Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT Security Bulletin ASB-2019.0345 Security update for Microsoft developer tools 11 December 2019 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Microsoft developer tools Operating System: Windows Android Impact/Access: Execute Arbitrary Code/Commands -- Remote with User Interaction Create Arbitrary Files -- Remote with User Interaction Provide Misleading Information -- Remote with User Interaction Access Confidential Data -- Unknown/Unspecified Resolution: Patch/Upgrade CVE Names: CVE-2019-1487 CVE-2019-1486 CVE-2019-1387 CVE-2019-1354 CVE-2019-1352 CVE-2019-1351 CVE-2019-1350 CVE-2019-1349 Member content until: Friday, January 10 2020 OVERVIEW Microsoft has released its monthly security patch update for the month of December 2019. This update resolves 8 vulnerabilities across the following products: [1] Microsoft Authentication Library (MSAL) for Android Microsoft Visual Studio 2017 version 15.0 Microsoft Visual Studio 2017 version 15.9 (includes 15.1 - 15.8) Microsoft Visual Studio 2017 version 16.0 Microsoft Visual Studio 2019 version 16.0 Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3) Microsoft Visual Studio Live Share extension IMPACT Microsoft has given the following details regarding these vulnerabilities. Details Impact Severity CVE-2019-1349 Remote Code Execution Critical CVE-2019-1350 Remote Code Execution Critical CVE-2019-1351 Tampering Moderate CVE-2019-1352 Remote Code Execution Critical CVE-2019-1354 Remote Code Execution Critical CVE-2019-1387 Remote Code Execution Critical CVE-2019-1486 Spoofing Important CVE-2019-1487 Information Disclosure Important MITIGATION Microsoft recommends updating the software with the version made available on the Microsoft Update Catalogue. [1] REFERENCES [1] Security Update Guide https://portal.msrc.microsoft.com/en-us/security-guidance AusCERT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBXfCM22aOgq3Tt24GAQj2wA/+IUd3j0SPdMLr/Ac4jKIHWL0biCyZUP66 WOW+7dNFSpzg883x6POlLLs6JOSrKR1U/H3nilCLBVLehDjissePMwn1as3szcYn hz2SDkNURVXRVKehHhVStEHNeWodfkDdDR4K9MY+8cuhKQTDPSKAEh1hlb9i/k1x zRMApVJITc/jv600eiT6crW7tMzTU2gQ2nyY5q+vUWNPPkGBpHSZn6ZiQ0eiBmOr Ip+5vhQlpT6LmmTDy+ij8jTLkaMgsaDmvb0P6q6kvHVGLrS4I9IzwvOAtscT7IPS +ercJpnNGqx6aZ+Qez6rCH3SQSpsfaLjSYov+VFPzhP8TNoRmmDt+DbJiaF17SAa RrCRorjMC1gajUev1NRLMv3ECkrPQXg9wfu/J6RYrKvfEQuAml3nJ+n8MOjtF7PT eyIoxCYoSfMMvvOvRPXQ4CYLrnOJCzgLjgRV4XTKtZK/nnzIRqGNVpQEY8waCNUT VKWh8JrnIXXG79mriKgjK9wDoul7y0IcBOqjS+oZ68MsmgToU+NjzpHN24vNPxGN iatx9gW+4VD4InajsnjGwxVeiwz6WA/aBAnkX+zqw/7/U4zedPKn60Vk+vp19YGC AAEfvgPasheQzek+7++odAsQ/7ZjELxxeu3qvZSI1JSIIML8/J02uEl/Qs0p9ydl COQIfsgnWEs= =Gjib -----END PGP SIGNATURE-----