-
Microsoft announced four security bulletins that address six vulnerabilities as part of the monthly security bulletin release on January 14th, 2014. A summary of these bulletins is on the Microsoft website at http://technet.microsoft.com/en-us/security/bulletin/ms14-jan. This document provides identification and mitigation techniques that administrators can deploy on Cisco network devices.
The vulnerabilities that have a client software attack vector, can be exploited locally on the vulnerable device, require user interaction, can be exploited using web-based attacks (these include but are not limited to cross-site scripting, phishing, and web-based email threats), email attachments, or files stored on network shares are in the following list:
The vulnerabilities that have a network mitigation are in the following list. Cisco devices provide one countermeasure for the vulnerabilities that have a network attack vector, which will be discussed in detail later in this document.
Information about affected and unaffected products is available in the respective Microsoft advisories and the Cisco Alerts that are referenced in Cisco Event Response: Microsoft Security Bulletin Release for January 2014.
In addition, multiple Cisco products use Microsoft operating systems as their base operating system. Cisco products that may be affected by the vulnerabilities described in the referenced Microsoft advisories are detailed in the "Associated Products" table in the "Product Sets" section.
-
MS14-001, Vulnerabilities in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (2916605): These vulnerabilities have been assigned Common Vulnerabilities and Exposures (CVE) identifiers CVE-2014-0258, CVE-2014-0259, and CVE-2014-0260. These vulnerabilities can be exploited remotely with authentication and require user interaction. Successful exploitation of the vulnerabilities that are associated with CVE-2014-0258, CVE-2014-0259, and CVE-2014-0260 may allow arbitrary code execution.
Due to the nature of the vulnerabilities, the only mitigation that will be provided will be via Cisco Sourcefire Next-Generation Intrusion Prevention System.
MS14-002, Vulnerability in Windows Kernel Could Allow Elevation of Privilege (2914368): This vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) identifier CVE-2013-5065. This vulnerability can be exploited locally with authentication and without user interaction. Successful exploitation of this vulnerability may allow an elevation of privilege.
Due to nature of the vulnerabilities, the only mitigation that will be provided will be via Cisco Sourcefire Next-Generation Intrusion Prevention System.
-
Information about vulnerable, unaffected, and fixed software is available in the Microsoft Security Bulletin Summary for January 2014, which is available at the following link: http://www.microsoft.com/technet/security/bulletin/ms14-jan.mspx
-
The vulnerabilities that have a client software attack vector, can be exploited locally on the vulnerable device, require user interaction, can be exploited using web-based attacks (these include but are not limited to cross-site scripting, phishing, and web-based email threats), email attachments, or files stored on network shares are in the following list:
These vulnerabilities are mitigated most successfully at the endpoint through software updates, user education, desktop administration best practices, and endpoint protection software such as Host Intrusion Prevention Systems (HIPS) or antivirus products.
The vulnerabilities that have a network mitigation are in the following list. Cisco devices provide several countermeasures for these vulnerabilities. This section of the document provides an overview of these techniques.
Effective use of Cisco Sourcefire Next Generation IPS provides visibility into and protection against attacks that attempt to exploit these vulnerabilities as discussed later in this document.
-
Organizations are advised to follow their standard risk evaluation and mitigation processes to determine the potential impact of these vulnerabilities. Triage refers to sorting projects and prioritizing efforts that are most likely to be successful. Cisco has provided documents that can help organizations develop a risk-based triage capability for their information security teams. Risk Triage for Security Vulnerability Announcements and Risk Triage and Prototyping can help organizations develop repeatable security evaluation and response processes.
-
Caution: The effectiveness of any mitigation technique depends on specific customer situations such as product mix, network topology, traffic behavior, and organizational mission. As with any configuration change, evaluate the impact of this configuration prior to applying the change.
Specific information about mitigation and identification is available for the Sourcefire Intrusion Prevention System.
Sourcefire Intrusion Prevention System
Sourcefire Signature Identification
The following Sourcefire Snort signatures are available for the Microsoft January 2014 Security Update.
Microsoft Advisory ID Microsoft Advisory Name CVE(s) Applicable Rules MS14-001 Vulnerabilities in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (2916605) CVE-2014-0258, CVE-2014-0259, CVE-2014-0260 1:28847, 1:28848, 1:28879 MS14-002 Vulnerability in Windows Kernel May Allow Elevation of Privilege (2914368) CVE-2013-5065 1:28867, 1:28868, 1:28869, 1:28870, 1:28871, 1:28872
-
THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.
