ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

April 2020 Patch Tuesday: Microsoft fixes three actively exploited vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-0981
+2 in the same advisory: …0910 …0993
A security feature bypass vulnerability exists when Windows fails to properly handle token relationships.An attacker who successfully exploited the vulnerabilit

A security feature bypass vulnerability exists when Windows fails to properly handle token relationships.An attacker who successfully exploited the vulnerability could allow an application with a certain integrity level to execute code at a different integrity level, leading to a sandbox escape.The update addresses the vulnerability by correcting how Windows handles token relationships, aka 'Windows Token Security Feature Bypass Vulnerability'.

NVD description · AI analysis pending
8.8
group max
1%
  • microsoft windows 10
  • microsoft windows server 2016
CVE-2020-0935
An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links, aka 'OneDrive for Windows El

An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links, aka 'OneDrive for Windows Elevation of Privilege Vulnerability'.

NVD description · AI analysis pending
5.5<1%
  • microsoft onedrive
CVE-2020-1020
+2 in the same advisory: …0938 …1027
Out-of-Bounds Write RCE in Microsoft Windows Adobe Font Manager Library

CVE-2020-1020 is a remote code execution vulnerability (out-of-bounds write, CWE-787) in the Adobe Font Manager Library shipped with Microsoft Windows, caused by improper handling of a specially crafted multi-master font in Adobe Type 1 PostScript format. Triggering it requires user interaction: an attacker delivers a malicious document or font, and the vulnerable code runs when the content is previewed or opened (no authentication is needed on the network path, but the user must interact). On all systems except Windows 10, successful exploitation allows the attacker to execute arbitrary code remotely in the context of the current user; on Windows 10 the flaw is present as well, with the full remote-code-execution impact described for non-Windows-10 systems. Affected software spans Windows 10 versions 1507 through 1909, Windows 7, Windows 8.1, Windows RT 8.1, and Windows Server 1903/1909. The bug was exploited in the wild as a zero-day by a sophisticated threat actor prior to patching (CISA KEV, added 2021-11-03), and EPSS assigns a 65% probability of exploitation within 30 days (99th percentile).

Do: Apply Microsoft's security update for CVE-2020-1020 via Windows Update (April 2020 Patch Tuesday cycle) on all Windows 7, 8.1, RT 8.1, Windows 10 1507-1909, and Windows Server 1903/1909 hosts, per CISA's required action. As interim mitigation, disable the Explorer preview and details panes and avoid opening or previewing untrusted documents and fonts. Verify the fix is deployed, prioritizing non-Windows-10 systems where successful exploitation yields full remote code execution.

8.8
group max
65% KEV
  • microsoft Windows 10 1507, 1607, 1709, 1803, 1809, 1903, 1909
  • microsoft Windows 7
  • microsoft Windows 8.1
  • +3 more
masshundreds of millions of Windows client/server devices (OS component shipped in all listed Windows releases)
CVE-2020-0968
Memory Corruption RCE in Microsoft Internet Explorer Scripting Engine

CVE-2020-0968 is a memory corruption vulnerability (CWE-787, out-of-bounds write) in Microsoft Internet Explorer's scripting engine, where the engine mishandles objects in memory in a way that can be leveraged for remote code execution. It is typically triggered when a user views a specially crafted webpage in Internet Explorer or in an application that hosts the IE rendering components; successful exploitation gives the attacker code execution in the context of the current user. Any Windows environment where Internet Explorer and its scripting engine are present is affected, which spans most enterprise and consumer Windows estates. Exploitation is confirmed in the wild: the flaw is listed in CISA's KEV catalog (added 2021-11-03) with known ransomware use, and EPSS assigns a 30.7% probability of exploitation within 30 days (98th percentile). No public proof-of-concept is known, indicating attackers are not dependent on public PoC code.

Do: Apply the Microsoft security updates that fix CVE-2020-0968 (released in the March 2020 Patch Tuesday batch) across all Windows systems with Internet Explorer, prioritizing user workstations and remote desktop/terminal servers per CISA's required action to apply vendor updates. Since the exploit path runs through web content, verify whether legacy web apps or desktop applications still invoke the IE engine and reduce reliance on IE as a default renderer. Confirm remediation by checking for the corresponding cumulative Windows/IE update rather than relying on a single KB lookup.

7.531% KEV ransomware
  • Microsoft Internet Explorer
masshundreds of millions of Windows endpoints (IE is a built-in OS component)
CVE-2020-1022
A remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'.

A remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'.

NVD description · AI analysis pending
8.07%
  • microsoft dynamics 365 business central
  • microsoft dynamics nav
CVE-2020-3954
+1 in the same advisory: …3953
Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.

Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.

NVD description · AI analysis pending
6.1
group max
<1%
  • vmware vrealize log insight
Full article877 words · extracted from helpnetsecurity.com · click to collapse

For the April 2020 Patch Tuesday, Adobe plugs 5 flaws and Microsoft 113, three of which are currently being exploited by attackers.

