June's Patch Tuesday reveals 23 ways to remotely pwn Windows – and over 100 more bugs that could ruin your day
(2020/06/09)
- Reference: 1591738125
- News link: https://www.theregister.co.uk/2020/06/09/june_2020_patch_tuesday/
- Source link:
Patch Tuesday Microsoft has given IT admins and folks another busy Patch Tuesday with 129 security vulnerabilities to address.
The Redmond giant has posted fixes for CVE-listed bugs in its latest monthly security update, including 23 that allow for remote code execution. The massive bundle is not entirely unexpected, as security experts [1]have suggested that vendors are still catching up on their patching and reporting routines.
Of the 129 patches this month, 11 were rated by Microsoft as critical security risks. Fortunately, there are no reports of public exploit code nor in-the-wild attacks on any of the flaws as yet – but remember Exploit Wednesday. Once the bugs are known, and patches available, exploits can be reverse-engineered.
LNK flaws strike again
One of the bugs that was of particular interest to researchers was [2]CVE-2020-1299 , a remote code execution issue that arises when trying to load Windows shortcut (LNK) files. This is the third time this year Microsoft has had to address an RCE bug in such shortcuts.
"An attacker could use this vulnerability to get code execution by having an affected system process a specially crafted .LNK file," [3]explained Dustin Childs of the Trend Micro Zero Day Initiative (ZDI).
"These types of files are often put on a USB drive in an attempt to bridge an air-gapped network."
Also catching the eye of the ZDI team was [4]CVE-2020-1229 , a security bypass bug in Outlook that, while not particularly concerning at first glance, poses a significant risk if chained with other exploits.
"This bug could allow attackers to automatically load remote images – even from within the Preview Pane," said Childs. "While this bypass alone could just disclose the IP address of a target system, it’s not unheard of to get code execution through the processing of specially crafted images (see any GDI+ bug)."
Other RCE bugs include [5]CVE-2020-1300 , which is exploited via a malformed CAB file, and [6]CVE-2020-1286 , a Windows Shell bug that can be exploited with malformed web pages or emails.
SharePoint Server admins will want to make sure they test out and install the fix for [7]CVE-2020-1181 as soon as possible in order to prevent remote code execution attacks. Microsoft also patched six SharePoint XSS flaws ( [8]CVE-2020-1177 , [9]CVE-2020-1183 , [10]CVE-2020-1297 , [11]CVE-2020-1298 , [12]CVE-2020-1318 , [13]CVE-2020-1320 ), two elevation of privilege flaws ( [14]CVE-2020-1295 , [15]CVE-2020-1178 ), and three spoofing bugs ( [16]CVE-2020-1148 , [17]CVE-2020-1289 , [18]CVE-2020-1323 ).
As usual, VBScript ( [19]CVE-2020-1213 , [20]CVE-2020-1216 , [21]CVE-2020-1260 ) and the ChakraCore Scripting Engine ( [22]CVE-2020-1073 ) were also among the recipients of critical remote code execution fixes.
While Microsoft tends not to consider Office and multimedia RCE bugs to be critical risks because users need to manually open files in order to trigger an attack, admins should put a priority on testing and patching the updates for Jet Database ( [23]CVE-2020-1208 , [24]CVE-2020-1236 ), Media Foundation ( [25]CVE-2020-1238 , [26]CVE-2020-1239 ), Excel ( [27]CVE-2020-1225 , [28]CVE-2020-1226 ), Office ( [29]CVE-2020-1321 ), VBScript ( [30]CVE-2020-1214 , [31]CVE-2020-1215 , [32]CVE-2020-1230 ), and SMB ( [33]CVE-2020-1301 ).
Those running word on Android will also want to make sure they update their software, as Microsoft issued a patch for [34]CVE-2020-1223 , a remote code execution flaw.
Haven't killed Flash yet? In that case you'll want this Adobe patch
Adobe has [35]issued a fix for a single remote code execution hole in its aging Flash Player plugin. CVE-2020-9633 is a use-after-free bug present in the Windows, macOS, Linux, and ChromeOS versions of Flash Player. Adobe did not say who found the flaw.
