{"id":12793,"date":"2018-07-13T07:00:10","date_gmt":"2018-07-13T15:00:10","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/07\/13\/news-6561\/"},"modified":"2018-07-13T07:00:10","modified_gmt":"2018-07-13T15:00:10","slug":"news-6561","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/07\/13\/news-6561\/","title":{"rendered":"Zero-Day Coverage Update \u2013 Week of July 9, 2018"},"content":{"rendered":"<p><strong>Credit to Author: Elisa Lippincott (Global Threat Communications)| Date: Fri, 13 Jul 2018 14:10:20 +0000<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"225\" src=\"https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/07\/0-day-graphic-large-300x225.png\" class=\"webfeedsFeaturedVisual wp-post-image\" alt=\"\" style=\"float: left; margin-right: 5px;\" srcset=\"https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/07\/0-day-graphic-large-300x225.png 300w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/07\/0-day-graphic-large.png 305w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>Earlier this week, I wrote a <a href=\"https:\/\/blog.trendmicro.com\/zero-day-initiative-a-1h2018-recap\/\">blog<\/a> covering a couple of the statistics from the Zero Day Initiative\u2019s (ZDI) first half of 2018. One of the stats that I didn\u2019t cover is the increasing focus on enterprise applications. The team is seeing consistent growth in submissions of Microsoft and Apple vulnerabilities, but now they\u2019re also seeing an increase of submissions in virtualization software vulnerabilities from the likes of VMware and Oracle. With a 33% increase in published advisories compared to 2017, the ZDI has their hands full. With more than 500 new researchers registering to participate in the program this year, the internal ZDI team is growing as well to accommodate this growth. 2018 may just be the biggest year yet for ZDI!<\/p>\n<p>In case you missed it, you can read Brian Gorenc\u2019s <a href=\"https:\/\/www.thezdi.com\/blog\/2018\/7\/9\/checking-in-a-look-back-at-the-first-half-of-2018\">blog<\/a> covering the detailed stats from the ZDI\u2019s first half of 2018.<\/p>\n<p><strong>Microsoft Security Updates<\/strong><\/p>\n<p>This week\u2019s Digital Vaccine\u00ae (DV) package includes coverage for Microsoft updates released on or before July 10, 2018. It was another big month for Microsoft with 53 security patches covering both browsers (Internet Explorer, Edge), ChakraCore, Windows, .NET Framework, ASP.NET, PowerShell, Visual Studio, and Microsoft Office and Office Services. Of these 53 CVEs, 18 are listed as Critical, 33 are rated Important, one is rated as Moderate, and one is rated as Low in severity.<\/p>\n<p>Five CVEs in this month\u2019s Microsoft update came through the Zero Day Initiative:<\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"20px\"><\/td>\n<td>\n<ul>\n<li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2018-8242\">CVE-2018-8242<\/a><\/li>\n<li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2018-8274\">CVE-2018-8274<\/a><\/li>\n<li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2018-8275\">CVE-2018-8275<\/a><\/li>\n<li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2018-8282\">CVE-2018-8282<\/a><\/li>\n<li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2018-8307\">CVE-2018-8307<\/a><\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td height=\"10px\"><\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The following table maps Digital Vaccine filters to Microsoft\u2019s updates. You can get more detailed information on this month\u2019s security updates from Dustin Childs\u2019 <a href=\"https:\/\/www.zerodayinitiative.com\/blog\/2018\/7\/10\/the-july-2018-security-update-review\">July 2018 Security Update Review<\/a> from the Zero Day Initiative:<\/p>\n<div class=\"lightTable\">\n<table width=\"0\">\n<tbody>\n<tr>\n<td width=\"120\"><strong>CVE #<\/strong><\/td>\n<td width=\"162\"><strong>Digital Vaccine Filter #<\/strong><\/td>\n<td width=\"354\"><strong>Status<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-0949<\/td>\n<td width=\"162\">32494<\/td>\n<td width=\"354\"><\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8125<\/td>\n<td width=\"162\">32486<\/td>\n<td width=\"354\"><\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8171<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8172<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8202<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8206<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8222<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8232<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8238<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8242<\/td>\n<td width=\"162\">32487<\/td>\n<td width=\"354\"><\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8260<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8262<\/td>\n<td width=\"162\">32491<\/td>\n<td width=\"354\"><\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8274<\/td>\n<td width=\"162\">32492<\/td>\n<td width=\"354\"><\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8275<\/td>\n<td width=\"162\">32493<\/td>\n<td width=\"354\"><\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8276<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8278<\/td>\n<td width=\"162\">32358<\/td>\n<td width=\"354\"><\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8279<\/td>\n<td width=\"162\">32359<\/td>\n<td width=\"354\"><\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8280<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8281<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8282<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8283<\/td>\n<td width=\"162\">32361<\/td>\n<td width=\"354\"><\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8284<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8286<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8287<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8288<\/td>\n<td width=\"162\">32488<\/td>\n<td