Microsoft May 2020 Patch Tuesday fixes 111 flaws, 13 Critical
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-0901 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Excel. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) containing a specially crafted file designed to exploit the vulnerability. An attacker would have no way to force users to visit the website. Instead, an attacker would have to convince users to click a link, typically by way of an enticement in an email or instant message, and then convince them to open the specially crafted file. The security update addresses the vulnerability by correcting how Microsoft Excel handles objects in memory. NVD description · AI analysis pending | 9.8 | 4% |
| — | ||
| CVE-2020-1117 | A remote code execution vulnerability exists in the way that the Color Management Module (ICM32.dll) handles objects in memory. A remote code execution vulnerability exists in the way that the Color Management Module (ICM32.dll) handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability and then convince users to view the website. An attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action, typically by getting them to click a link in an email or Instant Messenger message that takes users to the attacker's website, or by opening an attachment sent through email. The security update addresses the vulnerability by correcting how Color Management Module handles objects in memory. NVD description · AI analysis pending | 8.8 group max | 4% |
| — | ||
| CVE-2020-1102 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account. Exploitation of this vulnerability requires that a user uploads a specially crafted SharePoint application package to an affected version of SharePoint. The security update addresses the vulnerability by correcting how SharePoint checks the source markup of application packages. NVD description · AI analysis pending | 8.8 group max | 5% |
| — | ||
| CVE-2020-1062 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, the attacker could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker could host a specially crafted website designed to exploit the vulnerability through Internet Explorer and then convince a user to view the website. The attacker could also take advantage of compromised websites, or websites that accept or host user-provided content or advertisements, by adding specially crafted content that could exploit the vulnerability. However, in all cases an attacker would have no way to force a user to view the attacker-controlled content. Instead, an attacker would have to convince a user to take action, typically by an enticement in an email or instant message, or by getting the user to open an attachment sent through email. The security update addresses the vulnerability by modifying how Internet Explorer handles objects in memory. NVD description · AI analysis pending | 7.5 | 6% |
| — | ||
| CVE-2020-1056 | An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access info An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain. In a web-based attack scenario, an attacker could host a website that is used to attempt to exploit the vulnerability. In addition, compromised websites and websites that accept or host user-provided content could contain specially crafted content that could exploit the vulnerability. However, in all cases an attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action. For example, an attacker could trick users into clicking a link that takes them to the attacker's site. An attacker who successfully exploited this vulnerability could elevate privileges in affected versions of Microsoft Edge. The security update addresses the vulnerability by helping to ensure that cross-domain policies are properly enforced in Microsoft Edge. NVD description · AI analysis pending | 5.4 group max | 2% |
| — | ||
| CVE-2020-1054 | Privilege Escalation in Microsoft Windows Win32k Kernel Driver (CVE-2020-1054) CVE-2020-1054 is an elevation-of-privilege flaw (CWE-787, an out-of-bounds memory access) in the Windows kernel-mode driver (win32k), which fails to properly handle objects in memory. To exploit it, an attacker who can already log on to an affected Windows machine must run a specially crafted application, which triggers the memory-handling error and allows arbitrary code execution in kernel mode. Successful exploitation effectively yields full SYSTEM-level control of the host: the attacker can install programs, view, change or delete any data, and create new accounts with full user rights. Affected products per the CPE data are Windows 7, 8.1, RT 8.1, Windows 10 versions 1507 through 1909, and Windows Server 1803 and 