Also updated was the Adobe Experience Manager, an ad management tool. [36]The fix addresses six CVE-listed vulnerabilities (CVE-2020-9643, CVE-2020-9647, CVE-2020-9648, CVE-2020-9644, CVE-2020-9645, CVE-2020-9651) allowing for information disclosure and arbitrary JavaScript execution. Netcentric's Thomas Hartmann found CVE-2020-9644, while indie researcher Dmitry Muntyanov got credit for CVE-2020-9645.
The third of the updates was given to [37]Adobe Framemaker to clean up up three arbitrary code execution bugs (CVE-2020-9636, CVE-2020-9634, CVE-2020-9635). Adobe credits ZDI researcher Francis Provencher with reporting CVE-2020-9634 and CVE-2020-9635, while Honggang Ren of Fortiguard Labs found CVE-2020-9636.
Five Intel updates, including a re-hash of CacheOut bug
Chipzilla is now part of the Patch Tuesday as well, so everyone using Intel hardware will want to check out the fixes for flaws in [38]Innovation Engine (CVE-2020-8675, elevation of privilege via the firmware build and signing tool) and [39]Special Register Buffer (CVE-2020-0543, information disclosure caused by incomplete register data cleanup). This speculative execution vulnerability, dubbed [40]SGAxe [PDF], is a new take on the [41]CacheOut vulnerability .
A [42]single bulletin was issued to address 20 different vulnerabilities in CSME, SPS, TXE, AMT, ISM, and DAL. The bugs have a number of sources, including the IPv6 subsystem, improper input validation, and a one-way hash in CSME.
Exploits could allow for denial of service, information disclosure, and elevation of privilege, the latter being particularly bad in the context of Intel firmware.
Intel also issued updates, for its [43]BIOS (CVE-2020-0528, denial of service or elevation of privilege via improper buffer restrictions) and [44]SSD firmware (CVE-2020-0527, information disclosure from insufficient control flow management).
SAP pushes 17 updates
Those admins looking over SAP installations will want to check if their software is included in [45]the lineup of 17 June security notes, including fixes to [46]Apache Tomcat (CVE-2020-1938), [47]two [48]fixes for SAP Commerce (CVE-2020-6265, CVE-2020-6264), SAP [49]Success Factors (CVE-2020-6279), and [50]NetWeaver (CVE-2020-6275). ®
Sponsored: [51]The Forrester New Wave™: Public Cloud Enterprise Container Platforms, Q3 2019
[1] https://www.theregister.com/2020/05/29/bug_reports_down/
[2] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1299
[3] https://www.zerodayinitiative.com/blog/2020/6/9/the-june-2020-security-update-review
[4] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1229
[5] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1300
[6] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1286
[7] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1181
[8] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1177
[9] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1183
[10] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1297
[11] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1298
[12] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1318
[13] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1320
[14] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1295
[15] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1178
[16] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1148
[17] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1289
[18] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1323
[19] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1213
[20] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1216
[21] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1260
[22] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1073
[23] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1208
[24] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1236
[25] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1238
[26] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1239
[27] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1225
[28] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1226
[29] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1321
[30] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1214
[31] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1215
[32] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1230
[33] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1301
[34] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1223
[35] https://helpx.adobe.com/security/products/flash-player/apsb20-30.html
[36] https://helpx.adobe.com/security/products/experience-manager/apsb20-31.html
[37] https://helpx.adobe.com/security/products/framemaker/apsb20-32.html
[38] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00366.html
[39] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00320.html
[40] https://sgaxe.com/files/SGAxe.pdf
[41] https://www.theregister.com/2020/01/28/intel_processor_data_leak/
[42] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html
[43] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00322.html
[44] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00266.html
[45] https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=547426775
[46] https://launchpad.support.sap.com/#/notes/2928570
[47] https://launchpad.support.sap.com/#/notes/2918924
[48] https://launchpad.support.sap.com/#/notes/2906366
[49] https://launchpad.support.sap.com/#/notes/2933282
[50] https://launchpad.support.sap.com/#/notes/2912939
[51] https://go.theregister.com/tl/1956/-8475/the-forrester-new-wave-public-cloud-enterprise-container-platforms-q3-2019?td=wptl1956
The Redmond giant has posted fixes for CVE-listed bugs in its latest monthly security update, including 23 that allow for remote code execution. The massive bundle is not entirely unexpected, as security experts [1]have suggested that vendors are still catching up on their patching and reporting routines.
