Microsoft Patch Tuesday — April 2020: Vulnerability disclosures and Snort coverage
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-0687 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote C A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'. NVD description · AI analysis pending | 8.8 group max | 19% |
| — | ||
| CVE-2020-0760 | A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulner A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0991. NVD description · AI analysis pending | 8.8 | 9% |
| — | ||
| CVE-2020-0835 +1 in the same advisory: …1002 | An elevation of privilege vulnerability exists when Windows Defender antimalware platform improperly handles hard links, aka 'Windows Defender Antimalware Platf An elevation of privilege vulnerability exists when Windows Defender antimalware platform improperly handles hard links, aka 'Windows Defender Antimalware Platform Hard Link Elevation of Privilege Vulnerability'. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2020-0968 | Memory Corruption RCE in Microsoft Internet Explorer Scripting Engine CVE-2020-0968 is a memory corruption vulnerability (CWE-787, out-of-bounds write) in Microsoft Internet Explorer's scripting engine, where the engine mishandles objects in memory in a way that can be leveraged for remote code execution. It is typically triggered when a user views a specially crafted webpage in Internet Explorer or in an application that hosts the IE rendering components; successful exploitation gives the attacker code execution in the context of the current user. Any Windows environment where Internet Explorer and its scripting engine are present is affected, which spans most enterprise and consumer Windows estates. Exploitation is confirmed in the wild: the flaw is listed in CISA's KEV catalog (added 2021-11-03) with known ransomware use, and EPSS assigns a 30.7% probability of exploitation within 30 days (98th percentile). No public proof-of-concept is known, indicating attackers are not dependent on public PoC code. Do: Apply the Microsoft security updates that fix CVE-2020-0968 (released in the March 2020 Patch Tuesday batch) across all Windows systems with Internet Explorer, prioritizing user workstations and remote desktop/terminal servers per CISA's required action to apply vendor updates. Since the exploit path runs through web content, verify whether legacy web apps or desktop applications still invoke the IE engine and reduce reliance on IE as a default renderer. Confirm remediation by checking for the corresponding cumulative Windows/IE update rather than relying on a single KB lookup. | 7.5 group max | 31% | KEV ransomware |
| masshundreds of millions of Windows endpoints (IE is a built-in OS component) | |
| CVE-2020-0899 | An elevation of privilege vulnerability exists when Microsoft Visual Studio updater service improperly handles file permissions, aka 'Microsoft Visual Studio El An elevation of privilege vulnerability exists when Microsoft Visual Studio updater service improperly handles file permissions, aka 'Microsoft Visual Studio Elevation of Privilege Vulnerability'. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2020-0900 | An elevation of privilege vulnerability exists when the Visual Studio Extension Installer Service improperly handles file operations, aka 'Visual Studio Extensi An elevation of privilege vulnerability exists when the Visual Studio Extension Installer Service improperly handles file operations, aka 'Visual Studio Extension Installer Service Elevation of Privilege Vulnerability'. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2020-0906 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remo A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0979. NVD description · AI analysis pending | 8.8 | 12% |
| — | ||
| CVE-2020-0919 | An elevation of privilege vulnerability exists in Remote Desktop App for Mac in the way it allows an attacker to load unsigned binaries, aka 'Microsoft Remote D An elevation of privilege vulnerability exists in Remote Desktop App for Mac in the way it allows an attacker to load unsigned binaries, aka 'Microsoft Remote Desktop App for Mac Elevation of Privilege Vulnerability'. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2020-0932 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsof A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0931, CVE-2020-0971, CVE-2020-0974. NVD description · AI analysis pending | 8.8 group max | 31% |
| — | ||
| CVE-2020-0931 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsof A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0932, CVE-2020-0971, CVE-2020-0974. NVD description · AI analysis pending | 8.8 | 11% |
| — | ||
