April 2020 and - rest assured - your Windows PC can still be pwned by something so innocuous as an unruly font
- Reference: 1586901763
- News link: https://www.theregister.co.uk/2020/04/14/april_patch_tuesday/
- Source link:
April showers from Redmond
The April edition of Patch Tuesday sees the release of fixes for 113 CVE-listed bugs. Four really important ones are already being exploited in the wild. Of those, two target [1]font code ,another goes for an old VBScript [2]error and the last one [3]requires local access.
"In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability through Internet Explorer and then convince a user to view the website," Microsoft warns.
"An attacker could also embed an ActiveX control marked 'safe for initialization' in an application or Microsoft Office document that hosts the IE rendering engine."
A fifth flaw, ( [4]CVE-2020-0935 ) was publicly disclosed but not exploited in the wild. That flaw was an elevation of privilege bug in OneDrive.
The massive patch load is no accident, say experts.
"If you feel like there have been a lot of patches this year, you’re not wrong," [5]notes Dustin Childs of the Trend Micro Zero Day Initiative. "Microsoft has seen a 44 per cent increase in the number of CVEs patched between January to April of 2020 compared to the same time period in 2019."
As per usual, browser bugs make up most of this month's critical updates. Flaws in Redmond's Media Foundation, Chakra Scripting Engine, and SharePoint account for the lion's share of the critical-rated issues this month.
Of more interest are the critical flaws in Hyper-V ( [6]CVE-2020-0910 ) and VBScript ( [7]CVE-2020-0967 ) that allow remote code execution via a guest account or a VBScript engine code break.
Meanwhile, Adobe skipped updates for Flash this month, opting instead to put out fixes for a local [8]privilege escalation flaw in ColdFusion, an [9]information disclosure hole in After Effects, and an [10]information disclosure flaw in Digital Editions.
Six Intel updates
Over in the realm of Chipzilla, we have six patches for various firmware flaws.
They include escalation of privilege flaws [11]in the NUC firmware , escalation of privilege bugs in the [12]Intel Binary Configuration Tool, escalation of privilege errors in the [13]Modular Server Compute Module , Denial of Service bugs in the [14]Driver and Support Assistant , and elevation of privilege flaw in [15]ProSet/Wireless Wifi , and an escalation of privilege error in the [16]Intel Data Migration Software. ®
Sponsored: [17]Legacy Modernization: Finding Your Way With Low-Code
[1] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1020
[2] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0967
[3] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1027
[4] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0935
[5] https://www.zerodayinitiative.com/blog/2020/4/14/the-april-2020-security-update-review
[6] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0910
[7] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0967
[8] https://helpx.adobe.com/security/products/coldfusion/apsb20-18.html
[9] https://helpx.adobe.com/security/products/after_effects/apsb20-21.html
[10] https://helpx.adobe.com/security/products/Digital-Editions/apsb20-23.html
[11] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00363.html
[12] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00359.html
[13] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00351.html
[14] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00344.html
[15] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00338.html
[16] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00327.html
[17] https://go.theregister.co.uk/tl/1936/-8553/legacy-modernization-finding-your-way-with-low-code?td=wptl1936
Re: a broken Chakra Scripting Engine?
Mmmmm two 0 days targeting Windows 7 not patched...how many companies have had to delay retiring the last of them...plus the odd 2008 or 2008 R2 Server.
Let me guess Microsoft's ESU services (very expensive licence to get updates for EoL products) is about to get a bumper boost of Sales :)
"The massive patch load is no accident, say experts" - I'm no writer, but this sentence doesn't seem to fit with anything around it. Have they been saving the patches up? Are a large quantity of patches usually accidents? Granted the bugs are (in theory) accidents, but it sounds like this is only half of what the "experts" said.
No, it means that people are devoting more effort to finding and exploiting bugs.
An attacker could also embed an ActiveX control marked 'safe for initialization'
ActiveX "security" markings were ALWAYS IDIOTICALLY INSECURE, but I have to ask WHY this is STILL being ALLOWED to EXIST???
icon, because, facepalm
Re: An attacker could also embed an ActiveX control marked 'safe for initialization'
ActiveX will be probably be painfully around as long as you, BB, but once was useful, and patches can be attempted for it.
Much love
a broken Chakra Scripting Engine?
That's not very Zen of them now is it? =-)p
*Runs away before someone uses their Karma to run over my Dogma*