Patchday August 2020

Patchday August 2020

Patchday August 2020

‍Since 2003, Microsoft has released the latest security updates for the Windows and Windows Server operating systems and all other software products on the second Tuesday of every month. The fixed timing enables IT departments to plan patch management efficiently, as several patches can be applied with just one reboot.

In total, Microsoft published 120 vulnerabilities; 17 were classified as "critical", 103 as "important".‍

Security updates were released for the following products:

  • Microsoft Windows

  • Microsoft Edge (EdgeHTML-based)

  • Microsoft Edge (Chromium-based)

  • Microsoft ChakraCore

  • Internet Explorer

  • Microsoft Scripting Engine

  • SQL Server

  • Microsoft JET Database Engine

  • .NET Framework

  • ASP.NET Core

  • Microsoft Office and Microsoft Office Services and Web Apps

  • Microsoft Windows Codecs Library

  • Microsoft Dynamics

Even small vulnerabilities can have a big impact!

According to the Zero Day Initiative, the two vulnerabilities CVE-2020-1464 and CVE-2020-1380 are considered active at the time of publication!

If the Windows spoofing vulnerability CVE-2020-1464 is exploited by an attacker, he could bypass security functions and thus load improperly signed files.

The CVE-2020-1380 vulnerability is a memory issue in the scripting engine associated with Internet Explorer. The memory could be corrupted in such a way that an attacker exploiting this vulnerability could gain the same user rights as the current user. If administrative user rights are involved, the attacker could install programmes, modify data and even create new accounts with full user rights.

Five of the 17 critical vulnerabilities published in August affect the Windows Media Foundation (WMF). This is a multimedia framework and infrastructure platform for handling digital media in Windows 7-10 and Windows Server 2008-2019.

  • CVE-2020-1554

  • CVE-2020-1492

  • CVE-2020-1379

  • CVE-2020-1477

  • CVE-2020-1525

Also classified as critical and rarely occurring is the vulnerability CVE-2020-1472. If an attacker establishes a vulnerable secure Netlogon channel connection to a domain controller using the Netlogon Remote Protocol (MS-NRPC), there is an increased privilege escalation vulnerability. If an unauthenticated attacker establishes a connection to a domain controller via MS-NRPC, they can gain access to a domain administrator. This vulnerability will be fixed in a staggered two-part rollout.

Abdul-Aziz Hariri, security researcher at the Trend Micro Zero Day Initiative, reported the vulnerability CVE-2020-1585, among others. If an attacker tricks a user into viewing a specially crafted image file - the "AV1 Video Extension" codec is affected here - it allows the attacker to execute code.

For detailed information on the updates and recommendations for downloads, see Microsoft Security Update Guide.

For the 6 CVEs classified as publicly known: patch as soon as possible!

Max Mustermann

Adobe has also been taking part in Patchday since 2005. In August, Adobe only had to release updates for two products. 26 "leaks" were patched in Adobe Acrobat and Adobe Reader. Of these, 11 were assessed as critical. Detailed information on the Adobe Acrobat and Adobe Reader updates can be found here.

The gaps in Adobe Lightroom were classified as important and can be here.

Software manufacturer SAP has also been taking part in Patchday since 2010. In August, 16 vulnerabilities were published - two "Hot News", 6 vulnerabilities with a "High" rating and 8 with a "Medium" rating.

The update to NetWeaver, which protects against a critical cross-site scripting (XSS) vulnerability, is classified as "Hot News".

The vulnerabilities with the classification "High" concern:

  • SAP BusinessObjects

  • SAP Banking Services

  • SAP NetWeaver (ABAP)

  • SAP NetWeaver AS JAVA and Knowledge Management

  • SAP Adaptive Server Enterprise

Vulnerability management is an important part of a well-functioning security strategy and requires constant attention. Stay vigilant until the next patch day on 8 September 2020.

A vulnerability is a security hole that can be turned into a threat by intruders!

Max Mustermann

Read more here.

In an update from 23 September, KOMMUNAL reported that the first traces lead to Russia. The malware "Doppel Paymer" is presumably an encryption Trojan that has already been used by Russian hackers in other cases.

Check back soon when it says: It's Time for Patchday! The next one will take place on 10 November.