-
Version Description Section Date 1 Initial Release 2014-January-14 18:22 GMT
-
Complete information on reporting security vulnerabilities in Cisco products, obtaining assistance with security incidents, and registering to receive security information from Cisco, is available on Cisco's worldwide website at https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html. This includes instructions for press inquiries regarding Cisco security notices. All Cisco security advisories are available at http://www.cisco.com/go/psirt.
-
The security vulnerability applies to the following combinations of products.
Primary Products Microsoft, Inc. Office 2003 (SP3) | 2007 (SP3) | 2010 (SP1, SP2) | 2013 (32-bit editions, 64-bit editions) | 2013 RT (Base) Office Compatibility Pack SP3 (Base) Office SharePoint Server 2010 (SP1, SP2) | 2013 (Base) Windows 7 for 32-bit systems (SP1) | for x64-based systems (SP1) Windows Server 2003 Datacenter Edition (SP2) | Datacenter Edition, 64-bit (Itanium) (SP2) | Datacenter Edition x64 (AMD/EM64T) (SP2) | Enterprise Edition (SP2) | Enterprise Edition, 64-bit (Itanium) (SP2) | Enterprise Edition x64 (AMD/EM64T) (SP2) | Standard Edition (SP2) | Standard Edition, 64-bit (Itanium) (SP2) | Standard Edition x64 (AMD/EM64T) (SP2) | Web Edition (SP2) Windows Server 2008 R2 x64-Based Systems Edition (SP1) | Itanium-Based Systems Edition (SP1) Word 2003 (SP3) | 2007 (SP3) | 2010 (32-bit Edition, 64-bit Edition, SP1, SP2) | 2013 (RT, 32-bit editions, 64-bit editions) Word Viewer Original Release (Base) Office Web Apps 2010 (SP1, SP2) | 2013 (Base) Dynamics AX 4.0 (SP2) | 2009 (SP1) | 2012 (Base) | 2012 R2 (Base) Word Automation Services 2010 (Base) | 2013 (Base)
Associated Products Cisco Cisco Broadband Troubleshooter Original Release (Base) | 3.1 (Base) | 3.2 (Base) Cisco Building Broadband Service Manager (BBSM) Original Release (Base) | 2.5 (.1) | 3.0 (Base) | 4.0 (Base, .1) | 4.2 (Base) | 4.3 (Base) | 4.4 (Base) | 4.5 (Base) | 5.0 (Base) | 5.1 (Base) | 5.2 (Base) Cisco CNS Network Registrar 2.5 (Base) | 3.0 (Base) | 3.5 (Base, .1) | 5.0 (Base) | 5.5 (Base, .13) | 6.0 (.5, .5.2, .5.3, .5.4) | 6.1 (Base, .1, .1.1, .1.2, .1.3, .1.4) Cisco Collaboration Server Dynamic Content Adapter (DCA) Original Release (Base) | 1.0 (Base) | 2.0 (Base, (1)_SR2) Cisco Computer Telephony Integration (CTI) Option 4.7 ((0)_SR1, (0)_SR2, (0)_SR3, (0)_SR4) | 5.1 ((0)_SR1, (0)_SR2, (0)_SR3) | 6.0 ((0)_SR1, (0)_SR2, (0)_SR3, (0)_SR4, (0)_SR5) | 7.0 ((0)_SR1, (0)_SR2) | 7.1 ((2), (3), (4), (5)) Cisco Conference Connection 1.1 ((3), (3)spA) | 1.2 (Base, (1), (2), (2)SR1, (2)SR2) Cisco E-mail Manager