Zero-Day Coverage Update – Week of July 16, 2018

Credit to Author: Elisa Lippincott (Global Threat Communications)| Date: Fri, 20 Jul 2018 15:24:42 +0000

One night this week, I came across one of my favorite movies Willy Wonka and the Chocolate Factory. The world had gone crazy after the reclusive Willy Wonka announces that he has hidden five golden tickets in chocolate Wonka Bars that promised a factory tour and a lifetime supply of chocolate. There’s a scene at a school where a teacher, Mr. Turkentine, decides to teach the kids about percentages and uses the Wonka Bars as an example. He asks one student how many Wonka Bars she bought and she replied, “About a hundred.” Mr. Turkentine tells her that there are ten hundreds in a thousand so that’s 10 percent. He asks a couple of other students and the percentages are easy to figure out. Then he asks Charlie Bucket, a poor paperboy, how many Wonka Bars he bought, and he says “Two.” Mr. Turkentine replied, “Two? What do you mean you only opened two? I can’t figure out the percentage for just two, so let’s just pretend you opened two hundred.”

While Mr. Turkentine has trouble with percentages, the Zero Day Initiative (ZDI) doesn’t. This month, Adobe had a bigger than normal patch for their Acrobat product, covering 107 CVEs. 68 of those CVEs came through the ZDI program! I don’t have any trouble figuring out that percentage – that’s 63.6% of the Acrobat vulnerabilities that came through ZDI. The “golden ticket” for Trend Micro customers isn’t a lifetime of chocolate, but preemptive protection against these bugs!

MindshaRE: An Introduction to PyKD

Earlier this week, ZDI researcher Abdul-Aziz Hariri posted a blog covering the topic of using PyKD to help automate debugging tasks and crash dump analysis using Python. His post is part of the MindshaRE blog series that provides insight on various reversing techniques to security researchers and reverse engineers. The blog demonstrates the installation and basic configuration of PyKD and goes on the show how it can be used to execute Python script from inside WinDBG. You can read the full blog here.

Adobe Security Update

This week’s Digital Vaccine (DV) package includes coverage for Adobe updates released on or before July 10, 2018. The following table maps Digital Vaccine filters to the Microsoft updates. You can get more detailed information on this month’s security updates from Dustin Childs’ July 2018 Security Update Review from the Zero Day Initiative:

