Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-0901 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Excel. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) containing a specially crafted file designed to exploit the vulnerability. An attacker would have no way to force users to visit the website. Instead, an attacker would have to convince users to click a link, typically by way of an enticement in an email or instant message, and then convince them to open the specially crafted file. The security update addresses the vulnerability by correcting how Microsoft Excel handles objects in memory. NVD description · AI analysis pending | 9.8 | 4% |
| — | ||
| CVE-2020-1126 | A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Foundation handles objects in memory. NVD description · AI analysis pending | 8.8 group max | 4% |
| — | ||
| CVE-2020-1102 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account. Exploitation of this vulnerability requires that a user uploads a specially crafted SharePoint application package to an affected version of SharePoint. The security update addresses the vulnerability by correcting how SharePoint checks the source markup of application packages. NVD description · AI analysis pending | 8.8 group max | 5% |
| — | ||
| CVE-2020-1062 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, the attacker could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker could host a specially crafted website designed to exploit the vulnerability through Internet Explorer and then convince a user to view the website. The attacker could also take advantage of compromised websites, or websites that accept or host user-provided content or advertisements, by adding specially crafted content that could exploit the vulnerability. However, in all cases an attacker would have no way to force a user to view the attacker-controlled content. Instead, an attacker would have to convince a user to take action, typically by an enticement in an email or instant message, or by getting the user to open an attachment sent through email. The security update addresses the vulnerability by modifying how Internet Explorer handles objects in memory. NVD description · AI analysis pending | 7.5 | 6% |
| — | ||
| CVE-2020-1056 | An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access info An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain. In a web-based attack scenario, an attacker could host a website that is used to attempt to exploit the vulnerability. In addition, compromised websites and websites that accept or host user-provided content could contain specially crafted content that could exploit the vulnerability. However, in all cases an attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action. For example, an attacker could trick users into clicking a link that takes them to the attacker's site. An attacker who successfully exploited this vulnerability could elevate privileges in affected versions of Microsoft Edge. The security update addresses the vulnerability by helping to ensure that cross-domain policies are properly enforced in Microsoft Edge. NVD description · AI analysis pending | 5.4 group max | 2% |
| — | ||
| CVE-2020-1054 | Privilege Escalation in Microsoft Windows Win32k Kernel Driver (CVE-2020-1054) CVE-2020-1054 is an elevation-of-privilege flaw (CWE-787, an out-of-bounds memory access) in the Windows kernel-mode driver (win32k), which fails to properly handle objects in memory. To exploit it, an attacker who can already log on to an affected Windows machine must run a specially crafted application, which triggers the memory-handling error and allows arbitrary code execution in kernel mode. Successful exploitation effectively yields full SYSTEM-level control of the host: the attacker can install programs, view, change or delete any data, and create new accounts with full user rights. Affected products per the CPE data are Windows 7, 8.1, RT 8.1, Windows 10 versions 1507 through 1909, and Windows Server 1803 and 1903. The flaw was fixed in Microsoft's May 2020 Patch Tuesday, a public DrawIconEx-based local privilege escalation PoC exists, EPSS is 54.2% (99th percentile), and CISA added it to the KEV catalog on 2021-11-03, confirming exploitation in the wild; related threat reporting around this CVE ties it to malware campaigns such as PurpleFox and Raspberry Robin, while ransomware use is listed as unknown. Do: Apply Microsoft's May 2020 security updates (or any later cumulative update) to Windows 7, 8.1, RT 8.1, Windows 10 1507–1909, and Windows Server 1803/1903, per the CISA KEV required action; prioritize multi-user hosts such as RDS servers where low-privileged users can run code. For legacy systems that no longer receive updates (e.g., Windows 7/8.1 post-EOL), limit local logon and software-execution rights for untrusted users and monitor for local privilege escalation activity. | 7.0 | 54% | KEV PoC |
| mass≈1 billion Windows devices (global Windows 10 install base plus the legacy Windows 7/8.1 estate) | |
