Microsoft Patch Tuesday — March 2020: Vulnerability disclosures and Snort coverage
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-0690 | An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'. An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'. NVD description · AI analysis pending | 9.8 group max | 7% |
| — | ||
| CVE-2020-0758 +1 in the same advisory: …0700 | An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Se An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Server and Team Foundation Services Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0815. NVD description · AI analysis pending | 7.5 group max | 2% |
| — | ||
| CVE-2020-0761 | A remote code execution vulnerability exists when Active Directory integrated DNS (ADIDNS) mishandles objects in memory. A remote code execution vulnerability exists when Active Directory integrated DNS (ADIDNS) mishandles objects in memory. An authenticated attacker who successfully exploited the vulnerability could run arbitrary code in the context of the Local System Account To exploit the vulnerability, an authenticated attacker could send malicious requests to an Active Directory integrated DNS (ADIDNS) server. The update addresses the vulnerability by correcting how Active Directory integrated DNS (ADIDNS) handles objects in memory. NVD description · AI analysis pending | 8.8 | 4% |
| — | ||
| CVE-2020-0765 | An information disclosure vulnerability exists in the Remote Desktop Connection Manager (RDCMan) application when it improperly parses XML input containing a re An information disclosure vulnerability exists in the Remote Desktop Connection Manager (RDCMan) application when it improperly parses XML input containing a reference to an external entity, aka 'Remote Desktop Connection Manager Information Disclosure Vulnerability'. NVD description · AI analysis pending | 5.5 | 5% |
| — | ||
| CVE-2020-0848 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829, CVE-2020-0830, CVE-2020-0831, CVE-2020-0832, CVE-2020-0833. NVD description · AI analysis pending | 7.5 | 10% |
| — | ||
| CVE-2020-0787 | Privilege Escalation in Microsoft Windows Background Intelligent Transfer Service (BITS) CVE-2020-0787 is a privilege elevation flaw in the Windows Background Intelligent Transfer Service (BITS), which improperly handles symbolic links (CWE-269, CWE-59). An attacker who can already run low-privileged code on a machine — via a phishing payload or a chained remote-code-execution bug — can plant or manipulate symbolic links that BITS follows, causing the service to execute arbitrary code with SYSTEM-level privileges. Successful exploitation grants full control of the host, making this a common link in attack chains, and CISA notes known ransomware use. Because BITS ships by default with Windows, essentially every Windows client and server installation predating the vendor patch is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-01-28, and EPSS assigns a 42.5% probability of exploitation within 30 days (99th percentile). Do: Apply Microsoft's updates for CVE-2020-0787 per vendor instructions (the flaw was addressed in Microsoft's March 2020 security updates) across all Windows clients and servers, prioritizing user workstations and internet-facing systems given known ransomware use. Since this is a local privilege escalation, pair patching with controls that block the initial foothold (MFA, email/phishing defenses, EDR). Verify remediation by confirming endpoints report the relevant update installed and no BITS symlink abuse indicators remain. | 7.8 | 43% | KEV ransomware PoC |
| massorder of 1 billion+ Windows installations (unpatched systems at risk; patched systems unaffected) | |
| CVE-2020-0789 | A denial of service vulnerability exists when the Visual Studio Extension Installer Service improperly handles hard links, aka 'Visual Studio Extension Installe A denial of service vulnerability exists when the Visual Studio Extension Installer Service improperly handles hard links, aka 'Visual Studio Extension Installer Service Denial of Service Vulnerability'. NVD description · AI analysis pending | 7.1 | <1% |
| — | ||
| CVE-2020-0795 | This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated att This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePoint server, aka 'Microsoft SharePoint Reflective XSS Vulnerability'. This CVE ID is unique from CVE-2020-0891. NVD description · AI analysis pending | 5.4 | 2% |
| — | ||
| CVE-2020-0796 | Unauthenticated RCE in Microsoft SMBv3 (SMBGhost) CVE-2020-0796 ('SMBGhost') is a memory-corruption (CWE-119) flaw in Microsoft's Server Message Block 3.1.1 (SMBv3) implementation, in which certain crafted requests — notably malformed compressed SMBv3 messages — can corrupt memory on the target. An unauthenticated remote attacker can trigger it by sending specially crafted SMBv3 packets directly to any SMB-enabled host, with no credentials or user interaction required. Successful exploitation yields arbitrary code execution on the target server or client, giving the attacker full control of the host, and the flaw was widely characterized as wormable because a compromised host can then attack others. Any Windows system running SMBv3 is affected — SMBv3 is enabled by default on modern Windows 10 and Windows Server builds, with Windows 10 versions 1903/1909 and Windows Server 2019/versions 1903/1909 identified in Microsoft's advisory. Exploitation is confirmed in the wild: the CVE is in CISA KEV (added 2022-02-10) with known ransomware use, EPSS assigns a 99.8% probability of exploitation within 30 days (100th percentile), and no public PoC is listed in the source data. Do: Apply Microsoft's updates per vendor instructions immediately, prioritizing Windows 10 1903/1909 and Windows Server 2019/1903/1909 hosts and anything with SMB (TCP 445) reachable by untrusted networks. Until patched, disable SMBv3 compression per Microsoft's mitigation guidance (setting DisableCompression=1 under LanmanServer) and restrict inbound TCP 445 to trusted sources. Given confirmed ransomware use, hunt for post-exploitation activity on unpatched hosts. | 10.0 | 100% | KEV ransomware PoC ×2 |
| masstens of millions of Windows hosts with SMBv3 enabled; on the order of 1M+ hosts with SMB (TCP 445) exposed to the internet per public scans | |
| CVE-2020-0810 | An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector allows file creation in arbit An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system.An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.The update addresses the vulnerability by not permitting Diagnostics Hub Standard Collector or the Visual Studio Standard Collector to create files in arbitrary locations., aka 'Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability'. NVD description · AI analysis pending | 7.8 | 1% |
| — | ||
| CVE-2020-0815 | An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Se An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Server and Team Foundation Services Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0758. NVD description · AI analysis pending | 7.5 | 2% |
| — | ||
| CVE-2020-0816 | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'. A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'. NVD description · AI analysis pending | 8.8 group max | 11% |
| — | ||
| CVE-2020-0830 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corru A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829, CVE-2020-0831, CVE-2020-0832, CVE-2020-0833, CVE-2020-0848. NVD description · AI analysis pending | 7.5 | 9% |
| — | ||
| CVE-2020-0835 | An elevation of privilege vulnerability exists when Windows Defender antimalware platform improperly handles hard links, aka 'Windows Defender Antimalware Platf An elevation of privilege vulnerability exists when Windows Defender antimalware platform improperly handles hard links, aka 'Windows Defender Antimalware Platform Hard Link Elevation of Privilege Vulnerability'. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2020-0850 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Exec A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0851, CVE-2020-0852, CVE-2020-0855, CVE-2020-0892. NVD description · AI analysis pending | 8.8 group max | 9% |
| — | ||
| CVE-2020-0872 | A remote code execution vulnerability exists in Application Inspector version v1.0.23 or earlier when the tool reflects example code snippets from third-party s A remote code execution vulnerability exists in Application Inspector version v1.0.23 or earlier when the tool reflects example code snippets from third-party source files into its HTML output, aka 'Remote Code Execution Vulnerability in Application Inspector'. NVD description · AI analysis pending | 9.6 | 10% |
| — | ||
| CVE-2020-0884 | A spoofing vulnerability exists in Microsoft Visual Studio as it includes a reply URL that is not secured by SSL, aka 'Microsoft Visual Studio Spoofing Vulnerab A spoofing vulnerability exists in Microsoft Visual Studio as it includes a reply URL that is not secured by SSL, aka 'Microsoft Visual Studio Spoofing Vulnerability'. NVD description · AI analysis pending | 3.7 | 2% |
| — | ||
| CVE-2020-0891 | This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated att This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePoint server, aka 'Microsoft SharePoint Reflective XSS Vulnerability'. This CVE ID is unique from CVE-2020-0795. NVD description · AI analysis pending | 5.4 | 2% |
| — | ||
| CVE-2020-0902 | An elevation of privilege vulnerability exists in Service Fabric File Store Service under certain conditions, aka 'Service Fabric Elevation of Privilege'. An elevation of privilege vulnerability exists in Service Fabric File Store Service under certain conditions, aka 'Service Fabric Elevation of Privilege'. NVD description · AI analysis pending | 9.8 | 3% |
| — | ||
| CVE-2020-0903 | A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Excha A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'. NVD description · AI analysis pending | 5.4 | 2% |
| — |
Full article820 words · extracted from blog.talosintelligence.com · click to collapse
Tuesday, March 10, 2020 13:23
By Jon Munshaw and Vitor Ventura.
Update (March 12, 2020): Microsoft released an out-of-band patch for CVE-2020-0796, a code execution vulnerability SMB client and server for Windows. An unauthenticated attacker could exploit this vulnerability to execute remote code. Snort rules 53425 - 53428 protect against exploitation of CVE-2020-0796.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 117 vulnerabilities, 25 of which are considered critical. There is also one moderate vulnerability and 91 that are considered important.
This month's patches include updates to Microsoft Media Foundation, the GDI+ API and Windows Defender, among others.
Talos released a new set of SNORTⓇ rules today that provide coverage for some of these vulnerabilities, which you can see here.
Critical vulnerabilities Microsoft disclosed 25 critical vulnerabilities this month, 20 of which we will highlight below.
CVE-2020-0684 is a remote code execution vulnerability in Microsoft Windows that arises if the user opens a specially crafted, malicious .LNK file. This file could be presented to the victim on a removable drive or remote share, and then when opened, would execute a malicious binary embedded in the file.