Bulletin #CVE #Digital Vaccine FilterStatus
APSB18-21CVE-2018-500932561
APSB18-21CVE-2018-501032562
APSB18-21CVE-2018-501132563
APSB18-21CVE-2018-501232564
APSB18-21CVE-2018-1279932670
APSB18-21CVE-2018-1280332565
APSB18-21CVE-2018-501432566
APSB18-21CVE-2018-501532567
APSB18-21CVE-2018-501632568
APSB18-21CVE-2018-501732569
APSB18-21CVE-2018-501832570
APSB18-21CVE-2018-501932571
APSB18-21CVE-2018-502032573
APSB18-21CVE-2018-502132574
APSB18-21CVE-2018-502232575
APSB18-21CVE-2018-502332576
APSB18-21CVE-2018-502432577
APSB18-21CVE-2018-502532578
APSB18-21CVE-2018-502632579
APSB18-21CVE-2018-502732580
APSB18-21CVE-2018-502832581
APSB18-21CVE-2018-502932582
APSB18-21CVE-2018-503032583
APSB18-21CVE-2018-503132584
APSB18-21CVE-2018-503232585
APSB18-21CVE-2018-503332586
APSB18-21CVE-2018-503432587
APSB18-21CVE-2018-503532588
APSB18-21CVE-2018-503632589
APSB18-21CVE-2018-503732590
APSB18-21CVE-2018-503832591
APSB18-21CVE-2018-503932592
APSB18-21CVE-2018-504032593
APSB18-21CVE-2018-504132594
APSB18-21CVE-2018-504232595
APSB18-21CVE-2018-504332596
APSB18-21CVE-2018-504432597
APSB18-21CVE-2018-504532598
APSB18-21CVE-2018-504632599
APSB18-21CVE-2018-504732600
APSB18-21CVE-2018-504832601
APSB18-21CVE-2018-504932602
APSB18-21CVE-2018-505032603
APSB18-21CVE-2018-505132604
APSB18-21CVE-2018-505232605
APSB18-21CVE-2018-505332606
APSB18-21CVE-2018-505432607
APSB18-21CVE-2018-505532608
APSB18-21CVE-2018-505632609
APSB18-21CVE-2018-505732610
APSB18-21CVE-2018-505832611
APSB18-21CVE-2018-505932612
APSB18-21CVE-2018-506032613
APSB18-21CVE-2018-506132614
APSB18-21CVE-2018-506232615
APSB18-21CVE-2018-506332616
APSB18-21CVE-2018-506432617
APSB18-21CVE-2018-506532618
APSB18-21CVE-2018-506632619
APSB18-21CVE-2018-506732620
APSB18-21CVE-2018-506832621
APSB18-21CVE-2018-506932622
APSB18-21CVE-2018-507032623
APSB18-21CVE-2018-1275432624
APSB18-21CVE-2018-1275532625
APSB18-21CVE-2018-1275632626
APSB18-21CVE-2018-1275732627
APSB18-21CVE-2018-1275832628
APSB18-21CVE-2018-1276032629
APSB18-21CVE-2018-1276132630
APSB18-21CVE-2018-1276232631
APSB18-21CVE-2018-1276332632
APSB18-21CVE-2018-1276432633
APSB18-21CVE-2018-1276532634
APSB18-21CVE-2018-1276632635
APSB18-21CVE-2018-1276732636
APSB18-21CVE-2018-1276832637
APSB18-21CVE-2018-1277032638
APSB18-21CVE-2018-1277132639
APSB18-21CVE-2018-1277232640
APSB18-21CVE-2018-1277332641
APSB18-21CVE-2018-1277432642
APSB18-21CVE-2018-1277632643
APSB18-21CVE-2018-1277732644
APSB18-21CVE-2018-1277932645
APSB18-21CVE-2018-1278032646
APSB18-21CVE-2018-1278132647
APSB18-21CVE-2018-1278232648
APSB18-21CVE-2018-1278332649
APSB18-21CVE-2018-12784Vendor Deemed Reproducibility or Exploitation Unlikely
APSB18-21CVE-2018-1278532650
APSB18-21CVE-2018-1278632651
APSB18-21CVE-2018-1278732652
APSB18-21CVE-2018-1278832653
APSB18-21CVE-2018-1278932654
APSB18-21CVE-2018-1279032655
APSB18-21CVE-2018-1279132656
APSB18-21CVE-2018-1279232657
APSB18-21CVE-2018-12802Vendor Deemed Reproducibility or Exploitation Unlikely
APSB18-21CVE-2018-1279332658
APSB18-21CVE-2018-1279432659
APSB18-21CVE-2018-1279532660
APSB18-21CVE-2018-1279632661
APSB18-21CVE-2018-1279732662
APSB18-21CVE-2018-1279832663
APSB18-24CVE-2018-500732559
APSB18-24CVE-2018-500832560

 

Zero-Day Filters

There are no new zero-day filters in this week’s Digital Vaccine (DV) package. A number of existing filters in this week’s DV package were modified to update the filter description, update specific filter deployment recommendation, increase filter accuracy and/or optimize performance. You can browse the list of published advisories and upcoming advisories on the Zero Day Initiative website. You can also follow the Zero Day Initiative on Twitter @thezdi and on their blog.

Missed Last Week’s News?

Catch up on last week’s news in my weekly recap.

The post Zero-Day Coverage Update – Week of July 16, 2018 appeared first on .

http://feeds.trendmicro.com/TrendMicroSimplySecurity