| CVE-2020-1063 | A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected Dynamics server. The attacker who successfully exploited the vulnerability could then perform cross-site scripting attacks on affected systems and run script in the security context of the current authenticated user. These attacks could allow the attacker to read content that the attacker is not authorized to read, use the victim's identity to take actions within Dynamics Server on behalf of the user, such as change permissions and delete content, and inject malicious content in the browser of the user. The security update addresses the vulnerability by helping to ensure that Dynamics Server properly sanitizes web requests. NVD description · AI analysis pending | 5.4 | 1% |
| — | ||
| CVE-2020-1065 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. The security update addresses the vulnerability by modifying how the ChakraCore scripting engine handles objects in memory. NVD description · AI analysis pending | 4.2 | 2% |
| — | ||
| CVE-2020-1066 | An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level. An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level. To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program. The update addresses the vulnerability by correcting how .NET Framework activates COM objects. NVD description · AI analysis pending | 7.8 | 2% |
| — | ||
| CVE-2020-1108 | A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application. The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests. NVD description · AI analysis pending | 7.5 | 6% |
| — | ||
| CVE-2020-1150 | A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Foundation handles objects in memory. NVD description · AI analysis pending | 7.8 | 3% |
| — | ||
| CVE-2020-1161 | A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the ASP.NET Core application. The update addresses the vulnerability by correcting how the ASP.NET Core web application handles web requests. NVD description · AI analysis pending | 7.5 | 5% |
| — | ||
| CVE-2020-1171 +1 in the same advisory: …1192 | A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads configuration files after opening a project. A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads configuration files after opening a project. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would need to convince a target to clone a repository and open it in Visual Studio Code with the Python extension installed. Attacker-specified code would execute when the target opened the integrated terminal. The update address the vulnerability by modifying the way Visual Studio Code Python extension handles environment variables. NVD description · AI analysis pending | 8.8 group max | 5% |
| — | ||
| CVE-2020-1173 | A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments. A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments. An authenticated attacker could exploit the vulnerability by uploading a specially crafted payload and sending it to the user. The attacker who successfully exploited this vulnerability could then perform actions and run scripts in the security context of the user. This security update addresses the vulnerability by ensuring Power BI Report Server properly validates content-type of the attachments when uploading and opening. NVD description · AI analysis pending | 6.8 | 2% |
| — |
Full article597 words · extracted from blog.talosintelligence.com · click to collapse
Tuesday, May 12, 2020 15:05
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 111 vulnerabilities. Fifteen of the flaws Microsoft disclosed are considered critical. There are also 95 "important" vulnerabilities and six low- and moderate-severity vulnerabilities each.
Cisco Talos specifically disclosed CVE-2020-0901, a code execution vulnerability in Excel. This month’s security update also covers security issues in a variety of Microsoft services and software, including SharePoint, Media Foundation and the Chakra scripting engine.
Talos also released a new set of SNORTⓇ rules that provide coverage for some of these vulnerabilities. For more, check out the full Snort rule advisory here.
Critical vulnerabilities Microsoft disclosed 15 critical vulnerabilities, five of which we will highlight below.
CVE-2020-1023, CVE-2020-1024, CVE-2020-1069 and CVE-2020-1102 are remote code execution vulnerabilities in Microsoft SharePoint. An adversary could exploit any of these vulnerabilities to gain the ability to execute arbitrary code on the victim machine or server, depending on the specific bug. For CVE-2020-1069, an attacker would need to upload a specially crafted packet to a SharePoint server to successfully exploit the bug. The remainder requires the user to open a specially crafted SharePoint file.
CVE-2020-1062 is a memory corruption vulnerability in the Internet Explorer web browser. A user could trigger this vulnerability when they visit a specially crafted, attacker-controlled web page. An adversary could construct the page in such a way that it would corrupt memory on the victim machine, allowing them to execute arbitrary code in the context of the current user. Microsoft's update addresses the way in which Explorer handles objects in memory.