April 2020 Patch Tuesday

Adobe’s updates

On this Patch Tuesday, Adobe has released security updates for ColdFusion (2016 and 2018) for all platforms, After Effects (for Windows and macOS), and Digital Editions for Windows.

No critical vulnerabilities have been addressed this time. Both After Effects and Digital Editions are vulnerable to one single flaw each that could lead to information disclosure.

ColdFusion, a popular web application development platform, has received updates that fix vulnerabilities that could be exploited to perform application-lever DoS, privilege escalation, and system file structure disclosure.

The security advisory also notes that, in order for the Coldfusion update to secure the server, users must also update their ColdFusion JDK/JRE to the latest version of the LTS releases for 1.8 and JDK 11. Adobe has also pointed customers towards guides that should help them lock down their ColdFusion installations.

None of the fixed issues are under active attack.

Microsoft’s updates

As per usual, Microsoft has released patches for a wide variety of its software. 113 CVE-numbered vulnerabilities have been fixed, of which 17 are critical and 96 important.

First things first: two of the critical vulnerabilities can allow remote code execution and are under active exploitation.

CVE-2020-1020 and CVE-2020-0938 are two remote code execution flaws whose existence and active exploitation was revealed by Microsoft at the end of March.

Both affect the Windows Adobe Type Manager Library and both arise from how it improperly handles a specially-crafted multi-master font. They can be triggered by users viewing a specially crafted font/document or viewing it in the Windows Preview pane.

In the previously mentioned attacks in the wild, attackers used them to target Windows 7 users, though Windows 10, 8.1, RT 8.1 and various editions of Windows Server contain the vulnerable library. The risk they carry for Windows 10 machines is slight, i.e., a successful attack could only result in code execution within an AppContainer sandbox context with limited privileges and capabilities.

“Although the attacks specifically have targeted Windows 7 systems, not all Win7 systems will receive a patch since the OS left support in January of this year. Only those Windows 7 and Server 2008 customers with an ESU license will receive the patch,” noted Trend Micro Zero Day Initiative’s Dustin Childs.

Other vulnerabilities of note in this batch:

CVE-2020-0935: an elevation of privilege vulnerability that arises from the OneDrive for Windows Desktop application improperly handling symbolic links. This one has been publicly disclosed, but is not actively exploited. “Most customers have been protected from this vulnerability because OneDrive has its own updater that periodically checks and updates the OneDrive binary,” Microsoft noted.

CVE-2020-0993: A DoS bug in the Windows DNS service, affecting client systems. Despite not allowing code execution, Childs believes it should be high on admins’ test and deploy list, because of the widespread damage an authenticated attacker could inflict through it.

There’s CVE-2020-0981, a Windows Token security feature bypass vulnerability that can allow a sandbox escape, but it affects only Windows 10 version 1903 and higher.

Jimmy Graham, Senior Director of Product Management at Qualys advises admins to prioritize:

  • Scripting Engine, Adobe Font Manager Library, Media Foundation, Microsoft Graphics, and Windows Codecs patches for workstation-type devices. One of the patches fixes CVE-2020-0968, a RCE in Internet Explorer 11 and 9, which Microsoft initially flagged as being exploited in the wild.
  • The patch for CVE-2020-1027, an actively exploited privilege escalation vulnerability in the Windows Kernel, for all Windows devices
  • SharePoint patches covering RCE and XSS vulnerabilities for all SharePoint servers.

Less likely to be exploited but still important to be patched are a Hyper-V Hypervisor Escape flaw (CVE-2020-0910) and a RCE affecting Dynamics Business Central (CVE-2020-1022), he says.

“Organizations are already strained with the added stresses of the sudden shift to remote workers and the technological needs, but today’s Patch Tuesday is not one to skip,” noted Richard Melick, Sr. Technical Product Manager, Automox.

He advises IT and SecOps managers to create a deployment plan that addresses today’s zero-day, exploited, and critical vulnerabilities within 24 hours and the rest within 72 hours in order to stay ahead of weaponization.

Oracle’s updates

The April 2020 Patch Tuesday coincides with Oracle’s scheduled Critical Patch Update for April 2020.

It is yet to be released, but according to the pre-release announcement, 405 new security vulnerabilities will be addressed, in a wide variety of its offerings. Admins should take a peek at it and see whether there is extensive patching in their future.

UPDATE (April 15, 2020, 1:00 a.m. PT):

Microsoft has revised the update guide for CVE-2020-0968, the RCE in Internet Explorer 11 and 9, to say that it is not being exploited, so the number of actively exploited flaws is three instead of four. We’ve amended the article and the title to reflect this.

Oracle’s pre-release announcement has been replaced by the Critical Patch Update Advisory, which says that the CPU contains 397 new security patches.

VMware has also released a security update this Patch Tuesday, to fix Cross Site Scripting (XSS) and Open Redirect vulnerabilities (CVE-2020-3953, CVE-2020-3954) in VMware vRealize Log Insight, its centralized log management and intelligent analytics offering.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2020/04/14/april-2020-patch-tuesday/