February 2020 Patch Tuesday: Microsoft fixes 99 vulnerabilities, Adobe 42
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-0729 +1 in the same advisory: …0662 | A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfull A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'. NVD description · AI analysis pending | 8.8 | 31% |
| — | ||
| CVE-2020-0674 | Use-After-Free RCE in Microsoft Internet Explorer Scripting Engine CVE-2020-0674 is a use-after-free memory corruption flaw (CWE-416) in the way the Internet Explorer scripting engine handles objects in memory, distinct from a series of sibling scripting-engine RCEs fixed at the same time (CVE-2020-0673, 0710, 0711, 0712, 0713, 0767). Triggering it requires user interaction: an attacker must convince a user to view a specially crafted web page (for example via a phishing link or malicious web content) while it renders in Internet Explorer, and the mishandled memory then allows code execution under the high-complexity, network-reachable conditions reflected in the CVSS vector (AV:N/AC:H/UI:R). Successful exploitation gives the attacker remote code execution with the privileges of the logged-in user, so the practical risk is highest for users browsing with Internet Explorer on Windows, including IE 8 through IE 11 targeted by the public exploits. Exploitation is confirmed in the wild: Microsoft warned of the flaw as an unpatched zero-day being used in targeted attacks before its February 2020 Patch Tuesday fix, public PoC/exploit code is available (including a working exploit for IE 8-11), the Magnitude exploit kit referenced in coverage used it as a delivery vector, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 alongside a very high EPSS score (86.9% probability of exploitation in 30 days, 100th percentile). The required remediation is to apply the Microsoft security updates from February 2020 that address this CVE. Do: Apply the Microsoft February 2020 Patch Tuesday security updates that fix CVE-2020-0674 on all Windows endpoints and servers, prioritizing per the CISA KEV required action. Until patched, limit Internet Explorer use to trusted sites and consider Microsoft's suggested mitigations (such as restricting active scripting); note that third-party micropatches existed that emulated the vendor workaround without its usability side effects. After patching, verify IE11 remediation status across the estate and, where feasible, retire Internet Explorer usage entirely to reduce exposure to this recurring scripting-engine bug class. | 7.5 | 87% | KEV PoC ×4 |
| masshundreds of millions of Windows endpoints (IE 11 was bundled with every supported Windows release at disclosure) | |
| CVE-2020-0688 | RCE in Microsoft Exchange Server from Shared Install-Time Validation Keys CVE-2020-0688 is a remote code execution vulnerability in Microsoft Exchange Server caused by the validation key not being uniquely created at install time, leaving deployments with a predictable, shared key (CWE-287, improper authentication). A remote attacker who can reach an affected Exchange server and knows the common install-time key can supply maliciously crafted, cryptographically signed payloads that the server trusts, triggering code execution without needing per-server secrets. Successful exploitation gives the attacker code execution on the Exchange server, which can be used to access mail data, move laterally, and stage follow-on activity; CISA notes known use in ransomware campaigns. All organizations running the affected on-premises Microsoft Exchange Server are in scope per CISA's listing, though the affected version range is not specified in the source data. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2021-11-03 with known ransomware use, and EPSS rates 30-day exploitation probability at 100% (top percentile). Do: Apply Microsoft's Exchange security updates addressing CVE-2020-0688 (released in February 2020) to every on-premises Exchange server, per CISA's required action. As an interim mitigation, configure a unique ASP.NET machineKey in each Exchange server's web.config instead of the default shared install-time key, and hunt for indicators of exploitation given the known ransomware use. | 8.8 | 100% | KEV ransomware PoC ×2 |
| masshundreds of thousands of on-premises Exchange servers (≈500,000) |
Full article544 words · extracted from helpnetsecurity.com · click to collapse
February 2020 Patch Tuesday is here. To mark the occasion, Microsoft has released fixes for 99 vulnerabilities – 12 critical, one of which is being exploited in the wild – and Adobe 42, most of which are critical and none actively exploited.

Adobe patches
Security updates have been provided for various products:
- Framemaker, a document processor designed for writing and editing large or complex documents
- Acrobat and Reader (for PDF file creation, encryption, publishing, viewing, printing, etc.)
- Flash Player (the name says it all)
- Digital Editions (reader software for eBooks and other digital publications)
- Experience Manager (a web-based client-server system for building, managing and deploying commercial websites and related services).
Given that 38 out of the 42 flaws patched by Adobe this Tuesday are rated critical, I would venture to say that all the updates except the Experience Manager should be implemented quickly.
That said, users and admins should definitely give priority to some of Microsoft’s patches.
Microsoft patches
As noted before, Microsoft fixed nearly 100 vulnerabilities this Tuesday, interspersed through a number of products: Windows, Edge, IE, SQL Server, Exchange Server, Office, and more.
Five of the vulnerabilities fixed in this batch are publicly known and one (critical) is under active attack: CVE-2020-0674.
CVE-2020-0674 is a memory corruption vulnerability that allows remote code execution and affects Internet Explorer. Its existence and exploitation in “limited targeted attacks” was revealed mid-January, through an out-of-band security advisory.
At the time, Microsoft offered mitigation steps, but no fix. A few days later ACROS Security released a micropatch that implements the workaround. Now, finally, Microsoft released fixes.
“Even if you don’t use IE, you could still be affected by this bug though embedded objects in Office documents. Considering the listed workaround – disabling jscript.dll – breaks a fair amount of functionality, you should prioritize the testing and deployment of this patch,” Trend Micro’s Zero Day Initiative’s Dustin Childs advised.
He also singled out CVE-2020-0688, a code execution bug affecting Microsoft Exchange, as critical, as it’s easily exploitable (via a specially crafted email) and CVE-2020-0729, a RCE impacting link files (.LNK), similar to the one used to deliver Stuxnet to air-gapped systems.
Jimmy Graham, Senior Director of PM, Vulnerability at Qualys, pointed out CVE-2020-0662, a Windows RCE flaw, as worthy of attention and a quick implementation of the offered fix. The flaw can lead to RCE if an attacker has Domain User credentials.
“While this vulnerability is labeled as ‘Exploitation Less Likely,’ this vulnerability can be attacked over the network with no user interaction according to the CVSS Vector Strings set by Microsoft. The impacted service is not stated in the bulletin. Based on the information given, this should be prioritized across all Windows servers and workstations,” he advised.
He also urged admins to prioritize Scripting Engine, LNK files, and Media Foundation patches for workstation-type devices.
“Overall, this is a very heavy Patch Tuesday on the Microsoft end,” noted Jay Goodman, Technical Marketing Manager at Automox.
“The race to patch critical vulnerabilities on your systems within the next 72 hours is on. Attackers will have no shortage of exploitable vulnerabilities and new attack vectors to bring to bear in the coming days with nearly every build of Windows accounted for with critical vulnerabilities.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2020/02/11/february-2020-patch-tuesday/