1903. The flaw was fixed in Microsoft's May 2020 Patch Tuesday, a public DrawIconEx-based local privilege escalation PoC exists, EPSS is 54.2% (99th percentile), and CISA added it to the KEV catalog on 2021-11-03, confirming exploitation in the wild; related threat reporting around this CVE ties it to malware campaigns such as PurpleFox and Raspberry Robin, while ransomware use is listed as unknown. Do: Apply Microsoft's May 2020 security updates (or any later cumulative update) to Windows 7, 8.1, RT 8.1, Windows 10 1507–1909, and Windows Server 1803/1903, per the CISA KEV required action; prioritize multi-user hosts such as RDS servers where low-privileged users can run code. For legacy systems that no longer receive updates (e.g., Windows 7/8.1 post-EOL), limit local logon and software-execution rights for untrusted users and monitor for local privilege escalation activity. | 7.0 | 54% | KEV PoC |
| mass≈1 billion Windows devices (global Windows 10 install base plus the legacy Windows 7/8.1 estate) | |
| CVE-2020-1063 | A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected Dynamics server. The attacker who successfully exploited the vulnerability could then perform cross-site scripting attacks on affected systems and run script in the security context of the current authenticated user. These attacks could allow the attacker to read content that the attacker is not authorized to read, use the victim's identity to take actions within Dynamics Server on behalf of the user, such as change permissions and delete content, and inject malicious content in the browser of the user. The security update addresses the vulnerability by helping to ensure that Dynamics Server properly sanitizes web requests. NVD description · AI analysis pending | 5.4 | 1% |
| — | ||
| CVE-2020-1065 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. The security update addresses the vulnerability by modifying how the ChakraCore scripting engine handles objects in memory. NVD description · AI analysis pending | 4.2 | 2% |
| — | ||
| CVE-2020-1066 | An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level. An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level. To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program. The update addresses the vulnerability by correcting how .NET Framework activates COM objects. NVD description · AI analysis pending | 7.8 | 2% |
| — | ||
| CVE-2020-1108 | A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application. The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests. NVD description · AI analysis pending | 7.5 | 6% |
| — | ||
| CVE-2020-1161 | A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the ASP.NET Core application. The update addresses the vulnerability by correcting how the ASP.NET Core web application handles web requests. NVD description · AI analysis pending | 7.5 | 5% |
| — |
Full article1,375 words · extracted from securityaffairs.com · click to collapse
Microsoft issued May 2020 Patch Tuesday security updates that addressed 111 vulnerabilities impacting 12 products, including Microsoft Windows, Microsoft Edge, ChakraCore, Internet Explorer, Microsoft Office, and Microsoft Office Services and Web Apps, Visual Studio, Microsoft Dynamics, .NET Framework, .NET Core, and Power BI.
16 of 111vulnerabilities are rated as Critical severity, and 95 are rated as Important in severity.
“Eleven of these CVEs were reported through the ZDI program. None of the bugs being patched are listed as being publicly known or under active attack at the time of release.” reported ZDI. “That makes three months in a row that Microsoft has released patches for more than 110 CVEs.”
None of the flaws addressed by Microsoft are being exploited in attacks in the wild.
Below a list of the most severe issues fixed by Microsoft with May 2020 Patch Tuesday security updates:
– CVE-2020-1071 – Windows Remote Access Common Dialog Elevation of Privilege Vulnerability – An attacker could exploit the bug in the Remote Access Common Dialog to run arbitrary code with elevated privileges.
– CVE-2020-1135 – Windows Graphics Component Elevation of Privilege Vulnerability – This issue was demonstrated at the Pwn2Own by white-hat hackers from the Fluoroacetate team. The flaw could allow a logged-on user to take over a system by running a specially crafted program.
– CVE-2020-1067 – Windows Remote Code Execution Vulnerability – The RCE issue impact Windows OS and could be exploited by an attacker to execute arbitrary code with elevated permissions on affected systems. The issue could be exploited only by attacker with a domain user account, the issue could be used for lateral movements once inside a target network.