Original Release (Base) | 4.0 (Base, .5i, .6) | 5.0 (Base, (0)_SR1, (0)_SR3, (0)_SR4, (0)_SR5, (0)_SR6, (0)_SR7) Cisco Emergency Responder 1.1 (Base, (3), (4)) | 1.2 (Base, (1), (1)SR1, (2), (2)sr1, (3)a, (3)SR1, (3a)SR2) | 1.3 (Base, (1a), (2)) Cisco Intelligent Contact Manager (ICM) Original Release (Base) | 4.6 ((2)_SR1, (2)_SR2, (2)_SR3, (2)_SR4, (2)_SR5, (2)_SR6) | 5.0 ((0), (0)_SR2, (0)_SR3, (0)_SR4, (0)_SR5, (0)_SR7, (0)_SR8, (0)_SR9, (0)_SR10, (0)_SR11, (0)_SR12, (0)_SR13) | 6.0 ((0)_SR1, (0)_SR2, (0)_SR3, (0)_SR4, (0)_SR5, (0)_SR6, (0)_SR7, (0)_SR8, (0)_SR9, (0)_SR10) | 7.0 ((0)_SR1, (0)_SR2, (0)_SR3, (0)_SR4) | 7.1 ((2), (3), (4), (5)) Cisco Unified Contact Center Enterprise Edition (Base, 4.6.2, 5.0, 6.0, 7.0, 7.1, 7.1.1, 7.1.3) | Express Edition (Base, 2.0, 2.0.2, 2.1, 2.1.1a, 2.1.2, 2.1.3, 2.2, 2.2.1, 2.2.2, 2.2.3b, 2.2.3b_spE, 3.0, 3.0.2, 3.0.3a_spA, 3.0.3a_spB, 3.0.3a_spC, 3.0.3a_spD, 3.1, 3.1(1)_SR1, 3.1(1)_SR2, 3.1(2)_SR1, 3.1(2)_SR2, 3.1(2)_SR3, 3.1(2)_SR4, 3.1(3)_SR2, 3.1(3)_SR3, 3.1(3)_SR4, 3.1(3)_SR5, 3.5, 3.5.1, 3.5(1)_SR1, 3.5(2)_SR1, 3.5(3), 3.5(3)_SR1, 3.5(3)_SR2, 3.5(3)_SR3, 3.5(4)_SR1, 3.5(4)_SR2, 4.0, 4.0(1)_SR1, 4.0(4)_SR1, 4.0(5)_SR1, 4.1, 4.1(1)_SR1, 4.5, 4.5(2)_SR1, 4.5(2)_SR2, 5.0(1)_SR1) | Hosted Edition (Base, 4.6.2, 5.0, 6.0, 7.0, 7.1, 7.1.1, 7.1.3) Cisco Unified IP IVR 2.0 (.2) | 2.1 (.1a, .2, .3) | 2.2 ((5), .1, .2, .3b, .3b_spE, .5, .4) | 3.0 (.1_spB, .2, .3a_spA, .3a_spB, .3a_spC, .3a_spD) | 3.1 ((1)_SR2, (2)_SR1, (2)_SR2, (2)_SR3, (3)_SR1, (3)_SR2, (3)_SR3, (3)_SR4, (3)_SR5) | 3.5 ((1)_SR1, (1)_SR2, (1)_SR3, (2)_SR1, (3)_SR1, (3)_SR2, (3)_SR3, (4)_SR1, (4)_SR2, .1, .3) | 4.0 ((1)_SR1, (4)_SR1) | 4.1 ((1)_SR1) | 4.5 ((2)_SR1, (2)_SR2) | 5.0 ((1)_SR1) Cisco IP Interoperability and Collaboration System (IPICS) 1.0 ((1.1)) Cisco IP Queue Manager 2.2 (Base) Cisco IP/VC 3540 Application Server Module 3.2 (.0.1, .138) | 3.5 (.0.8) Cisco IP/VC 3540 Rate Matching Module 3.0 (.9) Cisco Media Blender Original Release (Base) | 3.0 (Base) | 4.0 (Base) | 5.0 (Base, (0)_SR1, (0)_SR2) Cisco Networking Services for Active Directory Original Release (Base) Cisco Outbound Option Original Release (Base) Cisco Personal Assistant 1.0 (Base, (1)) | 1.1 (Base) | 1.3 (Base, .1, .2, .3, .4) | 1.4 (Base, .2, .3, .4, .5, .6) Cisco Remote Monitoring Suite Option 1.0 (Base) | 2.0 (Base, (0)_SR1) Cisco Secure Access Control Server (ACS) for Windows 2.6 (Base) | 2.6.3.2 (Base) | 2.6.4 (Base) | 2.6.4.4 (Base) | 3.0 (Base) | 3.0.1 (Base) | 3.0.1.40 (Base) | 3.0.2 (Base) | 3.0.3 (Base) | 3.0.3.6 (Base) | 3.0.4 (Base) | 3.1.1 (Base) | 3.1.1.27 (Base) | 3.1.2 (Base) | 3.2 (Base) | 3.2.1 (Base) | 3.2.3 (Base) | 3.3.1 (Base) | 3.3.2.2 (Base) | 3.3.1.16 (Base) | 3.3.3.11 (Base) | 4.0 (Base) | 4.0.1 (Base) | 4.0.1.27 (Base) | 4.1.1.23 (Base) Cisco Secure Access Control Server Solution Engine (ACSE) 3.1 (Base, .1) | 3.2 (Base, .1.20, .2.5, .3) | 3.3 (Base, .1, .1.16, .2.2, .3, .4, .4.12) | 4.0 (Base, .1, .1.42, .1.44, .1.49) | 4.1 (Base, .1.23, .1.23.3, .3, .3.12) Cisco Secure User Registration Tool (URT) Original Release (Base) | 1.2 (Base, .1) | 2.0 (Base, .7, .8) | 2.5 (Base, .1, .2, .3, .4, .5) Cisco SN 5420 Storage Router 1.1 (Base, .3, .4, .5, .7, .8) | 2.1 (.1, .2) Cisco SN 5428-2 Storage Router 3.2 (.1, .2) | 3.3 (.1, .2) | 3.4 (.1) | 3.5 (Base, .1, .2, .3, .4) Cisco Trailhead Original Release (Base) | 4.0 (Base) Cisco Unified Communications Manager Original Release (Base) | 1.0 (Base) | 2.0 (Base) | 3.0 (Base) | 3.0.3(a) (Base) | 3.1 (Base, .1, .2, .3a) | 3.1(1) (Base) | 3.1(2) (Base) | 3.1(2)SR3 (Base) | 3.1(3) (Base) | 3.1(3)SR2 (Base) | 3.1(3)SR4 (Base) | 3.2 (Base) | 3.2(3)SR3 (Base) | 3.3 (Base) | 3.3(2)SPc (Base) | 3.3(3) (Base) | 3.3(3)ES61 (Base) | 3.3(3)SR3 (Base) | 3.3(3)SR4a (Base) | 3.3(3a) (Base) | 3.3(4) (Base) | 3.3(4)ES25 (Base) | 3.3(4)SR2 (Base) | 3.3(4c) (Base) | 3.3(5) (Base) | 3.3(5)ES24 (Base) | 3.3(5)SR1 (Base) | 3.3(5)SR1a (Base) | 3.3(5)SR2 (Base) | 3.3(5)SR2a (Base) | 3.3(5)SR3 (Base) | 3.3(59) (Base) | 3.3(61) (Base) | 3.3(63) (Base) | 3.3(64) (Base) | 3.3(65) (Base) | 3.3(66) (Base) | 3.3(67.5) (Base) | 3.3(68.1) (Base) | 3.3(71.0) (Base) | 3.3(74.0) (Base) | 3.3(78) (Base) | 3.3(76) (Base) | 4.0 (.1, .2) | 4.0(2a)ES40 (Base) | 4.0(2a)ES56 (Base) | 4.0(2a)SR2b (Base) | 4.0(2a)SR2c (Base) | 4.1 (Base) | 4.1(2) (Base) | 4.1(2)ES33 (Base) | 4.1(2)ES50 (Base) | 4.1(2)SR1 (Base) | 4.1(3) (Base) | 4.1(3)ES (Base) | 4.1(3)ES07 (Base) | 4.1(3)ES24 (Base) | 4.1(3)SR (Base) | 4.1(3)SR1 (Base) | 4.1(3)SR2 (Base) | 4.1(3)SR3 (Base) | 4.1(3)SR3b (Base) | 4.1(3)SR3c (Base) | 4.1(3)SR4 (Base) | 4.1(3)SR4b (Base) | 4.1(3)SR4d (Base) | 4.1(3)SR5 (Base) | 4.1(4) (Base) | 4.1(9) (Base) | 4.1(17) (Base) | 4.1(19) (Base) | 4.1(22) (Base) | 4.1(23) (Base) | 4.1(25) (Base) | 4.1(26) (Base) | 4.1(27.7) (Base) | 4.1(28.2) (Base) | 4.1(30.4) (Base) | 4.1(36) (Base) | 4.1(39) (Base) | 4.2(1) (Base) | 4.2(1)SR1b (Base) | 4.2(1.02) (Base) | 4.2(1.05.3) (Base) | 4.2(1.06) (Base) | 4.2(1.07) (Base) | 4.2(3) (Base) | 4.2(3)SR1 (Base) | 4.2(3)SR2 (Base) | 4.2(3.08) (Base) | 4.2(3.2.3) (Base) | 4.2(3.3) (Base) | 4.2(3.13) (Base) | 4.3(1) (Base) | 4.3(1)SR (Base) | 4.3(1.57) (Base) Cisco Unified Customer Voice Portal (CVP) 3.0 ((0), (0)SR1, (0)SR2) | 3.1 ((0), (0)SR1, (0)SR2) | 4.0 ((0), (1), (1)SR1, (2)) Cisco Unified MeetingPlace 4.3 (Base) | 5.3 (Base) | 5.2 (Base) | 5.4 (Base) | 6.0 (Base) Cisco Unified MeetingPlace Express 1.1 (Base) | 1.2 (Base) | 2.0 (Base) Cisco Unity Original Release (Base) | 2.0 (Base) | 2.1 (Base) | 2.2 (Base) | 2.3 (Base) | 2.4 (Base) | 2.46 (Base) | 3.0 (Base, .1) | 3.1 (Base, .2, .3, .5, .6) | 3.2 (Base) | 3.3 (Base) | 4.0 (Base, .1, .2, .3, .3b, .4, .5) | 4.1 (Base, .1) | 4.2 (Base, .1, .1 ES27) | 5.0 ((1)) | 7.0 ((2)) Cisco Unity Express 1.0.2 (Base) | 1.1.1 (Base) | 1.1.2 (Base) | 2.0.1 (Base) | 2.0.2 (Base) | 2.1.1 (Base) | 2.1.2 (Base) | 2.1.3 (Base) | 2.2.0 (Base) | 2.2.1 (Base) | 2.2.2 (Base) | 2.3.0 (Base) | 2.3.1 (Base) Cisco Wireless Control System (WCS) Software 1.0 (Base) | 2.0 (Base, 44.14, 44.24) | 2.2 (.0, .111.0) | 3.0 (Base, .101.0, .105.0) | 3.1 (Base, .20.0, .33.0, .35.0) | 3.2 (Base, .23.0, .25.0, .40.0, .51.0, .64.0) | 4.0 (Base, .1.0, .43.0, .66.0, .81.0, .87.0, .96.0, .97.0) | 4.1 (Base, .83.0) CiscoWorks IP Telephony Environment Monitor (ITEM) 1.3 (Base) | 1.4 (Base) | 2.0 (Base) CiscoWorks LAN Management Solution (LMS) 1.3 (Base) | 2.2 (Base) | 2.5 (Base) | 2.6 (Base) CiscoWorks QoS Policy Manager (QPM) 2.0 (Base, .1, .2, .3) | 2.1 (.2) | 3.0 (Base, .1) | 3.1 (Base) | 3.2 (Base, .1, .2, .3) CiscoWorks Routed WAN Management Solution (RWAN) 1.0 (Base) | 1.1 (Base) | 1.2 (Base) | 1.3 (Base, .1) CiscoWorks Small Network Management Solution (SNMS) 1.0 (Base) | 1.5 (Base) CiscoWorks VPN/Security Management Solution (VMS) 1.0 (Base) | 2.0 (Base) | 2.1 (Base) | 2.2 (Base) | 2.3 (Base) Cisco Collaboration Server 3.0 (Base) | 3.01 (Base) | 3.02 (Base) | 4.0 (Base) | 5.0 (Base) Cisco DOCSIS CPE Configurator 1.0 (Base) | 1.1 (Base) | 2.0 (Base) Cisco Unified IP Interactive Voice Response (IVR) 2.0 (Base) | 2.1 (Base) Cisco Service Control Engine (SCE) 3.0 (Base) | 3.1 (Base) Cisco Transport Manager Original Release (Base) | 2.0 (Base) | 2.1 (Base) | 2.2 (Base, .1) | 3.0 (Base, .1, .2) | 3.1 (Base) | 3.2 (Base) | 4.0 (Base) | 4.1 (Base, .4, .6, .6.6.1) | 4.6 (Base) | 4.7 (Base) | 5.0 (Base, .0.867.2, .1.873.2, .2, .2.92.1, .2.99.1, .2.105.1, .2.110.1) | 6.0 (Base, .0.405.1, .0.407.1, .0.412.1) | 7.0 (Base, .0.370.1, .0.372.1, .0.377.1, .0.389.1, .0.400.1, .395.1) | 7.2 (Base, .0.199.1)
-
THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE ALERTS AT ANY TIME.
A standalone copy or paraphrase of the text of this document that omits the distribution URL is an uncontrolled copy and may lack important information or contain factual errors. The information in this document is intended for end users of Cisco products