ZeroHour
Security Affairspublished ()ingested @securityaffairs

Microsoft’s Patch Tuesday updates for March 2020 fix 115 issues

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-0684
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfull

A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.

NVD description · AI analysis pending
8.89%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2020-0811
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based)L, aka 'Chakra

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based)L, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0812.

NVD description · AI analysis pending
7.58%
  • microsoft chakracore
  • microsoft edge
CVE-2020-0816
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'.

A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'.

NVD description · AI analysis pending
8.811%
  • microsoft edge
CVE-2020-0833
+1 in the same advisory: …0824
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory C

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829, CVE-2020-0830, CVE-2020-0831, CVE-2020-0832, CVE-2020-0848.

NVD description · AI analysis pending
7.59%
  • microsoft internet explorer
CVE-2020-0852
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Exec

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0855, CVE-2020-0892.

NVD description · AI analysis pending
7.812%
  • microsoft office
  • microsoft office online server
  • microsoft sharepoint server
Full article390 words · extracted from securityaffairs.com · click to collapse

Microsoft’s Patch Tuesday updates for March 2020 address 115 vulnerabilities, 26 issues have been rated as critical severity.

Microsoft’s Patch Tuesday updates for March 2020 address 115 vulnerabilities, 26 issues affecting Windows, Word, Dynamics Business Central, Edge, and Internet Explorer have been rated as critical severity.

Microsoft’s Patch Tuesday updates for March 2020 also address vulnerability Exchange Server, Office, Azure DevOps, Windows Defender, Visual Studio, and Dynamics.

88 vulnerabilities have been rated as important in severity, and only one as moderate in severity, most of the overall issues fixed by Microsoft (79) affect Windows OS,

The good news is that Microsoft is not aware of attacks in the wild that exploited one of the vulnerabilities patched this month and no one of the issues is listed as being publicly known. Seven of these flaws were reported through the ZDI program.

Let’s give a look at some of the more interesting issues addressed by Microsoft for this month that could be abused by vxers.

CVE-2020-0852The flaw is Remote Code Execution Vulnerability that affects Word. The vulnerability could be exploited by attackers by simply tricking victims into viewing a specially crafted file in the Preview Pane. The flaw could allow code execution at the level of the logged-on user.

CVE-2020-0684The flaw is a LNK Remote Code Execution Vulnerability that could allow an attacker to create malicious LNK shortcut files that can perform code execution.

“The attacker could present to the user a removable drive, or remote share, that contains a malicious .LNK file and an associated malicious binary,” reads the advisory published by Microsoft. “When the user opens this drive(or remote share) in Windows Explorer or any other application that parses the .LNK file, the malicious binary will execute code of the attacker’s choice on the target system.”

Other critical remote code execution vulnerabilities fixed by Microsoft impact Internet Explorer (CVE-2020-0833CVE-2020-0824), the Edge browser (CVE-2020-0816), and the Chakra scripting engine (CVE-2020-0811).

Additional technical details on the Microsoft’s Patch Tuesday updates for March 2020 are available in the analysis published by Zero Day Initiative.

Users and system administrators are recommended to apply the latest security patches as soon as possible to prevent attackers exploiting them.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – malware, Patch Tuesday)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/99358/security/microsoft-patch-tuesday-march-2020.html