The other critical vulnerabilities disclosed this month are:
- CVE-2020-1028
- CVE-2020-1056
- CVE-2020-1064
- CVE-2020-1065
- CVE-2020-1093
- CVE-2020-1117
- CVE-2020-1126
- CVE-2020-1136
- CVE-2020-1153
- CVE-2020-1192
Important vulnerabilities This release also included 95 important vulnerabilities, one of which we will highlight below.
CVE-2020-1103 is an information disclosure vulnerability in SharePoint that could allow an adversary to carry out cross-site search attacks. The vulnerability arises when users are logged in simultaneously to the same SharePoint server and visit a specially crafted web page. The attacker could then induce the browser to run search queries as the logged-in user, allowing them to obtain information on the logged-in user that could be used in subsequent attacks.
The remainder of the important vulnerabilities are:
- CVE-2020-0901
- CVE-2020-0909
- CVE-2020-0963
- CVE-2020-1010
- CVE-2020-1021
- CVE-2020-1035
- CVE-2020-1048
- CVE-2020-1051
- CVE-2020-1054
- CVE-2020-1055
- CVE-2020-1058
- CVE-2020-1059
- CVE-2020-1060
- CVE-2020-1061
- CVE-2020-1063
- CVE-2020-1066
- CVE-2020-1067
- CVE-2020-1068
- CVE-2020-1070
- CVE-2020-1071
- CVE-2020-1072
- CVE-2020-1075
- CVE-2020-1076
- CVE-2020-1077
- CVE-2020-1078
- CVE-2020-1079
- CVE-2020-1081
- CVE-2020-1082
- CVE-2020-1084
- CVE-2020-1086
- CVE-2020-1087
- CVE-2020-1088
- CVE-2020-1090
- CVE-2020-1092
- CVE-2020-1096
- CVE-2020-1099
- CVE-2020-1100
- CVE-2020-1101
- CVE-2020-1104
- CVE-2020-1105
- CVE-2020-1106
- CVE-2020-1107
- CVE-2020-1108
- CVE-2020-1109
- CVE-2020-1110
- CVE-2020-1111
- CVE-2020-1112
- CVE-2020-1113
- CVE-2020-1114
- CVE-2020-1116
- CVE-2020-1118
- CVE-2020-1121
- CVE-2020-1123
- CVE-2020-1124
- CVE-2020-1125
- CVE-2020-1131
- CVE-2020-1132
- CVE-2020-1134
- CVE-2020-1135
- CVE-2020-1137
- CVE-2020-1138
- CVE-2020-1139
- CVE-2020-1140
- CVE-2020-1141
- CVE-2020-1142
- CVE-2020-1143
- CVE-2020-1144
- CVE-2020-1145
- CVE-2020-1149
- CVE-2020-1150
- CVE-2020-1151
- CVE-2020-1154
- CVE-2020-1155
- CVE-2020-1156
- CVE-2020-1157
- CVE-2020-1158
- CVE-2020-1161
- CVE-2020-1164
- CVE-2020-1165
- CVE-2020-1166
- CVE-2020-1171
- CVE-2020-1173
- CVE-2020-1174
- CVE-2020-1175
- CVE-2020-1176
- CVE-2020-1179
- CVE-2020-1184
- CVE-2020-1185
- CVE-2020-1186
- CVE-2020-1187
- CVE-2020-1188
- CVE-2020-1189
- CVE-2020-1190
- CVE-2020-1191
Important vulnerabilities There is one moderate vulnerability: CVE-2020-1037, a memory corruption vulnerability in the Chakra Scripting Engine.
Coverage In response to these vulnerability disclosures, Talos is releasing a new SNORTⓇ rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Firepower customers should use the latest update to their ruleset by updating their SRU. Open Source Snort Subscriber Rule Set customers can stay up-to-date by downloading the latest rule pack available for purchase on Snort.org.
These rules are: 53916 - 53919, 53924 - 53933, 53940, 53941, 53950, 53951
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-may-2020/