-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
                         AUSCERT Security Bulletin

                               ASB-2018.0232
             Security updates for Microsoft Development Tools
                              10 October 2018

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:              .NET Core
                      Azure IoT Edge
                      ChakraCore
                      Hub Device Client SDK for Azure IoT
                      PowerShell Core
                      SQL Server Management Studio
Operating System:     Windows
                      Linux variants
Impact/Access:        Execute Arbitrary Code/Commands -- Remote with User Interaction
                      Access Confidential Data        -- Remote/Unauthenticated      
Resolution:           Patch/Upgrade
CVE Names:            CVE-2018-8533 CVE-2018-8532 CVE-2018-8531
                      CVE-2018-8527 CVE-2018-8513 CVE-2018-8511
                      CVE-2018-8510 CVE-2018-8505 CVE-2018-8503
                      CVE-2018-8500 CVE-2018-8473 CVE-2018-8292
Member content until: Friday, November  9 2018

OVERVIEW

        Microsoft has released its monthly security patch update for the month 
        of October 2018. This update resolves 12 vulnerabilities across the 
        following products: [1]
        
         .NET Core 1.0
         .NET Core 1.1
         .NET Core 2.1
         Azure IoT Edge
         ChakraCore
         Hub Device Client SDK for Azure IoT
         PowerShell Core 6.0
         SQL Server Management Studio 17.9
         SQL Server Management Studio 18.0 (Preview 4)


IMPACT

        Microsoft has given the following details regarding these 
        vulnerabilities.
        
        "Details         Impact                   Severity
         CVE-2018-8292   Information Disclosure   Important
         CVE-2018-8473   Remote Code Execution    Critical
         CVE-2018-8500   Remote Code Execution    Critical
         CVE-2018-8503   Remote Code Execution    Low
         CVE-2018-8505   Remote Code Execution    Critical
         CVE-2018-8510   Remote Code Execution    Critical
         CVE-2018-8511   Remote Code Execution    Critical
         CVE-2018-8513   Remote Code Execution    Critical
         CVE-2018-8527   Information Disclosure   Important
         CVE-2018-8531   Information Disclosure   Important
         CVE-2018-8532   Information Disclosure   Important
         CVE-2018-8533   Information Disclosure   Moderate" [1]


MITIGATION

        Microsoft recommends updating the software with the information 
        found from sources.
        
        Microsoft Security Advisory CVE-2018-8292: 
         .NET Core Information Disclosure Vulnerability #88 [2]
        
        Microsoft Security Advisory CVE-2018-8292 - 
         .NET Core Information Disclosure Vulnerability #7 [3]
        
        ChakraCore Roadmap [4]
        
        Download SQL Server Management Studio (SSMS) [5]
        
        SSMS 18.0 (preview 4) [6]
        
        Microsoft Azure IoT Hub SDK for C# Release 2018-10-9 [7]
        
        Update the IoT Edge runtime [8]


REFERENCES

        [1] Security Update Guide
            https://portal.msrc.microsoft.com/en-us/security-guidance

        [2] Microsoft Security Advisory CVE-2018-8292
            https://github.com/dotnet/announcements/issues/88

        [3] Microsoft Security Advisory CVE-2018-8292 - .NET Core Information
            Disclosure Vulnerability #7
            https://github.com/PowerShell/Announcements/issues/7

        [4] ChakraCore Roadmap
            https://github.com/Microsoft/ChakraCore/wiki/Roadmap#v

        [5] Download SQL Server Management Studio (SSMS)
            https://docs.microsoft.com/en-us/sql/ssms/download-sql-server-management-studio-ssms?view=sql-server-2017

        [6] SSMS 18.0 (preview 4)
            https://docs.microsoft.com/en-us/sql/ssms/sql-server-management-studio-changelog-ssms?view=sql-server-2017#ssms-180-preview-4download-sql-server-management-studio-ssmsmd

        [7] Microsoft Azure IoT Hub SDK for C# Release 2018-10-9
            https://github.com/Azure/azure-iot-sdk-csharp/releases/tag/2018-10-9

        [8] Update the IoT Edge runtime
            https://docs.microsoft.com/en-us/azure/iot-edge/how-to-update-iot-edge

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours 
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBW71eB2aOgq3Tt24GAQjoIg//QakRYm4/nLv2l2DNjqHK2ezeRlFTmNql
eNlWRYU9C7sRWld+x2eiVNdMtNJrzuutJxL1xnll+026WN2MriXolF9MpILfkUh0
dwEJ/cxheY4c0z47zzJ4A3L6na6WXkaLQUNeZDxuXhUj9gic7nt36fLZTnN1HnKj
G2xhlVxW6sLjjKkobsS7PY4gTyGliAcgk8od5rxuMUyKHHa9+qjlkxGb0CKTfKEu
5631/r+BOaUJiqqjBidbxY2qwa7XsiS1XjTRuGZpA2t7YxVrmCjMZQGO6+VWVvDz
VxRH0lqudF78WSIA5LzPhohYazL4+puAqar9Crl4YF9AZ4QspOUkGQ5te5+yj4/C
HXY+XME3LSdoQIjFr+K1bU/kT7lhkj15Ieu2hhTImZ84JhukJ0b923ky6DLjbAPE
zDIQI6Rlt+CWKToM52OqZNzbuldyGyrPGPwU1EZRHntp5iDrwh4ZkQ5HD6huD4xl
YLxHaVjgufGpvXALNZi0pf7AgWTZxFv3Q7VhGcZEFUis7/exo24SDshDf5kGaEVc
avvoSKKnSrcfAvXxSOxE3u6MndK71EM9KAPoouaYORHTFj8qsdI6MCjELK1DeUQ5
k3aXExAkj99CEFJe1j7HlMeYuDTGAvADpD7Kp8AzjZ2zoVF+7nT1Cq1xFw7B4cCr
V+hf3k7KVS0=
=dLV0
-----END PGP SIGNATURE-----