News: 1589347866

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Sadly, 111 in this story isn't binary. It's decimal. It's the number of security fixes emitted by Microsoft this week

(2020/05/13)


The May edition of Patch Tuesday landed this week. And there are scores of security fixes to install.

A total of [1]111 fixes were released by Microsoft, though on the bright side none are being actively exploited, as far as we know. Sixteen earned Microsoft's top rating of critical, and range from remote code execution to elevation of privilege.

One standout programming blunder was [2]CVE-2020-1067 , a remote-code execution (RCE) vulnerability in all supported versions of Windows. Anyone with a domain user account can exploit it for elevated access on the targeted system. It's rated important though that kinda masks the threat.

"This patch corrects an RCE bug in the Windows OS that could allow an attacker to execute arbitrary code with elevated permissions on affected systems," said Dustin Childs of the Trend Micro's ZDI. "The only thing keeping this from being critical is the fact that the attacker needs a domain user account for their specially crafted request to succeed. This makes the bug a prime target for insider threats, as well as penetration testers looking to expand their foothold in a target enterprise."

One malicious MMS is all it takes to pwn a Samsung smartphone: Bug squashed amid Android patch batch [3]READ MORE

There is a laundry list of vulnerabilities in Microsoft's web browser engines, Sharepoint, scripting engines, and Visual Studio that ZDI has [4]summarized here along with the less-important ones, such as elevation-of-privilege blunders in the Windows kernel. They basically boil down to holes that can be exploited by opening maliciously crafted files, or by malware already running on a PC.

"Most are related to web browsers or some form of browse-and-own scenario," noted Childs. "Chakra Core, IE, and EdgeHTML all receive critical-rated updates.

"None of the bugs being patched are listed as being publicly known or under active attack at the time of release. That makes three months in a row that Microsoft has released patches for more than 110 CVEs. We’ll see if they maintain that pace throughout the year."

If you want to drill down into some of the more interesting ones, there's [5]CVE-2020-1192 in the Visual Studio Code Python Extension; [6]CVE-2020-1023 , [7]CVE-2020-1024 , [8]CVE-2020-1102 , and [9]CVE-2020-1069 in Sharepoint; [10]CVE-2020-1093 in VBScript; and [11]CVE-2020-1153 in the Microsoft Graphics Components.

Make sure you download, test, and deploy the fixes as necessary.

Windows 7 problems

Those still running Windows 7, and even those paying Microsoft top dollar for support to do so, should be aware of [12]an issue with KB4556399, a .NET security and quality update. Depending on your configuration, it may fail to install.

On to Adobe: Two critical fixes for a number of CVEs

It were 36 bugs [13]patched by Adobe this month in Acrobat and Reader, and the usual assortment of code execution and denial of service flaws that require opening a document to exploit. Linux fans are spared this time around, as the patches are only for macOS and Windows boxes.

SAP, VMware critical flaws

Meanwhile, SAP admins will want to address a [14]number of bugs , including CVE-2020-6282 (code injection), note 2622660 (Chromium updates), CVE-2020-6242 (code injection), and CVE-2020-6219 (deserialization of untrusted data).

VMware also [15]emitted fixes for CVE-2020-11651 and CVE-2020-11652, which are authentication bypass and directory traversal vulnerabilities. ®

Sponsored: [16]How to Build Your Digital Experience Portfolio



[1] https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/2020-May

[2] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1067

[3] https://www.theregister.co.uk/2020/05/08/samsung_android_patches/

[4] https://www.zerodayinitiative.com/blog/2020/5/12/the-may-2020-security-update-review

[5] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1192

[6] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1023

[7] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1024

[8] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1102

[9] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1069

[10] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1093

[11] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1153

[12] https://www.askwoody.com/2020/many-reports-of-errors-when-trying-to-install-the-latest-net-patch-on-win7-systems-with-extended-security-updates-enabled/

[13] https://helpx.adobe.com/security/products/acrobat/apsb20-24.html

[14] https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222

[15] https://www.vmware.com/security/advisories/VMSA-2020-0009.html

[16] https://go.theregister.co.uk/tl/1936/-8578/how-to-build-your-digital-experience-portfolio?td=wptl1936

Gibson's Springtime Song (to the tune of "Deck the Halls"):

'Tis the season to chase mousies (Fa la la la la, la la la la)
Snatch them from their little housies (...)
First we chase them 'round the field (...)
Then we have them for a meal (...)

Toss them here and catch them there (...)
See them flying through the air (...)
Watch them fly and hear them squeal (...)
Falling mice have great appeal (...)

See the hunter stretched before us (...)
He's chased the mice in field and forest (...)
Watch him clean his long white whiskers (...)
Of the blood of little critters (...)