| CVE-2020-0935 | An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links, aka 'OneDrive for Windows El An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links, aka 'OneDrive for Windows Elevation of Privilege Vulnerability'. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2020-1020 | Out-of-Bounds Write RCE in Microsoft Windows Adobe Font Manager Library CVE-2020-1020 is a remote code execution vulnerability (out-of-bounds write, CWE-787) in the Adobe Font Manager Library shipped with Microsoft Windows, caused by improper handling of a specially crafted multi-master font in Adobe Type 1 PostScript format. Triggering it requires user interaction: an attacker delivers a malicious document or font, and the vulnerable code runs when the content is previewed or opened (no authentication is needed on the network path, but the user must interact). On all systems except Windows 10, successful exploitation allows the attacker to execute arbitrary code remotely in the context of the current user; on Windows 10 the flaw is present as well, with the full remote-code-execution impact described for non-Windows-10 systems. Affected software spans Windows 10 versions 1507 through 1909, Windows 7, Windows 8.1, Windows RT 8.1, and Windows Server 1903/1909. The bug was exploited in the wild as a zero-day by a sophisticated threat actor prior to patching (CISA KEV, added 2021-11-03), and EPSS assigns a 65% probability of exploitation within 30 days (99th percentile). Do: Apply Microsoft's security update for CVE-2020-1020 via Windows Update (April 2020 Patch Tuesday cycle) on all Windows 7, 8.1, RT 8.1, Windows 10 1507-1909, and Windows Server 1903/1909 hosts, per CISA's required action. As interim mitigation, disable the Explorer preview and details panes and avoid opening or previewing untrusted documents and fonts. Verify the fix is deployed, prioritizing non-Windows-10 systems where successful exploitation yields full remote code execution. | 8.8 group max | 65% | KEV |
| masshundreds of millions of Windows client/server devices (OS component shipped in all listed Windows releases) | |
| CVE-2020-0943 | An authentication bypass vulnerability exists in Microsoft YourPhoneCompanion application for Android, in the way the application processes notifications genera An authentication bypass vulnerability exists in Microsoft YourPhoneCompanion application for Android, in the way the application processes notifications generated by work profiles.This could allow an unauthenticated attacker to view notifications, aka 'Microsoft YourPhone Application for Android Authentication Bypass Vulnerability'. NVD description · AI analysis pending | 4.6 | 1% |
| — | ||
| CVE-2020-0954 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected Sha A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0923, CVE-2020-0924, CVE-2020-0925, CVE-2020-0926, CVE-2020-0927, CVE-2020-0930, CVE-2020-0933, CVE-2020-0973, CVE-2020-0978. NVD description · AI analysis pending | 5.4 | 2% |
| — | ||
| CVE-2020-0957 | An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0956, CVE-2020-0958. NVD description · AI analysis pending | 7.8 | 1% |
| — | ||
| CVE-2020-0961 | A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Ac A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. NVD description · AI analysis pending | 7.8 | 12% |
| — | ||
| CVE-2020-0969 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Chakra S A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. NVD description · AI analysis pending | 7.5 | 13% |
| — | ||
| CVE-2020-0970 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0968. NVD description · AI analysis pending | 7.5 | 13% |
| — | ||
| CVE-2020-0979 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remo A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0906. NVD description · AI analysis pending | 8.8 | 12% |
| — | ||
| CVE-2020-0984 | An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly validates updates before executing them, aka ' An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly validates updates before executing them, aka 'Microsoft (MAU) Office Elevation of Privilege Vulnerability'. NVD description · AI analysis pending | 7.8 | 1% |
| — | ||
| CVE-2020-1022 +1 in the same advisory: …1018 | A remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'. A remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'. NVD description · AI analysis pending | 8.0 group max | 7% |
| — | ||
| CVE-2020-1019 | An elevation of privilege vulnerability exists in RMS Sharing App for Mac in the way it allows an attacker to load unsigned binaries, aka 'Microsoft RMS Sharing An elevation of privilege vulnerability exists in RMS Sharing App for Mac in the way it allows an attacker to load unsigned binaries, aka 'Microsoft RMS Sharing App for Mac Elevation of Privilege Vulnerability'. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2020-1026 | A Security Feature Bypass vulnerability exists in the MSR JavaScript Cryptography Library that is caused by multiple bugs in the library’s Elliptic Curve Cryp A Security Feature Bypass vulnerability exists in the MSR JavaScript Cryptography Library that is caused by multiple bugs in the library’s Elliptic Curve Cryptography (ECC) implementation.An attacker could potentially abuse these bugs to learn information about a server’s private ECC key (a key leakage attack) or craft an invalid ECDSA signature that nevertheless passes as valid.The security update addresses the vulnerability by fixing the bugs disclosed in the ECC implementation, aka 'MSR JavaScript Cryptography Library Security Feature Bypass Vulnerability'. NVD description · AI analysis pending | 9.8 | 3% |
| — | ||
| CVE-2020-1050 +1 in the same advisory: …1049 | A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. This CVE ID is unique from CVE-2020-1049. NVD description · AI analysis pending | 6.1 group max | 2% |
| — |
Full article1,066 words · extracted from blog.talosintelligence.com · click to collapse
Tuesday, April 14, 2020 14:08
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 115 vulnerabilities. Nineteen of the flaws Microsoft disclosed are considered critical. The remainders are scored as being “important” updates.
