p" instead of the "o".

And thus history was made...

19 posted on 10/13/2020 7:09:53 PM PDT by kiryandil (Chris Wallace: Because someone has to drive the Clown Car)
[ Post Reply | Private Reply | To 14 | View Replies]

To: dayglored

I’m so glad I run Ubuntu ... Microsoft OS’ just aren’t worth the risk of running.


20 posted on 10/13/2020 7:10:39 PM PDT by usconservative (When The Ballot Box No Longer Counts, The Ammunition Box Does. (What's In Your Ammo Box?))
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-40 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson