ZeroHour
Cisco Talospublished ()ingested

Microsoft Patch Tuesday — Feb. 2020: Vulnerability disclosures and Snort coverage

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-0618
Authenticated deserialization RCE in Microsoft SQL Server Reporting Services

CVE-2020-0618 is a remote code execution flaw in Microsoft SQL Server Reporting Services (SSRS) caused by unsafe deserialization (CWE-502) of page-request/ViewState data submitted to a report server. An attacker with low-privilege (authenticated) access to a vulnerable SSRS instance can send a crafted serialized payload in a page request, with no user interaction, causing the server to deserialize attacker-controlled data and execute code. Successful exploitation yields remote code execution in the context of the SSRS service account, which is often highly privileged, enabling server compromise and lateral movement. Any organization running affected on-premises Microsoft SQL Server Reporting Services deployments is in scope. The flaw was patched in Microsoft's February 2020 Patch Tuesday, public PoCs have circulated since 2020, and CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-18 with known ransomware use and a near-certain EPSS score (99.0%), so exploitation in the wild is confirmed.

Do: Apply the SQL Server/SSRS security updates released in Microsoft's February 2020 Patch Tuesday (or subsequent cumulative updates) per Microsoft's guidance, satisfying CISA's KEV required action. Inventory environments for SSRS deployments — prioritizing internet-facing report servers — and hunt for evidence of exploitation given the known ransomware use. Restrict network access to report servers and confirm the SSRS service account is not over-privileged to limit impact if exploited.

8.899% KEV ransomware PoC ×2
  • Microsoft SQL Server Reporting Services (SSRS) Affected on-premises SQL Server Reporting Services builds as patched in the February 2020 Patch Tuesday updates; public PoC demonstrated against SQL Server Repo
large≈100,000–1,000,000 SSRS deployments, of which likely tens of thousands are internet-exposed
CVE-2020-0729
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfull

A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.

NVD description · AI analysis pending
8.8
group max
31%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2020-0767
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0674, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713.

NVD description · AI analysis pending
7.5
group max
18%
  • microsoft edge
  • microsoft chakracore
CVE-2020-0674
+2 in the same advisory: …0673 …0706
Use-After-Free RCE in Microsoft Internet Explorer Scripting Engine

CVE-2020-0674 is a use-after-free memory corruption flaw (CWE-416) in the way the Internet Explorer scripting engine handles objects in memory, distinct from a series of sibling scripting-engine RCEs fixed at the same time (CVE-2020-0673, 0710, 0711, 0712, 0713, 0767). Triggering it requires user interaction: an attacker must convince a user to view a specially crafted web page (for example via a phishing link or malicious web content) while it renders in Internet Explorer, and the mishandled memory then allows code execution under the high-complexity, network-reachable conditions reflected in the CVSS vector (AV:N/AC:H/UI:R). Successful exploitation gives the attacker remote code execution with the privileges of the logged-in user, so the practical risk is highest for users browsing with Internet Explorer on Windows, including IE 8 through IE 11 targeted by the public exploits. Exploitation is confirmed in the wild: Microsoft warned of the flaw as an unpatched zero-day being used in targeted attacks before its February 2020 Patch Tuesday fix, public PoC/exploit code is available (including a working exploit for IE 8-11), the Magnitude exploit kit referenced in coverage used it as a delivery vector, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 alongside a very high EPSS score (86.9% probability of exploitation in 30 days, 100th percentile). The required remediation is to apply the Microsoft security updates from February 2020 that address this CVE.

Do: Apply the Microsoft February 2020 Patch Tuesday security updates that fix CVE-2020-0674 on all Windows endpoints and servers, prioritizing per the CISA KEV required action. Until patched, limit Internet Explorer use to trusted sites and consider Microsoft's suggested mitigations (such as restricting active scripting); note that third-party micropatches existed that emulated the vendor workaround without its usability side effects. After patching, verify IE11 remediation status across the estate and, where feasible, retire Internet Explorer usage entirely to reduce exposure to this recurring scripting-engine bug class.

7.5
group max
87% KEV PoC ×4
  • microsoft internet explorer
masshundreds of millions of Windows endpoints (IE 11 was bundled with every supported Windows release at disclosure)
CVE-2020-0683
Local Privilege Escalation in Microsoft Windows Installer (Symbolic Link Handling)

CVE-2020-0683 is an elevation-of-privilege flaw in the Windows Installer (MSI) engine, classified as improper link resolution before file access (CWE-59): when the elevated Installer processes an MSI package, it can be made to follow attacker-controlled symbolic links. A local attacker holding only a low-privileged account can trigger or race an MSI installation so that the Installer's SYSTEM-level file operations are redirected through crafted symlinks into protected locations, with no user interaction required. Successful exploitation yields local privilege escalation to SYSTEM (CVSS 3.1 7.8, C:H/I:H/A:H), giving the attacker full control of the host, which is useful for disabling defenses and staging follow-on activity. Any unpatched system running an affected release is exposed — per the CPE data, Windows 7, Windows 8.1, Windows RT 8.1, Windows 10 versions 1507 through 1909, and Windows Server versions 1803 and 1903. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming in-the-wild exploitation (ransomware use unknown); EPSS currently estimates a 7.7% probability of exploitation within 30 days (94th percentile), and no public proof-of-concept is known.

Do: Apply Microsoft's February 2020 Patch Tuesday updates — or any later cumulative update/monthly rollup — to all Windows 7, 8.1, RT 8.1, Windows 10 (1507–1909), and Windows Server 1803/1903 systems, and verify the related sibling vulnerability CVE-2020-0686 is also addressed by the installed patch; CISA's KEV listing requires remediation per vendor instructions. Prioritize endpoints and shared/multi-user servers where untrusted or low-privileged users can run MSI installers, and sweep inventories for machines that skipped the February 2020 patch cycle. In the absence of a public PoC, treat MSI installation activity launched by non-administrative accounts as a possible indicator of exploitation attempts.

7.88% KEV
  • Microsoft Windows 10 1507, 1607, 1709, 1803, 1809, 1903, 1909 (pre-February 2020 security updates)
  • Microsoft Windows 7 all supported builds prior to the February 2020 security update
  • Microsoft Windows 8.1 all supported builds prior to the February 2020 security update
  • +2 more
masshundreds of millions of Windows devices (combined Windows 7/8.1/10 market share at the February 2020 disclosure)
CVE-2020-0688
+1 in the same advisory: …0692
RCE in Microsoft Exchange Server from Shared Install-Time Validation Keys

CVE-2020-0688 is a remote code execution vulnerability in Microsoft Exchange Server caused by the validation key not being uniquely created at install time, leaving deployments with a predictable, shared key (CWE-287, improper authentication). A remote attacker who can reach an affected Exchange server and knows the common install-time key can supply maliciously crafted, cryptographically signed payloads that the server trusts, triggering code execution without needing per-server secrets. Successful exploitation gives the attacker code execution on the Exchange server, which can be used to access mail data, move laterally, and stage follow-on activity; CISA notes known use in ransomware campaigns. All organizations running the affected on-premises Microsoft Exchange Server are in scope per CISA's listing, though the affected version range is not specified in the source data. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2021-11-03 with known ransomware use, and EPSS rates 30-day exploitation probability at 100% (top percentile).

Do: Apply Microsoft's Exchange security updates addressing CVE-2020-0688 (released in February 2020) to every on-premises Exchange server, per CISA's required action. As an interim mitigation, configure a unique ASP.NET machineKey in each Exchange server's web.config instead of the default shared install-time key, and hunt for indicators of exploitation given the known ransomware use.

8.8
group max
100% KEV ransomware PoC ×2
  • Microsoft Exchange Server
masshundreds of thousands of on-premises Exchange servers (≈500,000)
CVE-2020-0693
+1 in the same advisory: …0694
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected Sha

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0694.

NVD description · AI analysis pending
5.42%
  • microsoft sharepoint enterprise server
CVE-2020-0695
A spoofing vulnerability exists when Office Online Server does not validate origin in cross-origin communications correctly, aka 'Microsoft Office Online Server

A spoofing vulnerability exists when Office Online Server does not validate origin in cross-origin communications correctly, aka 'Microsoft Office Online Server Spoofing Vulnerability'.

NVD description · AI analysis pending
5.4<1%
  • microsoft office online server
CVE-2020-0696
A security feature bypass vulnerability exists in Microsoft Outlook software when it improperly handles the parsing of URI formats, aka 'Microsoft Outlook Secur

A security feature bypass vulnerability exists in Microsoft Outlook software when it improperly handles the parsing of URI formats, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'.

NVD description · AI analysis pending
6.55%
  • microsoft office
  • microsoft office 365 proplus
  • microsoft outlook
CVE-2020-0697
An elevation of privilege vulnerability exists in Microsoft Office OLicenseHeartbeat task, where an attacker who successfully exploited this vulnerability could

An elevation of privilege vulnerability exists in Microsoft Office OLicenseHeartbeat task, where an attacker who successfully exploited this vulnerability could run this task as SYSTEM.To exploit the vulnerability, an authenticated attacker would need to place a specially crafted file in a specific location, thereby allowing arbitrary file corruption.The security update addresses the vulnerability by correcting how the process validates the log file., aka 'Microsoft Office Tampering Vulnerability'.

NVD description · AI analysis pending
7.8<1%
  • microsoft office 365 proplus
CVE-2020-0702
A security feature bypass vulnerability exists in Surface Hub when prompting for credentials, aka 'Surface Hub Security Feature Bypass Vulnerability'.

A security feature bypass vulnerability exists in Surface Hub when prompting for credentials, aka 'Surface Hub Security Feature Bypass Vulnerability'.

NVD description · AI analysis pending
6.8<1%
  • microsoft surface hub firmware
CVE-2020-0733
An elevation of privilege vulnerability exists when the Windows Malicious Software Removal Tool (MSRT) improperly handles junctions.To exploit this vulnerabilit

An elevation of privilege vulnerability exists when the Windows Malicious Software Removal Tool (MSRT) improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Malicious Software Removal Tool Elevation of Privilege Vulnerability'.

NVD description · AI analysis pending
7.8<1%
  • microsoft windows malicious software removal tool
CVE-2020-0736
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerab

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'.

NVD description · AI analysis pending
5.51%
  • microsoft windows 7
  • microsoft windows server 2008
CVE-2020-0759
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remo

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.

NVD description · AI analysis pending
8.815%
  • microsoft excel
  • microsoft office 365 proplus
CVE-2020-0766
An elevation of privilege vulnerability exists when the Microsoft Store Runtime improperly handles memory.

An elevation of privilege vulnerability exists when the Microsoft Store Runtime improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correcting how the Microsoft Store Runtime handles memory.

NVD description · AI analysis pending
7.8<1%
  • microsoft windows 10
  • microsoft windows server 2016
  • microsoft windows server 2019
Full article683 words · extracted from blog.talosintelligence.com · click to collapse

Tuesday, February 11, 2020 14:31

By Jon Munshaw.

Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 98 vulnerabilities, 12 of which are considered critical and 84 that are considered important. There are also two bugs that were not assigned a severity.

This month's patches include updates to the Windows kernel, the Windows scripting engine and Remote Desktop Procol, among other software and features. Microsoft also provided a critical advisory covering updates to Adobe Flash Player.

Talos released a new set of SNORTⓇ rules today that provide coverage for some of these vulnerabilities, which you can see here.

Critical vulnerabilities Microsoft disclosed 12 critical vulnerabilities this month, all of which we will highlight below.

CVE-2020-0673, CVE-2020-0674, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713 and CVE-2020-0767 are all memory corruption vulnerabilities in the Microsoft scripting engine that deals with how Internet Explorer handles objects in memory. An attacker could use these vulnerabilities to corrupt memory on the victim machine in a way that would allow them to execute arbitrary code. A user could trigger this bug by visiting an attacker-controlled web page on Internet Explorer that's been specially crafted to exploit this vulnerability. Alternatively, an attacker could embed an ActiveX control marked "safe for initialization" in another application or Microsoft Office document that utilizes the Internet Explorer rendering engine and convince the victim to open that file.

CVE-2020-0681 and CVE-2020-0734 are remote code execution vulnerabilities in Remote Desktop Protocol when the user connects to a malicious server. An attacker can exploit these vulnerabilities by hosting a server, and convincing a user to connect to it, likely via social engineering or a man-in-the-middle technique.

CVE-2020-0662 is a remote code execution vulnerability in Windows 10 and some versions of Windows Server that exists in the way the software handles objects in memory. If successfully exploited, this vulnerability could allow an attacker to execute arbitrary code with elevated permissions on the victim machine. The attacker would need a domain user account, and then create a specially crafted request.

CVE-2020-0729 is a remote code execution vulnerability in Windows that could allow an attacker to remotely execute code if Windows processes a specially crafted .LNK file. An adversary could exploit this vulnerability by sending the user a removable drive or remote share containing a malicious .LNK file and an associated malicious binary. If the user opens the file in Windows Explorer or another application that parses .LNK files, the binary will execute code of the attacker's choice.

CVE-2020-0738 is a memory corruption vulnerability in Windows Media Foundation that exists in the way the software handles objects in memory. An attacker could exploit this bug by convincing the user to open a specially crafted, malicious file or web page, which would corrupt memory in a way the attacker could then install programs, manipulate user data or create new user accounts on the victim machine.

Important vulnerabilities This release also contains 84 important vulnerabilities:

Coverage  In response to these vulnerability disclosures, Talos is releasing a new SNORTⓇ rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Firepower customers should use the latest update to their ruleset by updating their SRU. Open Source Snort Subscriber Rule Set customers can stay up-to-date by downloading the latest rule pack available for purchase on Snort.org.

These rules are:  48701, 48702, 53050 - 53056, 53061, 53072, 53073, 53079 - 53089

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-feb-2020/