-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
                         AUSCERT Security Bulletin

                               ASB-2020.0096
      Microsoft Patch Tuesday update for Microsoft Edge for May 2020
                                13 May 2020

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:              Microsoft Edge
Operating System:     Windows
Impact/Access:        Execute Arbitrary Code/Commands -- Remote with User Interaction
                      Increased Privileges            -- Remote with User Interaction
                      Provide Misleading Information  -- Remote with User Interaction
Resolution:           Patch/Upgrade
CVE Names:            CVE-2020-1096 CVE-2020-1065 CVE-2020-1059
                      CVE-2020-1056 CVE-2020-1037 
Member content until: Friday, June 12 2020
Reference:            ESB-2020.1202

OVERVIEW

        Microsoft has released its monthly security patch update for the month of May 2020.
        
        This update resolves 5 vulnerabilities across the following products: [1]
        
         Microsoft Edge (EdgeHTML-based)


IMPACT

        Microsoft has given the following details regarding these vulnerabilities.
        
         Details         Impact                   Severity
         CVE-2020-1037   Remote Code Execution    Critical
         CVE-2020-1056   Elevation of Privilege   Critical
         CVE-2020-1059   Spoofing                 Important
         CVE-2020-1065   Remote Code Execution    Critical
         CVE-2020-1096   Remote Code Execution    Important


MITIGATION

        Microsoft recommends updating the software with the version made available on the Microsoft Update Catalogue for the following Knowledge Base articles. [1]
        
         KB4556807, KB4556826, KB4556813, KB4556799, KB4551853
         KB4556812


REFERENCES

        [1] Security Update Guide
            https://portal.msrc.microsoft.com/en-us/security-guidance

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours 
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBXrssG2aOgq3Tt24GAQjz5hAA3T7gYs7Plss7C87Ae1GF2fGPSyluC2DK
xnZ+Odty9fKMxnZCcdlt6NtLR9vEg3dCoD3JweYuMkxlbu7XNM5ZvFi6CRet25i4
hOaPOWmMbsm2R4pzg8D6F735nKPOEprBnA37dMqVQ23NLMrV+CybjivTH8nB8S68
k7t+X8jpBZJzjDcfSst+V63FOX8zWolDucjhu8KLWWMk/tLSKpiTYyQ15JrjtXyi
nOcx5XqJFq1hUjiUQ065CL61nULOauIEzxd/HJWkY6202mi2YYa0XSnGf2MnAQ1k
09sBiB2/5FeEPzx/vkHDWlg/hDq0BQKx5lvERj8MAQCLgKj0bTXxxO9f+4Gnze5l
AiKeQlmjYITOD778nX00yPzUOLso1tV1UNq1hxkEDYKomvBPgECohnBZUgxPzr8z
ltM1UIc2ZtV/foy3ZwHoKNv6PqV/80O1tXyncwAW8K34sCqw5Hy5cyL/0DhV8zjN
QHPA03tySfhQb7iT7R6NXye0mMjebZUA9/4dzENrc4iRbpMVq6ICA3SBuqL5a5kr
vzzhzKVRHKgb7XRz7gWVdPOdlvC/E6uskXYm6DAp2jLONod1usczG4+eOZx9Iv6f
QXMTOKMOAOT2BljSby1rbbZVHhPhkoHUdnjei4fJhCKa2D0nz6/p0anSm1gG9l6i
TMV4rOKuDFs=
=vEvy
-----END PGP SIGNATURE-----