Microsoft addresses three Windows issues actively exploited
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-1020 | Out-of-Bounds Write RCE in Microsoft Windows Adobe Font Manager Library CVE-2020-1020 is a remote code execution vulnerability (out-of-bounds write, CWE-787) in the Adobe Font Manager Library shipped with Microsoft Windows, caused by improper handling of a specially crafted multi-master font in Adobe Type 1 PostScript format. Triggering it requires user interaction: an attacker delivers a malicious document or font, and the vulnerable code runs when the content is previewed or opened (no authentication is needed on the network path, but the user must interact). On all systems except Windows 10, successful exploitation allows the attacker to execute arbitrary code remotely in the context of the current user; on Windows 10 the flaw is present as well, with the full remote-code-execution impact described for non-Windows-10 systems. Affected software spans Windows 10 versions 1507 through 1909, Windows 7, Windows 8.1, Windows RT 8.1, and Windows Server 1903/1909. The bug was exploited in the wild as a zero-day by a sophisticated threat actor prior to patching (CISA KEV, added 2021-11-03), and EPSS assigns a 65% probability of exploitation within 30 days (99th percentile). Do: Apply Microsoft's security update for CVE-2020-1020 via Windows Update (April 2020 Patch Tuesday cycle) on all Windows 7, 8.1, RT 8.1, Windows 10 1507-1909, and Windows Server 1903/1909 hosts, per CISA's required action. As interim mitigation, disable the Explorer preview and details panes and avoid opening or previewing untrusted documents and fonts. Verify the fix is deployed, prioritizing non-Windows-10 systems where successful exploitation yields full remote code execution. | 8.8 group max | 65% | KEV |
| masshundreds of millions of Windows client/server devices (OS component shipped in all listed Windows releases) | |
| CVE-2020-0968 | Memory Corruption RCE in Microsoft Internet Explorer Scripting Engine CVE-2020-0968 is a memory corruption vulnerability (CWE-787, out-of-bounds write) in Microsoft Internet Explorer's scripting engine, where the engine mishandles objects in memory in a way that can be leveraged for remote code execution. It is typically triggered when a user views a specially crafted webpage in Internet Explorer or in an application that hosts the IE rendering components; successful exploitation gives the attacker code execution in the context of the current user. Any Windows environment where Internet Explorer and its scripting engine are present is affected, which spans most enterprise and consumer Windows estates. Exploitation is confirmed in the wild: the flaw is listed in CISA's KEV catalog (added 2021-11-03) with known ransomware use, and EPSS assigns a 30.7% probability of exploitation within 30 days (98th percentile). No public proof-of-concept is known, indicating attackers are not dependent on public PoC code. Do: Apply the Microsoft security updates that fix CVE-2020-0968 (released in the March 2020 Patch Tuesday batch) across all Windows systems with Internet Explorer, prioritizing user workstations and remote desktop/terminal servers per CISA's required action to apply vendor updates. Since the exploit path runs through web content, verify whether legacy web apps or desktop applications still invoke the IE engine and reduce reliance on IE as a default renderer. Confirm remediation by checking for the corresponding cumulative Windows/IE update rather than relying on a single KB lookup. | 7.5 | 31% | KEV ransomware |
| masshundreds of millions of Windows endpoints (IE is a built-in OS component) |
Full article588 words · extracted from securityaffairs.com · click to collapse

Microsoft Patch Tuesday security updates for April 2020 address 113 flaws, including three Windows issues that have been exploited in attacks in the wild.
Microsoft Patch Tuesday security updates for April 2020 address 113 flaws, including two remote code execution flaws in Windows that are actively exploited.
17 vulnerabilities are rated critical, the remaining ones are rated as important.
The flaws addressed by Microsoft this month impact Windows, Edge, Internet Explorer, Office, Windows Defender, Dynamics, Apps for Android and Mac, and other products.
The two RCE flaws in Windows, tracked as CVE-2020-1020 and CVE-2020-0938, are related to the Adobe Type Manager Library.
In March, Microsoft warned of hackers exploiting the two zero-day remote code execution (RCE) vulnerabilities in the Windows Adobe Type Manager Library, both issues impact all supported versions of Windows.
Microsoft is aware of limited targeted attacks that could leverage unpatched vulnerabilities in the Adobe Type Manager Library, and is providing guidance to help reduce customer risk until the security update is released. See the link for more details. https://t.co/tUNjkHNZ0N
— Security Response (@msftsecresponse) March 23, 2020
The vulnerabilities affects the way Windows Adobe Type Manager Library handles a specially-crafted multi-master font – Adobe Type 1 PostScript format.
Microsoft describes multiple attack scenarios, the attackers could trick victims into opening a specially crafted document or viewing it in the Windows Preview pane.
The good news is that the number of targeted attacks in the wild exploiting the two RCE flaws is “limited”
Microsoft pointed out that a successful attack on systems running supported versions of Windows 10 could only result in code execution within an AppContainer sandbox context with limited privileges and capabilities.
Microsoft has credited researchers from Google’s Project Zero and Threat Analysis Group for reporting both vulnerabilities along with experts at Qi An Xin for reporting the CVE-2020-0938 flaw.
The third Windows flaw addressed by Microsoft, tracked as CVE-2020-1027. was also reported by Google. According to Microsoft, the vulnerability is a Windows kernel flaw actively exploited in the wild.
Google has also been credited by Microsoft for reporting an actively exploited Windows kernel vulnerability tracked as CVE-2020-1027.
“An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.” read the advisory published by Microsoft.
“To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.”
Another issue addressed by Microsoft that has been exploited in attacks in the wild is a remote code issue in Internet Explorer tracked as CVE-2020-0968.
“A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.” reads the advisory published by Microsoft. “If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.”
As usual, let me suggest reading the analysis published by Trend Micro’s Zero Day Initiative (ZDI) of the Microsoft Patch Tuesday security updates, it includes interesting details about the flaws.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – Microsoft Patch Tuesday, hacking)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/101592/security/microsoft-patch-tuesday-april-20.html