in

Microsoft August 2020 Patch Tuesday fixes 120 vulnerabilities, two zero-days

Microsoft has started rolling out today the August 2020 Patch Tuesday security updates.

This month, the company has patched 120 vulnerabilities across 13 different products, from Edge to Windows, and from SQL Server to the .NET Framework.

Among the 120 vulnerabilities fixed this month, 17 bugs have received the highest severity rating of “Critical,” and there are also two zero-days — vulnerabilities that have been exploited by hackers before Microsoft was able to provide today’s patches.

Zero-day #1

The first of the two zero-days patched this month is a bug in the Windows operating system. Tracked as CVE-2020-1464, Microsoft says that an attacker can exploit this bug and have Windows incorrectly validate file signatures.

The OS maker says attackers can (ab)use this bug to “bypass security features and load improperly signed files.”

As with all Microsoft security advisories, technical details about the bug and the real-world attacks have not been made public. Microsoft security team uses this approach to prevent other hackers from inferring how and where the vulnerability wors/resides, and prolong the time it takes for other exploits to appear in the wild.

Zero-day #2

As for the second zero-day, this one is tracked as CVE-2020-1380, and resides in the scripting engine that ships with Internet Explorer.

Microsoft said it received a report from antivirus maker Kaspersky that hackers had found a remote code execution (RCE) bug in the IE scripting engine and where abusing it in real-world attacks.

While the bug resides in the IE scripting engine, other native Microsoft apps are also impacted, such as the company’s Office suite.

This is because Office apps use the IE scripting engine to embed and render web pages inside Office documents, a feature where the scripting engine plays a major role.

This means the bug can be exploited by luring users on malicious sites, or by sending them booby-trapped Office files.

Below is some useful information about today’s Microsoft Patch Tuesday, but also the security updates released by other companies this month, which sysadmins might also need to address as well, besides Microsoft’s batch.

