Posts

Microsoft Security Bulletin Coverage for December 2019

SonicWall Capture Labs Threat Research Team has analyzed and addressed Microsoft’s security advisories for the month of December 2019. A list of issues reported, along with SonicWall coverage information are as follows:

CVE-2019-1332 Microsoft SQL Server Reporting Services XSS Vulnerability
There are no known exploits in the wild.
CVE-2019-1349 Git for Visual Studio Remote Code Execution Vulnerability
There are no known exploits in the wild.
CVE-2019-1350 Git for Visual Studio Remote Code Execution Vulnerability
There are no known exploits in the wild.
CVE-2019-1351 Git for Visual Studio Tampering Vulnerability
There are no known exploits in the wild.
CVE-2019-1352 Git for Visual Studio Remote Code Execution Vulnerability
There are no known exploits in the wild.
CVE-2019-1354 Git for Visual Studio Remote Code Execution Vulnerability
There are no known exploits in the wild.
CVE-2019-1387 Git for Visual Studio Remote Code Execution Vulnerability
There are no known exploits in the wild.
CVE-2019-1400 Microsoft Access Information Disclosure Vulnerability
There are no known exploits in the wild.
CVE-2019-1453 Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability
There are no known exploits in the wild.
CVE-2019-1458 Win32k Elevation of Privilege Vulnerability
ASPY 5854:Malformed-File exe.MP.114
CVE-2019-1461 Microsoft Word Denial of Service Vulnerability
There are no known exploits in the wild.
CVE-2019-1462 Microsoft PowerPoint Remote Code Execution Vulnerability
There are no known exploits in the wild.
CVE-2019-1463 Microsoft Access Information Disclosure Vulnerability
There are no known exploits in the wild.
CVE-2019-1464 Microsoft Excel Information Disclosure Vulnerability
There are no known exploits in the wild.
CVE-2019-1465 Windows GDI Information Disclosure Vulnerability
There are no known exploits in the wild.
CVE-2019-1466 Windows GDI Information Disclosure Vulnerability
There are no known exploits in the wild.
CVE-2019-1467 Windows GDI Information Disclosure Vulnerability
There are no known exploits in the wild.
CVE-2019-1468 Win32k Graphics Remote Code Execution Vulnerability
There are no known exploits in the wild.
CVE-2019-1469 Win32k Information Disclosure Vulnerability
ASPY 5855:Malformed-File exe.MP.115
CVE-2019-1470 Windows Hyper-V Information Disclosure Vulnerability
There are no known exploits in the wild.
CVE-2019-1471 Windows Hyper-V Remote Code Execution Vulnerability
There are no known exploits in the wild.
CVE-2019-1472 Windows Kernel Information Disclosure Vulnerability
There are no known exploits in the wild.
CVE-2019-1474 Windows Kernel Information Disclosure Vulnerability
There are no known exploits in the wild.
CVE-2019-1476 Windows Elevation of Privilege Vulnerability
There are no known exploits in the wild.
CVE-2019-1477 Windows Printer Service Elevation of Privilege Vulnerability
There are no known exploits in the wild.
CVE-2019-1478 Windows COM Server Elevation of Privilege Vulnerability
There are no known exploits in the wild.
CVE-2019-1480 Windows Media Player Information Disclosure Vulnerability
There are no known exploits in the wild.
CVE-2019-1481 Windows Media Player Information Disclosure Vulnerability
There are no known exploits in the wild.
CVE-2019-1483 Windows Elevation of Privilege Vulnerability
There are no known exploits in the wild.
CVE-2019-1484 Windows OLE Remote Code Execution Vulnerability
There are no known exploits in the wild.
CVE-2019-1485 VBScript Remote Code Execution Vulnerability
ASPY 14631:VBScript Remote Code Execution Vulnerability (DEC 19) 1
CVE-2019-1486 Visual Studio Live Share Spoofing Vulnerability
There are no known exploits in the wild.
CVE-2019-1487 Microsoft Authentication Library for Android Information Disclosure Vulnerability
There are no known exploits in the wild.
CVE-2019-1488 Microsoft Defender Security Feature Bypass Vulnerability
There are no known exploits in the wild.
CVE-2019-1489 Remote Desktop Protocol Information Disclosure Vulnerability
There are no known exploits in the wild.
CVE-2019-1490 Skype for Business and Lync Spoofing Vulnerability
There are no known exploits in the wild.