Sadly, 111 in this story isn't binary. It's decimal. It's the number of security fixes emitted by Microsoft this week
(2020/05/13)
- Reference: 1589347866
- News link: https://www.theregister.co.uk/2020/05/13/patch_tuesday_may/
- Source link:
The May edition of Patch Tuesday landed this week. And there are scores of security fixes to install.
A total of [1]111 fixes were released by Microsoft, though on the bright side none are being actively exploited, as far as we know. Sixteen earned Microsoft's top rating of critical, and range from remote code execution to elevation of privilege.
One standout programming blunder was [2]CVE-2020-1067 , a remote-code execution (RCE) vulnerability in all supported versions of Windows. Anyone with a domain user account can exploit it for elevated access on the targeted system. It's rated important though that kinda masks the threat.
"This patch corrects an RCE bug in the Windows OS that could allow an attacker to execute arbitrary code with elevated permissions on affected systems," said Dustin Childs of the Trend Micro's ZDI. "The only thing keeping this from being critical is the fact that the attacker needs a domain user account for their specially crafted request to succeed. This makes the bug a prime target for insider threats, as well as penetration testers looking to expand their foothold in a target enterprise."
One malicious MMS is all it takes to pwn a Samsung smartphone: Bug squashed amid Android patch batch [3]READ MORE
There is a laundry list of vulnerabilities in Microsoft's web browser engines, Sharepoint, scripting engines, and Visual Studio that ZDI has [4]summarized here along with the less-important ones, such as elevation-of-privilege blunders in the Windows kernel. They basically boil down to holes that can be exploited by opening maliciously crafted files, or by malware already running on a PC.
"Most are related to web browsers or some form of browse-and-own scenario," noted Childs. "Chakra Core, IE, and EdgeHTML all receive critical-rated updates.
"None of the bugs being patched are listed as being publicly known or under active attack at the time of release. That makes three months in a row that Microsoft has released patches for more than 110 CVEs. We’ll see if they maintain that pace throughout the year."
If you want to drill down into some of the more interesting ones, there's [5]CVE-2020-1192 in the Visual Studio Code Python Extension; [6]CVE-2020-1023 , [7]CVE-2020-1024 , [8]CVE-2020-1102 , and [9]CVE-2020-1069 in Sharepoint; [10]CVE-2020-1093 in VBScript; and [11]CVE-2020-1153 in the Microsoft Graphics Components.
Make sure you download, test, and deploy the fixes as necessary.
Windows 7 problems
Those still running Windows 7, and even those paying Microsoft top dollar for support to do so, should be aware of [12]an issue with KB4556399, a .NET security and quality update. Depending on your configuration, it may fail to install.
On to Adobe: Two critical fixes for a number of CVEs
It were 36 bugs [13]patched by Adobe this month in Acrobat and Reader, and the usual assortment of code execution and denial of service flaws that require opening a document to exploit. Linux fans are spared this time around, as the patches are only for macOS and Windows boxes.
SAP, VMware critical flaws
Meanwhile, SAP admins will want to address a [14]number of bugs , including CVE-2020-6282 (code injection), note 2622660 (Chromium updates), CVE-2020-6242 (code injection), and CVE-2020-6219 (deserialization of untrusted data).
VMware also [15]emitted fixes for CVE-2020-11651 and CVE-2020-11652, which are authentication bypass and directory traversal vulnerabilities. ®
Sponsored: [16]How to Build Your Digital Experience Portfolio
[1] https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/2020-May
[2] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1067
[3] https://www.theregister.co.uk/2020/05/08/samsung_android_patches/
[4] https://www.zerodayinitiative.com/blog/2020/5/12/the-may-2020-security-update-review
[5] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1192
[6] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1023
[7] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1024
[8] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1102
[9] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1069
[10] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1093
[11] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1153
[12] https://www.askwoody.com/2020/many-reports-of-errors-when-trying-to-install-the-latest-net-patch-on-win7-systems-with-extended-security-updates-enabled/
[13] https://helpx.adobe.com/security/products/acrobat/apsb20-24.html
[14] https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222
[15] https://www.vmware.com/security/advisories/VMSA-2020-0009.html
[16] https://go.theregister.co.uk/tl/1936/-8578/how-to-build-your-digital-experience-portfolio?td=wptl1936
A total of [1]111 fixes were released by Microsoft, though on the bright side none are being actively exploited, as far as we know. Sixteen earned Microsoft's top rating of critical, and range from remote code execution to elevation of privilege.
