Microsoft July 2020 addressed 123 security vulnerabilities impacting 13 products, none of them has been observed being exploited in attacks in the wild.
The July 2020 security release consists of security updates for the following software:
The most severe issue is the 17-year-old wormable issue SigRed, tracked as CVE-2020-1350, that allows hijacking of Microsoft Windows Server
The issue received a severity rating of 10.0 on the CVSS scale and affects Windows Server versions 2003 to 2019.
The vulnerability could be exploited by an unauthenticated, remote attacker to gain domain administrator privileges over targeted servers and take full control of an organization’s IT infrastructure.
“Today we released an update for CVE-2020-1350, a Critical Remote Code Execution (RCE) vulnerability in Windows DNS Server that is classified as a ‘wormable’ vulnerability and has a CVSS base score of 10.0. This issue results from a flaw in Microsoft’s DNS server role implementation and affects all Windows Server versions. Non-Microsoft DNS Servers are not affected.” reads the advisory published by Microsoft.
“Wormable vulnerabilities have the potential to spread via malware between vulnerable computers without user interaction. Windows DNS Server is a core networking component. While this vulnerability is not currently known to be used in active attacks, it is essential that customers apply Windows updates to address this vulnerability as soon as possible.”
Microsoft July 2020 also addressed several important flaws, including some remote code vulnerabilities in:
The complete list of the issues addressed by Microsoft is available in the Microsoft’s official Security Update Guide portal.
[adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Microsoft July 2020)
[adrotate banner=”5″]
[adrotate banner=”13″]