News: 1586901763

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

April 2020 and - rest assured - your Windows PC can still be pwned by something so innocuous as an unruly font

(2020/04/14)


Microsoft has delivered another epic Patch Tuesday, dropping fixes for more than 100 security bugs, and Adobe and Intel have added their dose of misery and security too.

April showers from Redmond

The April edition of Patch Tuesday sees the release of fixes for 113 CVE-listed bugs. Four really important ones are already being exploited in the wild. Of those, two target [1]font code ,another goes for an old VBScript [2]error and the last one [3]requires local access.

"In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability through Internet Explorer and then convince a user to view the website," Microsoft warns.

"An attacker could also embed an ActiveX control marked 'safe for initialization' in an application or Microsoft Office document that hosts the IE rendering engine."

A fifth flaw, ( [4]CVE-2020-0935 ) was publicly disclosed but not exploited in the wild. That flaw was an elevation of privilege bug in OneDrive.

The massive patch load is no accident, say experts.

"If you feel like there have been a lot of patches this year, you’re not wrong," [5]notes Dustin Childs of the Trend Micro Zero Day Initiative. "Microsoft has seen a 44 per cent increase in the number of CVEs patched between January to April of 2020 compared to the same time period in 2019."

As per usual, browser bugs make up most of this month's critical updates. Flaws in Redmond's Media Foundation, Chakra Scripting Engine, and SharePoint account for the lion's share of the critical-rated issues this month.

Of more interest are the critical flaws in Hyper-V ( [6]CVE-2020-0910 ) and VBScript ( [7]CVE-2020-0967 ) that allow remote code execution via a guest account or a VBScript engine code break.

Meanwhile, Adobe skipped updates for Flash this month, opting instead to put out fixes for a local [8]privilege escalation flaw in ColdFusion, an [9]information disclosure hole in After Effects, and an [10]information disclosure flaw in Digital Editions.

Six Intel updates

Over in the realm of Chipzilla, we have six patches for various firmware flaws.

They include escalation of privilege flaws [11]in the NUC firmware , escalation of privilege bugs in the [12]Intel Binary Configuration Tool, escalation of privilege errors in the [13]Modular Server Compute Module , Denial of Service bugs in the [14]Driver and Support Assistant , and elevation of privilege flaw in [15]ProSet/Wireless Wifi , and an escalation of privilege error in the [16]Intel Data Migration Software. ®

Sponsored: [17]Legacy Modernization: Finding Your Way With Low-Code



[1] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1020

[2] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0967

[3] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1027

[4] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0935

[5] https://www.zerodayinitiative.com/blog/2020/4/14/the-april-2020-security-update-review

[6] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0910

[7] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0967

[8] https://helpx.adobe.com/security/products/coldfusion/apsb20-18.html

[9] https://helpx.adobe.com/security/products/after_effects/apsb20-21.html

[10] https://helpx.adobe.com/security/products/Digital-Editions/apsb20-23.html

[11] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00363.html

[12] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00359.html

[13] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00351.html

[14] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00344.html

[15] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00338.html

[16] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00327.html

[17] https://go.theregister.co.uk/tl/1936/-8553/legacy-modernization-finding-your-way-with-low-code?td=wptl1936

a broken Chakra Scripting Engine?

Shadow Systems

That's not very Zen of them now is it? =-)p

*Runs away before someone uses their Karma to run over my Dogma*

Re: a broken Chakra Scripting Engine?

robidy

Mmmmm two 0 days targeting Windows 7 not patched...how many companies have had to delay retiring the last of them...plus the odd 2008 or 2008 R2 Server.

Let me guess Microsoft's ESU services (very expensive licence to get updates for EoL products) is about to get a bumper boost of Sales :)

MatthewSt

"The massive patch load is no accident, say experts" - I'm no writer, but this sentence doesn't seem to fit with anything around it. Have they been saving the patches up? Are a large quantity of patches usually accidents? Granted the bugs are (in theory) accidents, but it sounds like this is only half of what the "experts" said.

J. Cook

No, it means that people are devoting more effort to finding and exploiting bugs.

An attacker could also embed an ActiveX control marked 'safe for initialization'

bombastic bob

ActiveX "security" markings were ALWAYS IDIOTICALLY INSECURE, but I have to ask WHY this is STILL being ALLOWED to EXIST???

icon, because, facepalm

Re: An attacker could also embed an ActiveX control marked 'safe for initialization'

Anonymous Coward

ActiveX will be probably be painfully around as long as you, BB, but once was useful, and patches can be attempted for it.

Much love

Ten years of rejection slips is nature's way of telling you to stop writing.
-- R. Geis