This month’s security update covers security issues in a variety of Microsoft services and software, including SharePoint, the Windows font library and the Windows kernel. A Cisco Talos researcher discovered CVE-2020-0939, an information disclosure vulnerability in Microsoft Media Foundation. For more, check out Talos’ full Vulnerability Spotlight here.
Talos also released a new set of SNORTⓇ rules that provide coverage for some of these vulnerabilities. For more, check out the Snort blog post here.
Critical vulnerabilities Microsoft disclosed 19 critical vulnerabilities, 10 of which we will highlight below.
CVE-2020-0687 is a remote code execution vulnerability that exists in the way the Windows font library handles some embedded fonts stored in memory. An attacker could exploit this bug by tricking a victim into visiting a specially crafted website or opening a malicious file that contains an affected embedded font. This vulnerability acts in a way that would allow a malicious actor to gain complete control of the affected machine, giving them the ability to install new programs, manipulating data and creating new user accounts.
CVE-2020-0907 is a remote code execution vulnerability in Microsoft Graphics Components that arises when the system improperly handles objects in memory. This bug can only be triggered when a user opens a specially crafted file. The attacker could then gain the ability to execute arbitrary code.
CVE-2020-0929, CVE-2020-0931, CVE-2020-0932 are remote code execution vulnerabilities in Microsoft SharePoint. To exploit these vulnerabilities, an attacker needs to upload a specially crafted SharePoint package to an affected version of SharePoint, allowing them to execute arbitrary code in the SharePoint application pool and the SharePoint server.
CVE-2020-0938 and CVE-2020-1020 are remote code execution vulnerabilities that arises when Windows Adobe Type Manager Library processes certain types of OpenType and multi-master font - Adobe Type 1 PostScript fonts, respectively. If an attacker were to exploit this bug on any operating system other than Windows 10, they could gain the ability to execute arbitrary code remotely. On Windows 10, they would be limited to executing code in the AppContainer sandbox with limited privileges.
CVE-2020-0968 and CVE-2020-0970 are memory corruption vulnerabilities in the Windows scripting engine inside the Internet Explorer web browser. These bugs could corrupt memory in such a way that would allow an attacker to execute arbitrary code in the context of the current user. An adversary could exploit these vulnerabilities by tricking a user into visiting a specially crafted site in Internet Explorer. Alternatively, they could embed an ActiveX control marked "safe for initialization" in a Microsoft Office document or other application that hosts the Internet Explorer rendering engine, and then trick the user into opening that file.
CVE-2020-0969 is a memory corruption vulnerability in the Microsoft Edge web browser’s Chakra scripting engine. An attacker could exploit this flaw by tricking a user into visiting a specially crafted, malicious website. This would then corrupt the memory on the victim machine in such a way that the actor could gain the ability to execute arbitrary code in the context of the current user.
The other critical vulnerabilities disclosed this month are:
- CVE-2020-0910
- CVE-2020-0927
- CVE-2020-0948
- CVE-2020-0949
- CVE-2020-0950
- CVE-2020-0965
- CVE-2020-0967
- CVE-2020-0974
- CVE-2020-1022
Important vulnerabilities This release also contains 96 important vulnerabilities, eight of which we will highlight below.
CVE-2020-0760 is a remote code execution vulnerability in Microsoft Office that arises when a victim opens a specially crafted, malicious Office document. The flaw exists in when Office improperly handles certain type libraries — allowing the attacker to execute arbitrary code in the context of the current user.