width=\"354\"><\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8289<\/td>\n<td width=\"162\">32490<\/td>\n<td width=\"354\"><\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8290<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8291<\/td>\n<td width=\"162\">32360<\/td>\n<td width=\"354\"><\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8294<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8296<\/td>\n<td width=\"162\">32478<\/td>\n<td width=\"354\"><\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8297<\/td>\n<td width=\"162\">32551<\/td>\n<td width=\"354\"><\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8298<\/td>\n<td width=\"162\">32479<\/td>\n<td width=\"354\"><\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8299<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8300<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8301<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8304<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8305<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8306<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8307<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8308<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8309<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8310<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8311<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8312<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8313<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8314<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8319<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8323<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8324<\/td>\n<td width=\"162\">32558<\/td>\n<td width=\"354\"><\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8325<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8326<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8327<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">CVE-2018-8356<\/td>\n<td width=\"162\"><\/td>\n<td width=\"354\">Vendor Deemed Reproducibility or Exploitation Unlikely<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<p>&nbsp;<\/p>\n<p><strong>Zero-Day Filters<\/strong><\/p>\n<p>There is one new zero-day filter covering one vendor in this week\u2019s Digital Vaccine (DV) package. A number of existing filters in this week\u2019s DV package were modified to update the filter description, update specific filter deployment recommendation, increase filter accuracy and\/or optimize performance. You can browse the list of <a href=\"http:\/\/www.zerodayinitiative.com\/advisories\/published\/\">published advisories<\/a> and <a href=\"http:\/\/www.zerodayinitiative.com\/advisories\/upcoming\/\">upcoming advisories<\/a> on the <a href=\"http:\/\/www.zerodayinitiative.com\/\">Zero Day Initiative<\/a> website. You can also follow the Zero Day Initiative on Twitter <a href=\"https:\/\/twitter.com\/thezdi\">@thezdi<\/a> and on their <a href=\"https:\/\/www.zerodayinitiative.com\/blog\">blog<\/a>.<\/p>\n<p><strong><em>Advantech (1)<\/em><\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"20px\"><\/td>\n<td>\n<ul>\n<li>32341: RPC: Advantech Webaccess webvrpcs Directory Traversal Vulnerability (ZDI-18-024)<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td height=\"10px\"><\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>Missed Last Week\u2019s News?<\/strong><\/p>\n<p>Catch up on last week\u2019s news in my <a href=\"https:\/\/blog.trendmicro.com\/zero-day-coverage-update-week-of-july-2-2018\/\">weekly recap<\/a>.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.trendmicro.com\/zero-day-coverage-update-week-of-july-9-2018\/\">Zero-Day Coverage Update \u2013 Week of July 9, 2018<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.trendmicro.com\"><\/a>.<\/p>\n<p><a href=\"https:\/\/blog.trendmicro.com\/zero-day-coverage-update-week-of-july-9-2018\/\" target=\"bwo\" >http:\/\/feeds.trendmicro.com\/TrendMicroSimplySecurity<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Elisa Lippincott (Global Threat Communications)| Date: Fri, 13 Jul 2018 14:10:20 +0000<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"225\" src=\"https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/07\/0-day-graphic-large-300x225.png\" class=\"webfeedsFeaturedVisual wp-post-image\" alt=\"\" style=\"float: left; margin-right: 5px;\" srcset=\"https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/07\/0-day-graphic-large-300x225.png 300w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2018\/07\/0-day-graphic-large.png 305w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>Earlier this week, I wrote a blog covering a couple of the statistics from the Zero Day Initiative\u2019s (ZDI) first half of 2018. One of the stats that I didn\u2019t cover is the increasing focus on enterprise applications. The team is seeing consistent growth in submissions of Microsoft and Apple vulnerabilities, but now they\u2019re also&#8230;<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.trendmicro.com\/zero-day-coverage-update-week-of-july-9-2018\/\">Zero-Day Coverage Update \u2013 Week of July 9, 2018<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.trendmicro.com\"><\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10413],"tags":[18755,18255,10384,714,10415,18967],"class_list":["post-12793","post","type-post","status-publish","format-standard","hentry","category-security","category-trendmicro","tag-advantech","tag-digital-vaccine","tag-network","tag-security","tag-zero-day-initiative","tag-zero-day-coverage"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12793","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=12793"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12793\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=12793"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=12793"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=12793"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}