Of the 129 patches this month, 11 were rated by Microsoft as critical security risks. Fortunately, there are no reports of public exploit code nor in-the-wild attacks on any of the flaws as yet – but remember Exploit Wednesday. Once the bugs are known, and patches available, exploits can be reverse-engineered.
LNK flaws strike again
One of the bugs that was of particular interest to researchers was [2]CVE-2020-1299 , a remote code execution issue that arises when trying to load Windows shortcut (LNK) files. This is the third time this year Microsoft has had to address an RCE bug in such shortcuts.
"An attacker could use this vulnerability to get code execution by having an affected system process a specially crafted .LNK file," [3]explained Dustin Childs of the Trend Micro Zero Day Initiative (ZDI).
"These types of files are often put on a USB drive in an attempt to bridge an air-gapped network."
Also catching the eye of the ZDI team was [4]CVE-2020-1229 , a security bypass bug in Outlook that, while not particularly concerning at first glance, poses a significant risk if chained with other exploits.
"This bug could allow attackers to automatically load remote images – even from within the Preview Pane," said Childs. "While this bypass alone could just disclose the IP address of a target system, it’s not unheard of to get code execution through the processing of specially crafted images (see any GDI+ bug)."
Other RCE bugs include [5]CVE-2020-1300 , which is exploited via a malformed CAB file, and [6]CVE-2020-1286 , a Windows Shell bug that can be exploited with malformed web pages or emails.
SharePoint Server admins will want to make sure they test out and install the fix for [7]CVE-2020-1181 as soon as possible in order to prevent remote code execution attacks. Microsoft also patched six SharePoint XSS flaws ( [8]CVE-2020-1177 , [9]CVE-2020-1183 , [10]CVE-2020-1297 , [11]CVE-2020-1298 , [12]CVE-2020-1318 , [13]CVE-2020-1320 ), two elevation of privilege flaws ( [14]CVE-2020-1295 , [15]CVE-2020-1178 ), and three spoofing bugs ( [16]CVE-2020-1148 , [17]CVE-2020-1289 , [18]CVE-2020-1323 ).
As usual, VBScript ( [19]CVE-2020-1213 , [20]CVE-2020-1216 , [21]CVE-2020-1260 ) and the ChakraCore Scripting Engine ( [22]CVE-2020-1073 ) were also among the recipients of critical remote code execution fixes.
While Microsoft tends not to consider Office and multimedia RCE bugs to be critical risks because users need to manually open files in order to trigger an attack, admins should put a priority on testing and patching the updates for Jet Database ( [23]CVE-2020-1208 , [24]CVE-2020-1236 ), Media Foundation ( [25]CVE-2020-1238 , [26]CVE-2020-1239 ), Excel ( [27]CVE-2020-1225 , [28]CVE-2020-1226 ), Office ( [29]CVE-2020-1321 ), VBScript ( [30]CVE-2020-1214 , [31]CVE-2020-1215 , [32]CVE-2020-1230 ), and SMB ( [33]CVE-2020-1301 ).
Those running word on Android will also want to make sure they update their software, as Microsoft issued a patch for [34]CVE-2020-1223 , a remote code execution flaw.
Haven't killed Flash yet? In that case you'll want this Adobe patch
Adobe has [35]issued a fix for a single remote code execution hole in its aging Flash Player plugin. CVE-2020-9633 is a use-after-free bug present in the Windows, macOS, Linux, and ChromeOS versions of Flash Player. Adobe did not say who found the flaw.
Also updated was the Adobe Experience Manager, an ad management tool. [36]The fix addresses six CVE-listed vulnerabilities (CVE-2020-9643, CVE-2020-9647, CVE-2020-9648, CVE-2020-9644, CVE-2020-9645, CVE-2020-9651) allowing for information disclosure and arbitrary JavaScript execution. Netcentric's Thomas Hartmann found CVE-2020-9644, while indie researcher Dmitry Muntyanov got credit for CVE-2020-9645.
The third of the updates was given to [37]Adobe Framemaker to clean up up three arbitrary code execution bugs (CVE-2020-9636, CVE-2020-9634, CVE-2020-9635). Adobe credits ZDI researcher Francis Provencher with reporting CVE-2020-9634 and CVE-2020-9635, while Honggang Ren of Fortiguard Labs found CVE-2020-9636.