| Tag | CVE ID | CVE Title |
|---|---|---|
| .NET Core | CVE-2020-1161 | ASP.NET Core Denial of Service Vulnerability |
| .NET Core | CVE-2020-1108 | .NET Core & .NET Framework Denial of Service Vulnerability |
| .NET Framework | CVE-2020-1066 | .NET Framework Elevation of Privilege Vulnerability |
| Active Directory | CVE-2020-1055 | Microsoft Active Directory Federation Services Cross-Site Scripting Vulnerability |
| Common Log File System Driver | CVE-2020-1154 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| Internet Explorer | CVE-2020-1092 | Internet Explorer Memory Corruption Vulnerability |
| Internet Explorer | CVE-2020-1064 | MSHTML Engine Remote Code Execution Vulnerability |
| Internet Explorer | CVE-2020-1062 | Internet Explorer Memory Corruption Vulnerability |
| Internet Explorer | CVE-2020-1093 | VBScript Remote Code Execution Vulnerability |
| Microsoft Dynamics | CVE-2020-1063 | Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability |
| Microsoft Edge | CVE-2020-1059 | Microsoft Edge Spoofing Vulnerability |
| Microsoft Edge | CVE-2020-1056 | Microsoft Edge Elevation of Privilege Vulnerability |
| Microsoft Edge | CVE-2020-1096 | Microsoft Edge PDF Remote Code Execution Vulnerability |
| Microsoft Graphics Component | CVE-2020-1145 | Windows GDI Information Disclosure Vulnerability |
| Microsoft Graphics Component | CVE-2020-1135 | Windows Graphics Component Elevation of Privilege Vulnerability |
| Microsoft Graphics Component | CVE-2020-1179 | Windows GDI Information Disclosure Vulnerability |
| Microsoft Graphics Component | CVE-2020-1153 | Microsoft Graphics Components Remote Code Execution Vulnerability |
| Microsoft Graphics Component | CVE-2020-1140 | DirectX Elevation of Privilege Vulnerability |
| Microsoft Graphics Component | CVE-2020-0963 | Windows GDI Information Disclosure Vulnerability |
| Microsoft Graphics Component | CVE-2020-1054 | Win32k Elevation of Privilege Vulnerability |
| Microsoft Graphics Component | CVE-2020-1142 | Windows GDI Elevation of Privilege Vulnerability |
| Microsoft Graphics Component | CVE-2020-1117 | Microsoft Color Management Remote Code Execution Vulnerability |
| Microsoft Graphics Component | CVE-2020-1141 | Windows GDI Information Disclosure Vulnerability |
| Microsoft JET Database Engine | CVE-2020-1176 | Jet Database Engine Remote Code Execution Vulnerability |
| Microsoft JET Database Engine | CVE-2020-1051 | Jet Database Engine Remote Code Execution Vulnerability |
| Microsoft JET Database Engine | CVE-2020-1175 | Jet Database Engine Remote Code Execution Vulnerability |
| Microsoft JET Database Engine | CVE-2020-1174 | Jet Database Engine Remote Code Execution Vulnerability |
| Microsoft Office | CVE-2020-0901 | Microsoft Excel Remote Code Execution Vulnerability |
| Microsoft Office SharePoint | CVE-2020-1069 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| Microsoft Office SharePoint | CVE-2020-1100 | Microsoft Office SharePoint XSS Vulnerability |
| Microsoft Office SharePoint | CVE-2020-1105 | Microsoft SharePoint Spoofing Vulnerability |
| Microsoft Office SharePoint | CVE-2020-1102 | Microsoft SharePoint Remote Code Execution Vulnerability |
| Microsoft Office SharePoint | CVE-2020-1024 | Microsoft SharePoint Remote Code Execution Vulnerability |
| Microsoft Office SharePoint | CVE-2020-1023 | Microsoft SharePoint Remote Code Execution Vulnerability |
| Microsoft Office SharePoint | CVE-2020-1104 | Microsoft SharePoint Spoofing Vulnerability |
| Microsoft Office SharePoint | CVE-2020-1101 | Microsoft Office SharePoint XSS Vulnerability |
| Microsoft Office SharePoint | CVE-2020-1099 | Microsoft Office SharePoint XSS Vulnerability |
| Microsoft Office SharePoint | CVE-2020-1103 | Microsoft SharePoint Information Disclosure Vulnerability |
| Microsoft Office SharePoint | CVE-2020-1107 | Microsoft SharePoint Spoofing Vulnerability |
| Microsoft Office SharePoint | CVE-2020-1106 | Microsoft Office SharePoint XSS Vulnerability |
| Microsoft Scripting Engine | CVE-2020-1060 | VBScript Remote Code Execution Vulnerability |
| Microsoft Scripting Engine | CVE-2020-1065 | Scripting Engine Memory Corruption Vulnerability |
| Microsoft Scripting Engine | CVE-2020-1037 | Chakra Scripting Engine Memory Corruption Vulnerability |
| Microsoft Scripting Engine | CVE-2020-1035 | VBScript Remote Code Execution Vulnerability |
| Microsoft Scripting Engine | CVE-2020-1058 | VBScript Remote Code Execution Vulnerability |
