Microsoft Patch Tuesday, May 2020 Edition
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-1054 | Privilege Escalation in Microsoft Windows Win32k Kernel Driver (CVE-2020-1054) CVE-2020-1054 is an elevation-of-privilege flaw (CWE-787, an out-of-bounds memory access) in the Windows kernel-mode driver (win32k), which fails to properly handle objects in memory. To exploit it, an attacker who can already log on to an affected Windows machine must run a specially crafted application, which triggers the memory-handling error and allows arbitrary code execution in kernel mode. Successful exploitation effectively yields full SYSTEM-level control of the host: the attacker can install programs, view, change or delete any data, and create new accounts with full user rights. Affected products per the CPE data are Windows 7, 8.1, RT 8.1, Windows 10 versions 1507 through 1909, and Windows Server 1803 and 1903. The flaw was fixed in Microsoft's May 2020 Patch Tuesday, a public DrawIconEx-based local privilege escalation PoC exists, EPSS is 54.2% (99th percentile), and CISA added it to the KEV catalog on 2021-11-03, confirming exploitation in the wild; related threat reporting around this CVE ties it to malware campaigns such as PurpleFox and Raspberry Robin, while ransomware use is listed as unknown. Do: Apply Microsoft's May 2020 security updates (or any later cumulative update) to Windows 7, 8.1, RT 8.1, Windows 10 1507–1909, and Windows Server 1803/1903, per the CISA KEV required action; prioritize multi-user hosts such as RDS servers where low-privileged users can run code. For legacy systems that no longer receive updates (e.g., Windows 7/8.1 post-EOL), limit local logon and software-execution rights for untrusted users and monitor for local privilege escalation activity. | 7.0 | 54% | KEV PoC |
| mass≈1 billion Windows devices (global Windows 10 install base plus the legacy Windows 7/8.1 estate) | |
| CVE-2020-1126 | A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Foundation handles objects in memory. NVD description · AI analysis pending | 8.8 group max | 4% |
| — |
Full article903 words · extracted from krebsonsecurity.com · click to collapse
Microsoft today issued software updates to plug at least 111 security holes in Windows and Windows-based programs. None of the vulnerabilities were labeled as being publicly exploited or detailed prior to today, but as always if you’re running Windows on any of your machines it’s time once again to prepare to get your patches on.
May marks the third month in a row that Microsoft has pushed out fixes for more than 110 security flaws in its operating system and related software. At least 16 of the bugs are labeled “Critical,” meaning ne’er-do-wells can exploit them to install malware or seize remote control over vulnerable systems with little or no help from users.
But focusing solely on Microsoft’s severity ratings may obscure the seriousness of the flaws being addressed this month. Todd Schell, senior product manager at security vendor Ivanti, notes that if one looks at the “exploitability assessment” tied to each patch — i.e., how likely Microsoft considers each can and will be exploited for nefarious purposes — it makes sense to pay just as much attention to the vulnerabilities Microsoft has labeled with the lesser severity rating of “Important.”
Virtually all of the non-critical flaws in this month’s batch earned Microsoft’s “Important” rating.
“What is interesting and often overlooked is seven of the ten [fixes] at higher risk of exploit are only rated as Important,” Schell said. “It is not uncommon to look to the critical vulnerabilities as the most concerning, but many of the vulnerabilities that end up being exploited are rated as Important vs Critical.”
For example, Satnam Narang from Tenable notes that two remote code execution flaws in Microsoft Color Management (CVE-2020-1117) and Windows Media Foundation (CVE-2020-1126) could be exploited by tricking a user into opening a malicious email attachment or visiting a website that contains code designed to exploit the vulnerabilities. However, Microsoft rates these vulnerabilities as “Exploitation Less Likely,” according to their Exploitability Index.
In contrast, three elevation of privilege vulnerabilities that received a rating of “Exploitation More Likely” were also patched, Narang notes. These include a pair of “Important” flaws in Win32k (CVE-2020-1054, CVE-2020-1143) and one in the Windows Graphics Component (CVE-2020-1135). Elevation of Privilege vulnerabilities are used by attackers once they’ve managed to gain access to a system in order to execute code on their target systems with elevated privileges. There are at least 56 of these types of fixes in the May release.
Schell says if your organization’s plan for prioritizing the deployment of this month’s patches stops at vendor severity or even CVSS scores above a certain level you may want to reassess your metrics.
“Look to other risk metrics like Publicly Disclosed, Exploited (obviously), and Exploitability Assessment (Microsoft specific) to expand your prioritization process,” he advised.
As it usually does each month on Patch Tuesday, Adobe also has issued updates for some of its products. An update for Adobe Acrobat and Reader covers two dozen critical and important vulnerabilities. There are no security fixes for Adobe’s Flash Player in this month’s release.
Just a friendly reminder that while many of the vulnerabilities fixed in today’s Microsoft patch batch affect Windows 7 operating systems — including all three of the zero-day flaws — this OS is no longer being supported with security updates (unless you’re an enterprise taking advantage of Microsoft’s paid extended security updates program, which is available to Windows 7 Professional and Windows 7 enterprise users).
If you rely on Windows 7 for day-to-day use, it’s time to think about upgrading to something newer. That something might be a PC with Windows 10. Or maybe you have always wanted that shiny MacOS computer.
If cost is a primary motivator and the user you have in mind doesn’t do much with the system other than browsing the Web, perhaps a Chromebook or an older machine with a recent version of Linux is the answer (Ubuntu may be easiest for non-Linux natives). Whichever system you choose, it’s important to pick one that fits the owner’s needs and provides security updates on an ongoing basis.
Keep in mind that while staying up-to-date on Windows patches is a must, it’s important to make sure you’re updating only after you’ve backed up your important data and files. A reliable backup means you’re not losing your mind when the odd buggy patch causes problems booting the system.
So backup your files before installing any patches. Windows 10 even has some built-in tools to help you do that, either on a per-file/folder basis or by making a complete and bootable copy of your hard drive all at once.
And if you wish to ensure Windows has been set to pause updating so you can back up your files and/or system before the operating system decides to reboot and install patches on its own schedule, see this guide.
As always, if you experience glitches or problems installing any of these patches this month, please consider leaving a comment about it below; there’s a better-than-even chance other readers have experienced the same and may chime in here with some helpful tips. Also, keep an eye on the AskWoody blog from Woody Leonhard, who keeps a reliable lookout for buggy Microsoft updates each month.
Further reading:
SANS Internet Storm Center breakdown by vulnerability and severity
Text extracted automatically; images, tables and formatting may be missing. Original: https://krebsonsecurity.com/2020/05/microsoft-patch-tuesday-may-2020-edition/