Microsoft Patch Tuesday — Nov. 2019: Vulnerability disclosures and Snort coverage

Microsoft Patch Tuesday — Nov. 2019: Vulnerability disclosures and Snort coverage

By Jon Munshaw.

Microsoft released its monthly security update today, disclosing a variety of vulnerabilities in several of its products. The latest Patch Tuesday discloses 75 vulnerabilities, 13 of which are considered "critical," with the rest being deemed "important."

This month’s security update covers security issues in a variety of Microsoft services and software, including the Scripting Engine, the Windows Hyper-V hypervisor, and Win32. Cisco Talos discovered one of these vulnerabilities, CVE-2019-1448 —a remote code execution vulnerability in Microsoft Excel. For more on this bug, read our full Vulnerability Spotlight here. We are also disclosing a remote code execution vulnerability in Microsoft Media Foundation.

Talos also released a new set of SNORTⓇ rules that provide coverage for some of these vulnerabilities. For more, check out the Snort blog post here.

Critical vulnerabilities


Microsoft disclosed 13 critical vulnerabilities this month, nine of which we will highlight below.

CVE-2019-0721, CVE-2019-1389, CVE-2019-1397 and microsoft patch tuesday vulnerability disclosures snort coverage