{"id":12434,"date":"2019-12-24T00:07:00","date_gmt":"2019-12-23T23:07:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=12434"},"modified":"2019-12-24T07:26:40","modified_gmt":"2019-12-24T06:26:40","slug":"microsoft-security-advisories-17-dez-2019","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2019\/12\/24\/microsoft-security-advisories-17-dez-2019\/","title":{"rendered":"Microsoft Security Advisories Dez. 17, 2019"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" height=\"47\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2019\/12\/23\/microsoft-security-advisories-17-dez-2019\/\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]Microsoft issued two security advisories on December 17, 2019, which warn of vulnerabilities in SharePoint Server and refer to LDAP Channel Binding and LDAP Signing.<\/p>\n<p><!--more--><\/p>\n<h2>Microsoft SharePoint Server CVE-2019-1491<\/h2>\n<p>An information disclosure vulnerability exists in Microsoft SharePoint, <a href=\"https:\/\/www.us-cert.gov\/ncas\/current-activity\/2019\/12\/18\/microsoft-releases-information-cve-2019-1491\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2019-1491<\/a>, that has allowed hackers to obtain sensitive information. An attacker who exploited this vulnerability could read arbitrary files on the server. To exploit the vulnerability, an attacker would have to send a specially crafted request to a vulnerable SharePoint Server instance.<\/p>\n<p>Microsoft has released a patch as part of the <a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2019-Dec\" target=\"_blank\" rel=\"noopener noreferrer\">December 2019 Security Updates<\/a>. The update addresses the vulnerability by modifying the way requests are processed by the affected APIs. In the Security Advisory dated December 17, 2019, it is announced that the CVE has undergone a major revision.<\/p>\n<p>* <a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/CVE-2019-1491\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2019-1491<\/a> Revision Information:<br \/>\nMicrosoft SharePoint Server Information Disclosure Vulnerability<br \/>\n&#8211; Version: 1.0<br \/>\n&#8211; Reason for Revision: Information published.<\/p>\n<p>This CVE was added to this month's security updates. This is just an information change. Customers who have successfully installed the appropriate updates do not need to take any further action.<\/p>\n<h2>Security Advisories ADV190023 December 17, 2019<\/h2>\n<p>Microsoft has also released the Security Advisory ADV190023 with instructions for enabling LDAP channel binding and LDAP signature:<\/p>\n<p>* Microsoft Security Advisory <a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/ADV190023\" target=\"_blank\" rel=\"noopener noreferrer\">ADV190023<\/a><br \/>\n&#8211; Microsoft Guidance for Enabling LDAP Channel Binding and LDAP Signing<br \/>\n&#8211; Reason for Revision: In the Recommended Actions section, updated the opening<br \/>\nsentence to indicate that the Windows update will be available in March 2020.<br \/>\n&#8211; Originally posted: August 13, 2019<br \/>\n&#8211; Updated: December 17, 2019<br \/>\n&#8211; Version: 1.2<\/p>\n<p>Details can be found in the very extensive Microsoft document <a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/ADV190023\" target=\"_blank\" rel=\"noopener noreferrer\">ADV190023<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Microsoft issued two security advisories on December 17, 2019, which warn of vulnerabilities in SharePoint Server and refer to LDAP Channel Binding and LDAP Signing.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580],"tags":[69],"class_list":["post-12434","post","type-post","status-publish","format-standard","hentry","category-security","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/12434","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=12434"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/12434\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=12434"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=12434"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=12434"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}