One standout programming blunder was [2]CVE-2020-1067 , a remote-code execution (RCE) vulnerability in all supported versions of Windows. Anyone with a domain user account can exploit it for elevated access on the targeted system. It's rated important though that kinda masks the threat.
"This patch corrects an RCE bug in the Windows OS that could allow an attacker to execute arbitrary code with elevated permissions on affected systems," said Dustin Childs of the Trend Micro's ZDI. "The only thing keeping this from being critical is the fact that the attacker needs a domain user account for their specially crafted request to succeed. This makes the bug a prime target for insider threats, as well as penetration testers looking to expand their foothold in a target enterprise."
One malicious MMS is all it takes to pwn a Samsung smartphone: Bug squashed amid Android patch batch [3]READ MORE
There is a laundry list of vulnerabilities in Microsoft's web browser engines, Sharepoint, scripting engines, and Visual Studio that ZDI has [4]summarized here along with the less-important ones, such as elevation-of-privilege blunders in the Windows kernel. They basically boil down to holes that can be exploited by opening maliciously crafted files, or by malware already running on a PC.
"Most are related to web browsers or some form of browse-and-own scenario," noted Childs. "Chakra Core, IE, and EdgeHTML all receive critical-rated updates.
"None of the bugs being patched are listed as being publicly known or under active attack at the time of release. That makes three months in a row that Microsoft has released patches for more than 110 CVEs. We’ll see if they maintain that pace throughout the year."
If you want to drill down into some of the more interesting ones, there's [5]CVE-2020-1192 in the Visual Studio Code Python Extension; [6]CVE-2020-1023 , [7]CVE-2020-1024 , [8]CVE-2020-1102 , and [9]CVE-2020-1069 in Sharepoint; [10]CVE-2020-1093 in VBScript; and [11]CVE-2020-1153 in the Microsoft Graphics Components.
Make sure you download, test, and deploy the fixes as necessary.
Windows 7 problems
Those still running Windows 7, and even those paying Microsoft top dollar for support to do so, should be aware of [12]an issue with KB4556399, a .NET security and quality update. Depending on your configuration, it may fail to install.
On to Adobe: Two critical fixes for a number of CVEs
It were 36 bugs [13]patched by Adobe this month in Acrobat and Reader, and the usual assortment of code execution and denial of service flaws that require opening a document to exploit. Linux fans are spared this time around, as the patches are only for macOS and Windows boxes.
SAP, VMware critical flaws
Meanwhile, SAP admins will want to address a [14]number of bugs , including CVE-2020-6282 (code injection), note 2622660 (Chromium updates), CVE-2020-6242 (code injection), and CVE-2020-6219 (deserialization of untrusted data).
VMware also [15]emitted fixes for CVE-2020-11651 and CVE-2020-11652, which are authentication bypass and directory traversal vulnerabilities. ®
Sponsored: [16]How to Build Your Digital Experience Portfolio
[1] https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/2020-May
[2] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1067
[3] https://www.theregister.co.uk/2020/05/08/samsung_android_patches/
[4] https://www.zerodayinitiative.com/blog/2020/5/12/the-may-2020-security-update-review
[5] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1192
[6] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1023
[7] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1024
[8] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1102
[9] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1069
[10] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1093
[11] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1153
[12] https://www.askwoody.com/2020/many-reports-of-errors-when-trying-to-install-the-latest-net-patch-on-win7-systems-with-extended-security-updates-enabled/
[13] https://helpx.adobe.com/security/products/acrobat/apsb20-24.html
[14] https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222
[15] https://www.vmware.com/security/advisories/VMSA-2020-0009.html
[16] https://go.theregister.co.uk/tl/1936/-8578/how-to-build-your-digital-experience-portfolio?td=wptl1936