CVE-2020-0801, CVE-2020-0807, CVE-2020-0809 and CVE-2020-0869 are memory corruption vulnerabilities in Microsoft Media Foundation. All of these could allow an attacker to gain the ability to install programs, view, change or delete data or create new user accounts on the victim machine. A user could trigger this vulnerability by opening a specially crafted, malicious file or web page. Attackers are most likely to try and exploit this vulnerability via spam emails with malicious links and attachments.
CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829, CVE-2020-0831, CVE-2020-0832, CVE-2020-0833 and CVE-2020-0848 are all memory corruption vulnerabilities in the way the ChakraCore scripting engine handles objects in memory. If successful, an attacker could corrupt the victim machine's memory in a way that would allow them to execute arbitrary code in the context of the current user.
CVE-2020-0824 and CVE-2020-0847 are remote code execution vulnerabilities in the VBScript engine. An attacker could exploit these bugs by tricking the user into visiting a specially crafted website in the Internet Explorer web browser or by marking an ActiveX control marked "safe for initialization" in an application or Microsoft Office document that hosts the Internet Explorer rendering engine. These bugs specifically require user interaction and would rely on some form of social engineering on the attacker's part.
CVE-2020-0881 and CVE-2020-0883 are remote code execution vulnerabilities in GDI+, an API for C and C++ programmers. An attacker could exploit these bugs by hosting a specially crafted website and then convincing the user to open it. Additionally, a victim could open a malicious document designed to exploit this vulnerability that's provided to them via email or any other file-sharing method.
These are the other critical vulnerabilities:
Important vulnerabilities This release also contains 91 important vulnerabilities, five of which we will highlight.
CVE-2020-0850, CVE-2020-0851, CVE-2020-0852 and CVE-2020-0855 are all remote code execution vulnerabilities that exist in the way Microsoft Word handles objects in memory. If successful, the attacker could use these bugs to carry out malicious actions in the context of the current user via the Word document. Attackers are likely to use spam emails to try and distribute these malicious documents.
CVE-2020-0761 is a remote code execution vulnerability that exists in Active Directory. This vulnerability occurs when Active Directory integrated DNS (ADIDNS) mishandles objects in memory. The can result in autheniticated code execution in the context of the Local System Account. This attack is triggered by an authenticated user sending malicious requests to an Active Directory integrated DNS server.
The other important vulnerabilities are:
- CVE-2020-0645
- CVE-2020-0690
- CVE-2020-0700
- CVE-2020-0758
- CVE-2020-0762
- CVE-2020-0763
- CVE-2020-0769
- CVE-2020-0770
- CVE-2020-0771
- CVE-2020-0772
- CVE-2020-0773
- CVE-2020-0774
- CVE-2020-0775
- CVE-2020-0776
- CVE-2020-0777
- CVE-2020-0778
- CVE-2020-0779
- CVE-2020-0780
- CVE-2020-0781
- CVE-2020-0783
- CVE-2020-0785
- CVE-2020-0786
- CVE-2020-0787
- CVE-2020-0788
- CVE-2020-0789
- CVE-2020-0791
- CVE-2020-0793
- CVE-2020-0795
- CVE-2020-0797
- CVE-2020-0798
- CVE-2020-0799
- CVE-2020-0800
- CVE-2020-0802
- CVE-2020-0803
- CVE-2020-0804
- CVE-2020-0806
- CVE-2020-0808
- CVE-2020-0810
- CVE-2020-0813
- CVE-2020-0814
- CVE-2020-0815
- CVE-2020-0819
- CVE-2020-0820
- CVE-2020-0822
- CVE-2020-0834
- CVE-2020-0835
- CVE-2020-0840
- CVE-2020-0841
- CVE-2020-0842
- CVE-2020-0843
- CVE-2020-0844
- CVE-2020-0845
- CVE-2020-0853
- CVE-2020-0854
- CVE-2020-0857
- CVE-2020-0858
- CVE-2020-0859
- CVE-2020-0860
- CVE-2020-0861
- CVE-2020-0863
- CVE-2020-0864
- CVE-2020-0865
- CVE-2020-0866
- CVE-2020-0867
- CVE-2020-0868
- CVE-2020-0871
- CVE-2020-0872
- CVE-2020-0874
- CVE-2020-0876
- CVE-2020-0877
- CVE-2020-0879
- CVE-2020-0880
- CVE-2020-0882
- CVE-2020-0884
- CVE-2020-0885
- CVE-2020-0887
- CVE-2020-0891
- CVE-2020-0892
- CVE-2020-0893
- CVE-2020-0894
- CVE-2020-0896
- CVE-2020-0897
- CVE-2020-0898
- CVE-2020-0902
- CVE-2020-0903
- CVE-2020-0849
Important vulnerabilities
There is also one moderate vulnerability, CVE-2020-0765.
Coverage In response to these vulnerability disclosures, Talos is releasing a new SNORTⓇ rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Firepower customers should use the latest update to their ruleset by updating their SRU. Open Source Snort Subscriber Rule Set customers can stay up-to-date by downloading the latest rule pack available for purchase on Snort.org.
These rules are: 52213, 52214, 53402 - 53409, 53414 - 53419, 53420 - 53424
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-march-2020/