| Microsoft Windows | CVE-2020-1111 | Windows Clipboard Service Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1112 | Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1082 | Windows Error Reporting Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1086 | Windows Runtime Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1048 | Windows Print Spooler Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1090 | Windows Runtime Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1088 | Windows Error Reporting Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1166 | Windows Clipboard Service Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1021 | Windows Error Reporting Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1164 | Windows Runtime Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1165 | Windows Clipboard Service Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1184 | Windows State Repository Service Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1188 | Windows State Repository Service Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1191 | Windows State Repository Service Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1185 | Windows State Repository Service Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1187 | Windows State Repository Service Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1125 | Windows Runtime Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1131 | Windows State Repository Service Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1121 | Windows Clipboard Service Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1123 | Connected User Experiences and Telemetry Service Denial of Service Vulnerability |
| Microsoft Windows | CVE-2020-1132 | Windows Error Reporting Manager Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1010 | Microsoft Windows Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1028 | Media Foundation Memory Corruption Vulnerability |
| Microsoft Windows | CVE-2020-1136 | Media Foundation Memory Corruption Vulnerability |
| Microsoft Windows | CVE-2020-1139 | Windows Runtime Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1144 | Windows State Repository Service Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1149 | Windows Runtime Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1076 | Windows Denial of Service Vulnerability |
| Microsoft Windows | CVE-2020-1143 | Win32k Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1071 | Windows Remote Access Common Dialog Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1155 | Windows Runtime Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1150 | Media Foundation Memory Corruption Vulnerability |
| Microsoft Windows | CVE-2020-1151 | Windows Runtime Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1138 | Windows Storage Service Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1118 | Microsoft Windows Transport Layer Security Denial of Service Vulnerability |
| Microsoft Windows | CVE-2020-1124 | Windows State Repository Service Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1084 | Connected User Experiences and Telemetry Service Denial of Service Vulnerability |
| Microsoft Windows | CVE-2020-1116 | Windows CSRSS Information Disclosure Vulnerability |
| Microsoft Windows | CVE-2020-1078 | Windows Installer Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1137 | Windows Push Notification Service Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1126 | Media Foundation Memory Corruption Vulnerability |
| Microsoft Windows | CVE-2020-1134 | Windows State Repository Service Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1070 | Windows Print Spooler Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1068 | Microsoft Windows Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1067 | Windows Remote Code Execution Vulnerability |
| Microsoft Windows | CVE-2020-1072 | Windows Kernel Information Disclosure Vulnerability |
| Microsoft Windows | CVE-2020-1081 | Windows Printer Service Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1079 | Microsoft Windows Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1077 | Windows Runtime Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1190 | Windows State Repository Service Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1158 | Windows Runtime Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1157 | Windows Runtime Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1186 | Windows State Repository Service Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1156 | Windows Runtime Elevation of Privilege Vulnerability |
| Microsoft Windows | CVE-2020-1189 | Windows State Repository Service Elevation of Privilege Vulnerability |
| Power BI | CVE-2020-1173 | Microsoft Power BI Report Server Spoofing Vulnerability |
| Visual Studio | CVE-2020-1192 | Visual Studio Code Python Extension Remote Code Execution Vulnerability |
| Visual Studio | CVE-2020-1171 | Visual Studio Code Python Extension Remote Code Execution Vulnerability |
| Windows Hyper-V | CVE-2020-0909 | Windows Hyper-V Denial of Service Vulnerability |
| Windows Kernel | CVE-2020-1114 | Windows Kernel Elevation of Privilege Vulnerability |
| Windows Kernel | CVE-2020-1087 | Windows Kernel Elevation of Privilege Vulnerability |
| Windows Scripting | CVE-2020-1061 | Microsoft Script Runtime Remote Code Execution Vulnerability |
| Windows Subsystem for Linux | CVE-2020-1075 | Windows Subsystem for Linux Information Disclosure Vulnerability |
| Windows Task Scheduler | CVE-2020-1113 | Windows Task Scheduler Security Feature Bypass Vulnerability |
| Windows Update Stack | CVE-2020-1109 | Windows Update Stack Elevation of Privilege Vulnerability |
| Windows Update Stack | CVE-2020-1110 | Windows Update Stack Elevation of Privilege Vulnerability |
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/103158/security/microsoft-may-2020-patch-tuesday.html