Microsoft July 2020 Security Updates address 123 vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-1036 | A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1040, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043. NVD description · AI analysis pending | 9.0 | 6% |
| — | ||
| CVE-2020-1040 | Guest-to-Host RCE in Microsoft Hyper-V RemoteFX vGPU on Windows Server CVE-2020-1040 is a critical (CVSS 3.1: 9.0) remote code execution flaw in the Hyper-V RemoteFX vGPU component, where the host server fails to properly validate input from an authenticated user on a guest operating system. An attacker who can authenticate to a guest VM configured with a RemoteFX vGPU can send crafted input to the virtual GPU and execute code on the host, achieving a guest-to-host escape with high impact to confidentiality, integrity and availability (scope changed). Only Hyper-V hosts running Windows Server 2008, 2012 or 2016 with the RemoteFX vGPU feature enabled and VMs using RemoteFX 3D video are affected. It is one of five related RemoteFX vGPU vulnerabilities (CVE-2020-1032, 1036, 1041, 1042, 1043) fixed in Microsoft's July 2020 security updates, a release that addressed 123 vulnerabilities and drew attention to RemoteFX issues on AMD and Intel-based systems. CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, indicating exploitation in the wild; EPSS estimates a 7.3% chance of exploitation within 30 days (94th percentile), while no public proof-of-concept is known. Do: Apply Microsoft's July 2020 or later security updates to all Hyper-V hosts running Windows Server 2008, 2012 or 2016 with RemoteFX vGPU, per the CISA KEV required action. Until patched, remove the RemoteFX 3D video adapter from guest VMs or disable RemoteFX on the host, and inventory the environment for VMs with RemoteFX vGPU attached. Restrict which users can log on to vGPU-enabled guests, since exploitation requires an authenticated guest user. | 9.0 | 7% | KEV |
| largetens of thousands of Hyper-V hosts (enterprise Windows Server estates with RemoteFX vGPU enabled) | |
| CVE-2020-1240 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remo A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. NVD description · AI analysis pending | 8.8 group max | 14% |
| — | ||
| CVE-2020-1350 | Wormable Unauthenticated RCE in Microsoft Windows DNS Server CVE-2020-1350 is a critical (CVSS 10.0) remote code execution vulnerability in the DNS Server role of Microsoft Windows Server, caused by improper input handling (CWE-20) when the server fails to properly process crafted DNS requests, notably malicious DNS signature (SIG) records delivered over TCP. An unauthenticated attacker can trigger it by sending a crafted DNS query that forces the vulnerable DNS server to perform an upstream lookup and receive a malicious response, overflowing a heap buffer. Successful exploitation yields code execution with SYSTEM privileges on the DNS server, which is very often an Active Directory domain controller, giving the attacker control of the host and typically the entire domain; the flaw is considered wormable because compromised DNS servers can propagate attacks to other servers they query. Any Windows Server 2008, 2012, 2016, or 2019 host running the DNS Server role is affected — internet-facing DNS servers are directly explovable, while internal DNS servers can be reached via malicious DNS responses passed through firewalls. The flaw was fixed in Microsoft's July 2020 updates, is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03, required action: apply vendor updates), carries EPSS of 91.4% (100th percentile), and appears in the NSA's top-25 list of flaws exploited by Chinese state-sponsored hackers; no public PoC is cataloged in this dataset and ransomware use is listed as unknown. Do: Apply the July 2020 (or later) Microsoft security updates for each affected Windows Server release, prioritizing internet-facing DNS servers and domain controllers; if patching must be delayed, apply Microsoft's registry-based workaround limiting TCP DNS packet size (TcpReceivePacketSize = 0xFF00) and restart the DNS Server service. Inventory hosts with the DNS Server role installed and review their TCP/53 exposure, especially any resolvers reachable from the internet, and confirm remediation per CISA's required action. | 10.0 | 91% | KEV |
| masshundreds of thousands of internet-exposed Windows DNS servers (est.), with millions of total deployments including internal domain controllers | |
| CVE-2020-1421 | A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfull A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'. NVD description · AI analysis pending | 8.8 group max | 75% |
| — | ||
| CVE-2020-1444 | A remote code execution vulnerability exists in the way Microsoft SharePoint software parses specially crafted email messages, aka 'Microsoft SharePoint Remote A remote code execution vulnerability exists in the way Microsoft SharePoint software parses specially crafted email messages, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. NVD description · AI analysis pending | 4.3 | 9% |
| — | ||
| CVE-2020-1448 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Exec A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1447. NVD description · AI analysis pending | 8.8 | 10% |
| — |
Full article411 words · extracted from securityaffairs.com · click to collapse

Microsoft July 2020 addressed 123 security flaws across 13 products, including a 17-year-old wormable issue for hijacking Microsoft Windows Server dubbed SigRed.
Microsoft July 2020 addressed 123 security vulnerabilities impacting 13 products, none of them has been observed being exploited in attacks in the wild.
The July 2020 security release consists of security updates for the following software:
- Microsoft Windows
- Microsoft Edge (EdgeHTML-based)
- Microsoft Edge (Chromium-based) in IE Mode
- Microsoft ChakraCore
- Internet Explorer
- Microsoft Office and Microsoft Office Services and Web Apps
- Windows Defender
- Skype for Business
- Visual Studio
- Microsoft OneDrive
- Open Source Software
- .NET Framework
- Azure DevOps
The most severe issue is the 17-year-old wormable issue SigRed, tracked as CVE-2020-1350, that allows hijacking of Microsoft Windows Server
The issue received a severity rating of 10.0 on the CVSS scale and affects Windows Server versions 2003 to 2019.
The vulnerability could be exploited by an unauthenticated, remote attacker to gain domain administrator privileges over targeted servers and take full control of an organization’s IT infrastructure.
“Today we released an update for CVE-2020-1350, a Critical Remote Code Execution (RCE) vulnerability in Windows DNS Server that is classified as a ‘wormable’ vulnerability and has a CVSS base score of 10.0. This issue results from a flaw in Microsoft’s DNS server role implementation and affects all Windows Server versions. Non-Microsoft DNS Servers are not affected.” reads the advisory published by Microsoft.
“Wormable vulnerabilities have the potential to spread via malware between vulnerable computers without user interaction. Windows DNS Server is a core networking component. While this vulnerability is not currently known to be used in active attacks, it is essential that customers apply Windows updates to address this vulnerability as soon as possible.”
Microsoft July 2020 also addressed several important flaws, including some remote code vulnerabilities in:
- Jet Database Engine (CVE-2020-1400, CVE-2020-1401, CVE-2020-1407)
- RemoteFX vGPU component of Microsoft’s Hyper-V hypervisor technology (CVE-2020-1041, CVE-2020-1040, CVE-2020-1032, CVE-2020-1036, CVE-2020-1042, CVE-2020-1043)
- Microsoft Excel (CVE-2020-1240)
- Microsoft Outlook (CVE-2020-1349)
- Microsoft Sharepoint (CVE-2020-1444)
- Microsoft Word (CVE-2020-1446, CVE-2020-1447, CVE-2020-1448)
- Windows LNK shortcut files (CVE-2020-1421)
- Multiple Windows graphics components (CVE-2020-1435, CVE-2020-1408, CVE-2020-1412, CVE-2020-1409, CVE-2020-1436, CVE-2020-1355)
The complete list of the issues addressed by Microsoft is available in the Microsoft’s official Security Update Guide portal.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Microsoft July 2020)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/105914/security/microsoft-july-2020-patch-tuesday.html