Microsoft's May 'Patch Tuesday' remedies 111 vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-1062 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, the attacker could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker could host a specially crafted website designed to exploit the vulnerability through Internet Explorer and then convince a user to view the website. The attacker could also take advantage of compromised websites, or websites that accept or host user-provided content or advertisements, by adding specially crafted content that could exploit the vulnerability. However, in all cases an attacker would have no way to force a user to view the attacker-controlled content. Instead, an attacker would have to convince a user to take action, typically by an enticement in an email or instant message, or by getting the user to open an attachment sent through email. The security update addresses the vulnerability by modifying how Internet Explorer handles objects in memory. NVD description · AI analysis pending | 7.5 | 6% |
| — | ||
| CVE-2020-1069 | A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls. A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls. An authenticated attacker who successfully exploited the vulnerability could use a specially crafted page to perform actions in the security context of the SharePoint application pool process. To exploit the vulnerability, an authenticated user must create and invoke a specially crafted page on an affected version of Microsoft SharePoint Server. The security update addresses the vulnerability by correcting how Microsoft SharePoint Server handles processing of created content. NVD description · AI analysis pending | 8.8 | 4% |
| — |
Full article699 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The biggest fix is for a critical issue in Microsoft SharePoint.
Microsoft has released a set of software upgrades meant to address more than 100 vulnerabilities in the company’s products, the latest in a series of scheduled updates that comes as many corporate security executives are working remotely.
The announcement comes as part of Microsoft’s “Patch Tuesday” release, the batch of security updates that the company publishes each month to mitigate known vulnerabilities. The May 2020 list includes 111 vulnerabilities, including 13 “critical” issues, 91 classified as “important,” three “moderate” bugs and four “low” priority. Hackers don’t appear to be exploiting any of the vulnerabilities, according to the advisory.
The updates pertain to vulnerabilities in Microsoft Edge, the Windows Defender security software, Microsoft Office, Internet Explorer, and a number of other products.
Among the most urgent patches are meant to repair flaws in Microsoft SharePoint that could enable hackers to executive arbitrary code on a victim’s machine. One of the SharePoint vulnerabilities (CVE-2020-1069) requires attackers to upload a specially crafted pack to a SharePoint server in order to exploit the bug, according to researchers from Cisco’s Talos threat intelligence team. Other issues require users to open specific SharePoint files designed to infect them.
Another bug (CVE-2020-1062) is a memory corruption flaw. Hackers could use that issue if an Internet Explorer user visits a specific web page controlled by the attackers, then infiltrate a victim’s machine.
Microsoft previously patched 113 vulnerabilities in its April Patch Tuesday update, and 115 issues in March. The latest release also includes no zero-day vulnerabilities, unlike prior examples.
This release coincides with another security update for Adobe products, including patches for 24 vulnerabilities in the Acrobat and Acrobat reader software. While Adobe says hackers haven’t seized on any of those bugs, 12 of the 24 issues are described as “critical.”
More Scoops
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
While the vendor hit another monthly record, it hasn’t resulted in a flood of active exploits. Researchers encourage customers to focus on their specific areas of risk…
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-patch-tuesday-may-2020/