in

Microsoft May 2020 Patch Tuesday fixes 111 vulnerabilities

windows-updates-patch-tuesday.jpg

Microsoft has started rolling out today the May 2020 Patch Tuesday security updates. This month, the company has patched 111 vulnerabilities across 12 different products, from Edge to Windows, and from Visual Studio to the .NET Framework.

This month’s Patch Tuesday is the third-largest in Microsoft’s history after the company patched 115 bugs in March 2020 and 113 in April 2020.

While Microsoft has patched actively-exploited zero-day vulnerabilities in the past two months, there are no such bugs in this release.

This means that system administrators have time at their disposal to test today’s Patch Tuesday for bugs or other issues before deploying the updates to all their systems.

Patches shouldn’t be delayed too much because threat actors regularly patch-diff the Microsoft security updates in search of bugs that can be easily exploited.

Among the most severe bugs patched this month that could be weaponized for attacks against users in the future, we list:

Additional information about this month’s Patch Tuesday is included below, including links to security advisories published by other companies:

  • Microsoft’s official Security Update Guide portal lists all security updates in a filterable table.
  • ZDNet has also put together this page listing all this month’s security advisories on one single page.
  • Adobe’s security updates are detailed here.
  • SAP security updates are available here.
  • VMWare security updates are available here.
  • Firefox security updates have been released last week, with the release of Firefox v76.
  • Google Chrome security updates are now released bi-weekly. Security updates have been released last week, and a new batch is scheduled for next week, with the Chrome v83 release.
  • The Android Security Bulletin for May 2020 is detailed here. Patches started rolling out to users’ phones last week.
TagCVE IDCVE Title
.NET CoreCVE-2020-1161ASP.NET Core Denial of Service Vulnerability
.NET CoreCVE-2020-1108.NET Core & .NET Framework Denial of Service Vulnerability
.NET FrameworkCVE-2020-1066.NET Framework Elevation of Privilege Vulnerability
Active DirectoryCVE-2020-1055Microsoft Active Directory Federation Services Cross-Site Scripting Vulnerability
Common Log File System DriverCVE-2020-1154Windows Common Log File System Driver Elevation of Privilege Vulnerability
Internet ExplorerCVE-2020-1092Internet Explorer Memory Corruption Vulnerability
Internet ExplorerCVE-2020-1064MSHTML Engine Remote Code Execution Vulnerability
Internet ExplorerCVE-2020-1062Internet Explorer Memory Corruption Vulnerability
Internet ExplorerCVE-2020-1093VBScript Remote Code Execution Vulnerability
Microsoft DynamicsCVE-2020-1063Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability
Microsoft EdgeCVE-2020-1059Microsoft Edge Spoofing Vulnerability
Microsoft EdgeCVE-2020-1056Microsoft Edge Elevation of Privilege Vulnerability
Microsoft EdgeCVE-2020-1096Microsoft Edge PDF Remote Code Execution Vulnerability
Microsoft Graphics ComponentCVE-2020-1145Windows GDI Information Disclosure Vulnerability
Microsoft Graphics ComponentCVE-2020-1135Windows Graphics Component Elevation of Privilege Vulnerability
Microsoft Graphics ComponentCVE-2020-1179Windows GDI Information Disclosure Vulnerability
Microsoft Graphics ComponentCVE-2020-1153Microsoft Graphics Components Remote Code Execution Vulnerability
Microsoft Graphics ComponentCVE-2020-1140DirectX Elevation of Privilege Vulnerability
Microsoft Graphics ComponentCVE-2020-0963Windows GDI Information Disclosure Vulnerability
Microsoft Graphics ComponentCVE-2020-1054Win32k Elevation of Privilege Vulnerability
Microsoft Graphics ComponentCVE-2020-1142Windows GDI Elevation of Privilege Vulnerability
Microsoft Graphics ComponentCVE-2020-1117Microsoft Color Management Remote Code Execution Vulnerability
Microsoft Graphics ComponentCVE-2020-1141Windows GDI Information Disclosure Vulnerability
Microsoft JET Database EngineCVE-2020-1176Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2020-1051Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2020-1175Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2020-1174Jet Database Engine Remote Code Execution Vulnerability
Microsoft OfficeCVE-2020-0901Microsoft Excel Remote Code Execution Vulnerability
Microsoft Office SharePointCVE-2020-1069Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft Office SharePointCVE-2020-1100Microsoft Office SharePoint XSS Vulnerability
Microsoft Office SharePointCVE-2020-1105Microsoft SharePoint Spoofing Vulnerability
Microsoft Office SharePointCVE-2020-1102Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft Office SharePointCVE-2020-1024Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft Office SharePointCVE-2020-1023Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft Office SharePointCVE-2020-1104Microsoft SharePoint Spoofing Vulnerability
Microsoft Office SharePointCVE-2020-1101Microsoft Office SharePoint XSS Vulnerability
Microsoft Office SharePointCVE-2020-1099Microsoft Office SharePoint XSS Vulnerability
Microsoft Office SharePointCVE-2020-1103Microsoft SharePoint Information Disclosure Vulnerability
Microsoft Office SharePointCVE-2020-1107Microsoft SharePoint Spoofing Vulnerability
Microsoft Office SharePointCVE-2020-1106Microsoft Office SharePoint XSS Vulnerability
Microsoft Scripting EngineCVE-2020-1060VBScript Remote Code Execution Vulnerability
Microsoft Scripting EngineCVE-2020-1065Scripting Engine Memory Corruption Vulnerability
Microsoft Scripting EngineCVE-2020-1037Chakra Scripting Engine Memory Corruption Vulnerability