CVE-2020-0784 is an elevation of privilege vulnerability in DirectX that could allow a malicious actor to execute arbitrary code in kernel mode. To successfully exploit this flaw, an attacker needs to log onto the affected system, and then run a specially crafted application.
CVE-2020-0956, CVE-2020-0957, CVE-2020-0958 are all elevation of privilege vulnerabilities in the Windows kernel-mode driver that could allow an attacker to execute arbitrary code in kernel mode. To successfully exploit this flaw, an attacker needs to log onto the affected system, and then run a specially crafted application.
CVE-2020-1004 is an elevation of privilege vulnerability in Windows Graphics Component. Exploitation of this vulnerability can only take place in the local context, requiring a malicious user to run a specially crafted application of the victim machine. If successful, the attacker could run certain processes in an elevated context.
CVE-2020-1005 is an information disclosure vulnerability in the Windows Graphics Component that arises when the software improperly handles objects in memory. An attacker could exploit this flaw by logging on to an affected machine and running a specially crafted application. This could force the victim machine to disclose sensitive information that the attacker could then use in additional attacks.
CVE-2020-1027 is an elevation of privilege vulnerability in the Windows Kernel that could allow a malicious user to gain the ability to execute arbitrary code with elevated privileges. The malicious actor would need to be already locally authenticated, and then run a specially crafted application.
The other important vulnerabilities are:
- CVE-2020-0699
- CVE-2020-0794
- CVE-2020-0821
- CVE-2020-0835
- CVE-2020-0888
- CVE-2020-0889
- CVE-2020-0895
- CVE-2020-0899
- CVE-2020-0900
- CVE-2020-0906
- CVE-2020-0913
- CVE-2020-0917
- CVE-2020-0918
- CVE-2020-0919
- CVE-2020-0920
- CVE-2020-0923
- CVE-2020-0924
- CVE-2020-0925
- CVE-2020-0926
- CVE-2020-0930
- CVE-2020-0933
- CVE-2020-0934
- CVE-2020-0935
- CVE-2020-0936
- CVE-2020-0937
- CVE-2020-0938
- CVE-2020-0939
- CVE-2020-0940
- CVE-2020-0942
- CVE-2020-0943
- CVE-2020-0944
- CVE-2020-0945
- CVE-2020-0946
- CVE-2020-0947
- CVE-2020-0952
- CVE-2020-0953
- CVE-2020-0954
- CVE-2020-0955
- CVE-2020-0959
- CVE-2020-0960
- CVE-2020-0961
- CVE-2020-0962
- CVE-2020-0964
- CVE-2020-0966
- CVE-2020-0971
- CVE-2020-0972
- CVE-2020-0973
- CVE-2020-0975
- CVE-2020-0976
- CVE-2020-0977
- CVE-2020-0978
- CVE-2020-0979
- CVE-2020-0980
- CVE-2020-0981
- CVE-2020-0982
- CVE-2020-0983
- CVE-2020-0984
- CVE-2020-0985
- CVE-2020-0987
- CVE-2020-0988
- CVE-2020-0991
- CVE-2020-0992
- CVE-2020-0993
- CVE-2020-0994
- CVE-2020-0995
- CVE-2020-0996
- CVE-2020-0999
- CVE-2020-1000
- CVE-2020-1001
- CVE-2020-1002
- CVE-2020-1003
- CVE-2020-1006
- CVE-2020-1007
- CVE-2020-1008
- CVE-2020-1009
- CVE-2020-1011
- CVE-2020-1014
- CVE-2020-1015
- CVE-2020-1016
- CVE-2020-1017
- CVE-2020-1018
- CVE-2020-1019
- CVE-2020-1020
- CVE-2020-1026
- CVE-2020-1029
- CVE-2020-1049
- CVE-2020-1050
- CVE-2020-1094
Coverage In response to these vulnerability disclosures, Talos is releasing a new SNORTⓇ rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Firepower customers should use the latest update to their ruleset by updating their SRU. Open Source Snort Subscriber Rule Set customers can stay up-to-date by downloading the latest rule pack available for purchase on Snort.org.
These rules are: 53489 - 53492, 53619 - 53630, 53652 - 53655
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-april-2020/