Published:
15 April 2020
Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT Security Bulletin ASB-2020.0081 Security updates for Microsoft Extended Security Update products 15 April 2020 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Internet Explorer 9 Windows 7 Windows Server 2008 Impact/Access: Execute Arbitrary Code/Commands -- Remote with User Interaction Access Confidential Data -- Existing Account Increased Privileges -- Existing Account Denial of Service -- Existing Account Resolution: Patch/Upgrade Member content until: Friday, May 15 2020 OVERVIEW Microsoft has released its monthly security patch update for the month of April 2020. This update resolves 41 vulnerabilities across the following products: [1] Internet Explorer 9 Windows 7 for 32-bit Systems Service Pack 1 Windows 7 for x64-based Systems Service Pack 1 Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1 Windows Server 2008 R2 for x64-based Systems Service Pack 1 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) Windows Server 2008 for 32-bit Systems Service Pack 2 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) Windows Server 2008 for Itanium-Based Systems Service Pack 2 Windows Server 2008 for x64-based Systems Service Pack 2 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) IMPACT Microsoft has given the following details regarding these vulnerabilities. Details Impact Severity CVE-2020-0687 Remote Code Execution Critical CVE-2020-0821 Information Disclosure Important CVE-2020-0889 Remote Code Execution Important CVE-2020-0895 Remote Code Execution Low CVE-2020-0907 Remote Code Execution Critical CVE-2020-0938 Remote Code Execution Critical CVE-2020-0946 Information Disclosure Important CVE-2020-0952 Information Disclosure Important CVE-2020-0953 Remote Code Execution Important CVE-2020-0955 Information Disclosure Important CVE-2020-0956 Elevation of Privilege Important CVE-2020-0957 Elevation of Privilege Important CVE-2020-0958 Elevation of Privilege Important CVE-2020-0959 Remote Code Execution Important CVE-2020-0960 Remote Code Execution Important CVE-2020-0962 Information Disclosure Important CVE-2020-0964 Remote Code Execution Important CVE-2020-0965 Remote Code Execution Critical CVE-2020-0966 Remote Code Execution Low CVE-2020-0967 Remote Code Execution Moderate CVE-2020-0968 Remote Code Execution Moderate CVE-2020-0982 Information Disclosure Important CVE-2020-0987 Information Disclosure Important CVE-2020-0988 Remote Code Execution Important CVE-2020-0992 Remote Code Execution Important CVE-2020-0993 Denial of Service Important CVE-2020-0994 Remote Code Execution Important CVE-2020-0995 Remote Code Execution Important CVE-2020-0999 Remote Code Execution Important CVE-2020-1000 Elevation of Privilege Important CVE-2020-1004 Elevation of Privilege Important CVE-2020-1005 Information Disclosure Important CVE-2020-1007 Information Disclosure Important CVE-2020-1008 Remote Code Execution Important CVE-2020-1009 Elevation of Privilege Important CVE-2020-1011 Elevation of Privilege Important CVE-2020-1014 Elevation of Privilege Important CVE-2020-1015 Elevation of Privilege Important CVE-2020-1020 Remote Code Execution Critical CVE-2020-1027 Elevation of Privilege Important CVE-2020-1094 Elevation of Privilege Important MITIGATION Microsoft recommends updating the software with the version made available on the Microsoft Update Catalogue for the following Knowledge Base articles. [1] KB4550964, KB4550951, KB4550905, KB4550957, KB4550965 REFERENCES [1] Security Update Guide https://portal.msrc.microsoft.com/en-us/security-guidance AusCERT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBXpaFrmaOgq3Tt24GAQiJwg//Z1UzDeYWtT4uoM38gXGwN5YbcrVJURgB HWfXO4pa/D6TfvILO5chKEN5Wd7jJVK1PZpF2d7vxrqoU1/gr3vsuf7ClHcZazfw r6mGCQKroDhi3iwPPAi1RT4NWIGlI2fsQzT5LpTD1tddwmK0qAyhoEJkBrrBnb2o 5xrAe0IJ+b7U5rAnMPo56u/XlQz2Up/qBk+NmF893q0s1qZnxeOOx4RTWHgRtnGQ 8vhHeE66a8M6l5BPGhy4C+ETnwyNmPL+fdiszKCl6FcCvhZJFnUx6KgLdIV8uxQy /j9WoMK88MnivhZZBmxWTbwSC8cav+VE+9sQrFSjIrUXJzI03s3++FHbc/M2RhBf eJmvUbLae+IhevQnuV0O/bAItub7i6xGdT2Li6Yy/Fp0FyqGVXlHzBJ38Acrt+vN GnHFoTVT44jCv2ZWosWSbVVuU2tay2Q5orznFbAknvhpKR/L2IhkZHkxwpdVedAc +b1jBmJNHr9eiBWRCqbYHEbhC5YXMYLKHxyvg9lx7667tKy4NiJZIHpDah1anFBO 0P1MmNO5EYHhtVIKVMFV2L2MLSJb25o5+3c3/O8hwY9EKPkrkeB6aWhCzVxDqjZp yaSCEJTHfpR+Ce34I8F3IPocIgWxUU6h8LuoJAzafl+tbLGxZz5nQaaQI7XFeWjn aGGVR1606+s= =+FQl -----END PGP SIGNATURE-----