Five Intel updates, including a re-hash of CacheOut bug
Chipzilla is now part of the Patch Tuesday as well, so everyone using Intel hardware will want to check out the fixes for flaws in [38]Innovation Engine (CVE-2020-8675, elevation of privilege via the firmware build and signing tool) and [39]Special Register Buffer (CVE-2020-0543, information disclosure caused by incomplete register data cleanup). This speculative execution vulnerability, dubbed [40]SGAxe [PDF], is a new take on the [41]CacheOut vulnerability .
A [42]single bulletin was issued to address 20 different vulnerabilities in CSME, SPS, TXE, AMT, ISM, and DAL. The bugs have a number of sources, including the IPv6 subsystem, improper input validation, and a one-way hash in CSME.
Exploits could allow for denial of service, information disclosure, and elevation of privilege, the latter being particularly bad in the context of Intel firmware.
Intel also issued updates, for its [43]BIOS (CVE-2020-0528, denial of service or elevation of privilege via improper buffer restrictions) and [44]SSD firmware (CVE-2020-0527, information disclosure from insufficient control flow management).
SAP pushes 17 updates
Those admins looking over SAP installations will want to check if their software is included in [45]the lineup of 17 June security notes, including fixes to [46]Apache Tomcat (CVE-2020-1938), [47]two [48]fixes for SAP Commerce (CVE-2020-6265, CVE-2020-6264), SAP [49]Success Factors (CVE-2020-6279), and [50]NetWeaver (CVE-2020-6275). ®
Sponsored: [51]The Forrester New Wave™: Public Cloud Enterprise Container Platforms, Q3 2019
[1] https://www.theregister.com/2020/05/29/bug_reports_down/
[2] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1299
[3] https://www.zerodayinitiative.com/blog/2020/6/9/the-june-2020-security-update-review
[4] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1229
[5] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1300
[6] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1286
[7] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1181
[8] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1177
[9] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1183
[10] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1297
[11] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1298
[12] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1318
[13] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1320
[14] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1295
[15] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1178
[16] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1148
[17] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1289
[18] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1323
[19] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1213
[20] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1216
[21] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1260
[22] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1073
[23] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1208
[24] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1236
[25] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1238
[26] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1239
[27] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1225
[28] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1226
[29] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1321
[30] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1214
[31] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1215
[32] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1230
[33] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1301
[34] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1223
[35] https://helpx.adobe.com/security/products/flash-player/apsb20-30.html
[36] https://helpx.adobe.com/security/products/experience-manager/apsb20-31.html
[37] https://helpx.adobe.com/security/products/framemaker/apsb20-32.html
[38] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00366.html
[39] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00320.html
[40] https://sgaxe.com/files/SGAxe.pdf
[41] https://www.theregister.com/2020/01/28/intel_processor_data_leak/
[42] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html
[43] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00322.html
[44] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00266.html
[45] https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=547426775
[46] https://launchpad.support.sap.com/#/notes/2928570
[47] https://launchpad.support.sap.com/#/notes/2918924
[48] https://launchpad.support.sap.com/#/notes/2906366
[49] https://launchpad.support.sap.com/#/notes/2933282
[50] https://launchpad.support.sap.com/#/notes/2912939
[51] https://go.theregister.com/tl/1956/-8475/the-forrester-new-wave-public-cloud-enterprise-container-platforms-q3-2019?td=wptl1956
Re: Isn't the title the inverse? "23 ways to STOP remotely pwn Windows..."
Giles C
Well as the article says patch Tuesday then exploit Wednesday.
I’m sure someone will be busy working out how to exploit machines which haven’t got the patches installed yet, and probably have something out to spam users with tonight...
Patches
diodesign
Patch Tuesday reveals the ways Windows et al can be pwned, with patches to stop that from happening. The patches disclose not only the way in which the bugs can be exploited but provides enough material for reverse engineers to product exploits.
C.
Isn't the title the inverse? "23 ways to STOP remotely pwn Windows..."
I think these patches are meant to correct flaws in all these systems/applications rather than introduce new ones.
However, given the players, I could be mistaken.