Microsoft Scripting EngineCVE-2020-1035VBScript Remote Code Execution Vulnerability
Microsoft Scripting EngineCVE-2020-1058VBScript Remote Code Execution Vulnerability
Microsoft WindowsCVE-2020-1111Windows Clipboard Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1112Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1082Windows Error Reporting Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1086Windows Runtime Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1048Windows Print Spooler Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1090Windows Runtime Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1088Windows Error Reporting Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1166Windows Clipboard Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1021Windows Error Reporting Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1164Windows Runtime Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1165Windows Clipboard Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1184Windows State Repository Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1188Windows State Repository Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1191Windows State Repository Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1185Windows State Repository Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1187Windows State Repository Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1125Windows Runtime Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1131Windows State Repository Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1121Windows Clipboard Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1123Connected User Experiences and Telemetry Service Denial of Service Vulnerability
Microsoft WindowsCVE-2020-1132Windows Error Reporting Manager Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1010Microsoft Windows Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1028Media Foundation Memory Corruption Vulnerability
Microsoft WindowsCVE-2020-1136Media Foundation Memory Corruption Vulnerability
Microsoft WindowsCVE-2020-1139Windows Runtime Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1144Windows State Repository Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1149Windows Runtime Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1076Windows Denial of Service Vulnerability
Microsoft WindowsCVE-2020-1143Win32k Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1071Windows Remote Access Common Dialog Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1155Windows Runtime Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1150Media Foundation Memory Corruption Vulnerability
Microsoft WindowsCVE-2020-1151Windows Runtime Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1138Windows Storage Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1118Microsoft Windows Transport Layer Security Denial of Service Vulnerability
Microsoft WindowsCVE-2020-1124Windows State Repository Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1084Connected User Experiences and Telemetry Service Denial of Service Vulnerability
Microsoft WindowsCVE-2020-1116Windows CSRSS Information Disclosure Vulnerability
Microsoft WindowsCVE-2020-1078Windows Installer Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1137Windows Push Notification Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1126Media Foundation Memory Corruption Vulnerability
Microsoft WindowsCVE-2020-1134Windows State Repository Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1070Windows Print Spooler Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1068Microsoft Windows Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1067Windows Remote Code Execution Vulnerability
Microsoft WindowsCVE-2020-1072Windows Kernel Information Disclosure Vulnerability
Microsoft WindowsCVE-2020-1081Windows Printer Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1079Microsoft Windows Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1077Windows Runtime Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1190Windows State Repository Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1158Windows Runtime Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1157Windows Runtime Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1186Windows State Repository Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1156Windows Runtime Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1189Windows State Repository Service Elevation of Privilege Vulnerability
Power BICVE-2020-1173Microsoft Power BI Report Server Spoofing Vulnerability
Visual StudioCVE-2020-1192Visual Studio Code Python Extension Remote Code Execution Vulnerability
Visual StudioCVE-2020-1171Visual Studio Code Python Extension Remote Code Execution Vulnerability
Windows Hyper-VCVE-2020-0909Windows Hyper-V Denial of Service Vulnerability
Windows KernelCVE-2020-1114Windows Kernel Elevation of Privilege Vulnerability
Windows KernelCVE-2020-1087Windows Kernel Elevation of Privilege Vulnerability
Windows ScriptingCVE-2020-1061Microsoft Script Runtime Remote Code Execution Vulnerability
Windows Subsystem for LinuxCVE-2020-1075Windows Subsystem for Linux Information Disclosure Vulnerability
Windows Task SchedulerCVE-2020-1113Windows Task Scheduler Security Feature Bypass Vulnerability
Windows Update StackCVE-2020-1109Windows Update Stack Elevation of Privilege Vulnerability
Windows Update StackCVE-2020-1110Windows Update Stack Elevation of Privilege Vulnerability


Source: Information Technologies - zdnet.com

On the three-year anniversary of WannaCry, US exposes new North Korean malware

Out-of-date, insecure open-source software is everywhere