  • Microsoft’s official Security Update Guide portal lists all security updates in a filterable table.
  • ZDNet has published this file listing all this month’s security advisories on one single page.
  • Adobe’s security updates are detailed here.
  • SAP security updates are available here.
  • VMWare security updates are available here.
  • Citrix has also released some patches today.
  • Oracle’s quarterly patches (for Q2 2020, July edition) are available here.
  • Chrome 84 security updates are detailed here.
  • The Android Security Bulletin for August 2020 is detailed here. Patches started rolling out to users’ phones last week.
TagCVE IDCVE Title
.NET FrameworkCVE-2020-1476ASP.NET and .NET Elevation of Privilege Vulnerability
.NET FrameworkCVE-2020-1046.NET Framework Remote Code Execution Vulnerability
ASP.NETCVE-2020-1597ASP.NET Core Denial of Service Vulnerability
Internet ExplorerCVE-2020-1567MSHTML Engine Remote Code Execution Vulnerability
Microsoft DynamicsCVE-2020-1591Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability
Microsoft EdgeCVE-2020-1569Microsoft Edge Memory Corruption Vulnerability
Microsoft EdgeCVE-2020-1568Microsoft Edge PDF Remote Code Execution Vulnerability
Microsoft Graphics ComponentCVE-2020-1562Microsoft Graphics Components Remote Code Execution Vulnerability
Microsoft Graphics ComponentCVE-2020-1577DirectWrite Information Disclosure Vulnerability
Microsoft Graphics ComponentCVE-2020-1561Microsoft Graphics Components Remote Code Execution Vulnerability
Microsoft Graphics ComponentCVE-2020-1510Win32k Information Disclosure Vulnerability
Microsoft Graphics ComponentCVE-2020-1529Windows GDI Elevation of Privilege Vulnerability
Microsoft JET Database EngineCVE-2020-1473Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2020-1558Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2020-1557Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2020-1564Jet Database Engine Remote Code Execution Vulnerability
Microsoft OfficeCVE-2020-1483Microsoft Outlook Memory Corruption Vulnerability
Microsoft OfficeCVE-2020-1504Microsoft Excel Remote Code Execution Vulnerability
Microsoft OfficeCVE-2020-1503Microsoft Word Information Disclosure Vulnerability
Microsoft OfficeCVE-2020-1495Microsoft Excel Remote Code Execution Vulnerability
Microsoft OfficeCVE-2020-1494Microsoft Excel Remote Code Execution Vulnerability
Microsoft OfficeCVE-2020-1493Microsoft Outlook Information Disclosure Vulnerability
Microsoft OfficeCVE-2020-1496Microsoft Excel Remote Code Execution Vulnerability
Microsoft OfficeCVE-2020-1502Microsoft Word Information Disclosure Vulnerability
Microsoft OfficeCVE-2020-1498Microsoft Excel Remote Code Execution Vulnerability
Microsoft OfficeCVE-2020-1497Microsoft Excel Information Disclosure Vulnerability
Microsoft OfficeCVE-2020-1581Microsoft Office Click-to-Run Elevation of Privilege Vulnerability
Microsoft OfficeCVE-2020-1563Microsoft Office Remote Code Execution Vulnerability
Microsoft OfficeCVE-2020-1582Microsoft Access Remote Code Execution Vulnerability
Microsoft OfficeCVE-2020-1583Microsoft Word Information Disclosure Vulnerability
Microsoft Office SharePointCVE-2020-1505Microsoft SharePoint Information Disclosure Vulnerability
Microsoft Office SharePointCVE-2020-1573Microsoft Office SharePoint XSS Vulnerability
Microsoft Office SharePointCVE-2020-1499Microsoft SharePoint Spoofing Vulnerability
Microsoft Office SharePointCVE-2020-1500Microsoft SharePoint Spoofing Vulnerability
Microsoft Office SharePointCVE-2020-1580Microsoft Office SharePoint XSS Vulnerability
Microsoft Office SharePointCVE-2020-1501Microsoft SharePoint Spoofing Vulnerability
Microsoft Scripting EngineCVE-2020-1570Scripting Engine Memory Corruption Vulnerability
Microsoft Scripting EngineCVE-2020-1555Scripting Engine Memory Corruption Vulnerability
Microsoft Scripting EngineCVE-2020-1380Scripting Engine Memory Corruption Vulnerability
Microsoft Video ControlCVE-2020-1492Media Foundation Memory Corruption Vulnerability
Microsoft WindowsCVE-2020-1485Windows Image Acquisition Service Information Disclosure Vulnerability
Microsoft WindowsCVE-2020-1587Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1551Windows Backup Engine Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1484Windows Work Folders Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1489Windows CSC Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1584Windows dnsrslvr.dll Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1486Windows Kernel Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1488Windows AppX Deployment Extensions Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1490Windows Storage Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1515Windows Telephony Server Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1513Windows CSC Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1553Windows Runtime Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1552Windows Work Folder Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1566Windows Kernel Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1579Windows Function Discovery SSDP Provider Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1512Windows State Repository Service Information Disclosure Vulnerability
Microsoft WindowsCVE-2020-1511Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1480Windows GDI Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1542Windows Backup Engine Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1543Windows Backup Engine Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1540Windows Backup Engine Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1541Windows Backup Engine Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1544Windows Backup Engine Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1547Windows Backup Engine Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1519Windows UPnP Device Host Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1545Windows Backup Engine Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1546Windows Backup Engine Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1539Windows Backup Engine Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1528Windows Radio Manager API Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1530Windows Remote Access Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1526Windows Network Connection Broker Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1527Windows Custom Protocol Engine Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1534Windows Backup Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1537Windows Remote Access Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1520Windows Font Driver Host Remote Code Execution Vulnerability
Microsoft WindowsCVE-2020-1535Windows Backup Engine Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1536Windows Backup Engine Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1470Windows Work Folders Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1509Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1459Windows ARM Information Disclosure Vulnerability
Microsoft WindowsCVE-2020-1538Windows UPnP Device Host Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1475Windows Server Resource Management Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1464Windows Spoofing Vulnerability
Microsoft WindowsCVE-2020-1467Windows Hard Link Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1550Windows CDP User Components Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1517Windows File Server Resource Management Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1518Windows File Server Resource Management Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1516Windows Work Folders Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1549Windows CDP User Components Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1383Windows RRAS Service Information Disclosure Vulnerability
Microsoft Windows Codecs LibraryCVE-2020-1574Microsoft Windows Codecs Library Remote Code Execution Vulnerability
Microsoft Windows Codecs LibraryCVE-2020-1560Microsoft Windows Codecs Library Remote Code Execution Vulnerability
Microsoft Windows Codecs LibraryCVE-2020-1585Microsoft Windows Codecs Library Remote Code Execution Vulnerability
NetlogonCVE-2020-1472Netlogon Elevation of Privilege Vulnerability
SQL ServerCVE-2020-1455Microsoft SQL Server Management Studio Denial of Service Vulnerability
Visual StudioCVE-2020-0604Visual Studio Code Remote Code Execution Vulnerability
Windows AICVE-2020-1521Windows Speech Runtime Elevation of Privilege Vulnerability
Windows AICVE-2020-1522Windows Speech Runtime Elevation of Privilege Vulnerability
Windows AICVE-2020-1524Windows Speech Shell Components Elevation of Privilege Vulnerability
Windows COMCVE-2020-1474Windows Image Acquisition Service Information Disclosure Vulnerability
Windows KernelCVE-2020-1578Windows Kernel Information Disclosure Vulnerability
Windows KernelCVE-2020-1417Windows Kernel Elevation of Privilege Vulnerability
Windows KernelCVE-2020-1479DirectX Elevation of Privilege Vulnerability
Windows MediaCVE-2020-1379Media Foundation Memory Corruption Vulnerability
Windows MediaCVE-2020-1554Media Foundation Memory Corruption Vulnerability
Windows MediaCVE-2020-1339Windows Media Remote Code Execution Vulnerability
Windows MediaCVE-2020-1525Media Foundation Memory Corruption Vulnerability
Windows MediaCVE-2020-1487Media Foundation Information Disclosure Vulnerability
Windows Media PlayerCVE-2020-1478Media Foundation Memory Corruption Vulnerability
Windows Media PlayerCVE-2020-1477Media Foundation Memory Corruption Vulnerability
Windows Print Spooler ComponentsCVE-2020-1337Windows Print Spooler Elevation of Privilege Vulnerability
Windows RDPCVE-2020-1466Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
Windows RegistryCVE-2020-1377Windows Registry Elevation of Privilege Vulnerability
Windows RegistryCVE-2020-1378Windows Registry Elevation of Privilege Vulnerability
Windows ShellCVE-2020-1565Windows Elevation of Privilege Vulnerability
Windows ShellCVE-2020-1531Windows Accounts Control Elevation of Privilege Vulnerability
Windows Update StackCVE-2020-1571Windows Setup Elevation of Privilege Vulnerability
Windows Update StackCVE-2020-1548Windows WaasMedic Service Information Disclosure Vulnerability
Windows WalletServiceCVE-2020-1556Windows WalletService Elevation of Privilege Vulnerability
Windows WalletServiceCVE-2020-1533Windows WalletService Elevation of Privilege Vulnerability


Source: Information Technologies - zdnet.com

Threema joins the ranks of E2EE chat apps that support encrypted video calls

Coughs and hiccups aside, internet seems mostly immune to pandemic pressures