{"id":17709,"date":"2020-02-11T16:17:02","date_gmt":"2020-02-12T00:17:02","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2020\/02\/11\/news-11444\/"},"modified":"2020-02-11T16:17:02","modified_gmt":"2020-02-12T00:17:02","slug":"news-11444","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2020\/02\/11\/news-11444\/","title":{"rendered":"Microsoft Patch Tuesday, February 2020 Edition"},"content":{"rendered":"<p><strong>Credit to Author: BrianKrebs| Date: Tue, 11 Feb 2020 23:13:57 +0000<\/strong><\/p>\n<p><strong>Microsoft<\/strong> today released updates to plug nearly 100 security holes in various versions of its <strong>Windows<\/strong> operating system and related software, including a zero-day vulnerability in <strong>Internet Explorer<\/strong>\u00a0(IE) that is actively being exploited. Also, <strong>Adobe<\/strong> has issued a bevy of security updates for its various products, including <strong>Flash Player<\/strong> and <strong>Adobe Reader\/Acrobat<\/strong>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-full wp-image-26837\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2014\/07\/brokenwindows.png\" alt=\"\" width=\"229\" height=\"240\" \/>A dozen of the vulnerabilities Microsoft patched today are rated &#8220;critical,&#8221; meaning malware or miscreants could exploit them remotely to gain complete control over an affected system with little to no help from the user.<\/p>\n<p>Last month, Microsoft released an advisory warning that attackers were exploiting a previously unknown flaw in IE. That vulnerability, assigned as <a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0674\" target=\"_blank\" rel=\"noopener\">CVE-2020-0674<\/a>, has been patched with this month&#8217;s release. It could be used to install malware just by getting a user to browse to a malicious or hacked Web site.<\/p>\n<p>Microsoft once again fixed a critical flaw in the way Windows handles shortcut (.lnk) files (<a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0729\" target=\"_blank\" rel=\"noopener\">CVE-2020-0729<\/a>) that affects <strong>Windows 8<\/strong> and <strong>10<\/strong> systems, as well as <strong>Windows Server 2008-2012<\/strong>. <strong>Allan Liska<\/strong>, intelligence analyst at <strong>Recorded Future<\/strong>, says Microsoft considers exploitation of the vulnerability unlikely, but that a similar vulnerability discovered last year, <a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-1280\" target=\"_blank\" rel=\"noopener\">CVE-2019-1280<\/a>, was being actively exploited by the <a href=\"https:\/\/www.cyber.nj.gov\/threat-profiles\/trojan-variants\/astaroth\" target=\"_blank\" rel=\"noopener\">Astaroth trojan<\/a> as recently as September.<\/p>\n<p>Another flaw fixed this month in <strong>Microsoft Exchange 2010<\/strong> through <strong>2019<\/strong> may merit special attention. The bug could allow attackers to exploit the Exchange Server and execute arbitrary code just by sending a specially crafted email. This vulnerability\u00a0(<a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0688\" target=\"_blank\" rel=\"noopener\">CVE-2020-0688<\/a>) is rated &#8220;important&#8221; rather than &#8220;critical,&#8221; but Liska says it seems potentially dangerous, as Microsoft identifies this as a vulnerability that is likely to be exploited.<\/p>\n<p>In addition, Redmond addressed a critical issue (<a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0618\" target=\"_blank\" rel=\"noopener\">CVE-2020-0618<\/a>) in the way <strong>Microsoft SQL Server<\/strong> versions 2012-2016 handle page requests.<\/p>\n<p>After a several-month respite from patches for its Flash Player browser plug-in, Adobe has once again blessed us with a security update for this program (fixes <a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb20-06.html\" target=\"_blank\" rel=\"noopener\">one critical flaw<\/a>). Thankfully, <strong>Chrome<\/strong> and <strong>Firefox<\/strong> both now disable Flash by default, and Chrome and <strong>IE\/Edg<\/strong>e auto-update the program when new security updates are available. Adobe is slated to retire Flash Player later this year.<span id=\"more-50414\"><\/span><\/p>\n<p>Other Adobe products for which the company shipped updates today include <strong>Experience Manager<\/strong>, <strong>Digital Editions<\/strong>, <strong>Framemaker<\/strong> and <strong>Acrobat\/Reader <\/strong>(<a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb20-05.html\" target=\"_blank\" rel=\"noopener\">17 flaws<\/a>). Security experts at <strong>Qualys<\/strong> note that on January 28th, Adobe also issued <a href=\"https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb20-02.html\" target=\"_blank\" rel=\"noopener\">an out-of-band patch<\/a> for <strong>Magento<\/strong>, labeled as Priority 2.<\/p>\n<p>&#8220;While none of the vulnerabilities disclosed in Adobe\u2019s release are known to be Actively Attacked today, all patches should be prioritized on systems with these products installed,&#8221; said Qualys&#8217;s <strong>Jimmy Graham<\/strong>.<\/p>\n<p>Windows 7 users should be aware by now that while a fair number of flaws addressed this month by Microsoft affect Windows 7 systems, this operating system is no longer being supported with security updates (unless you&#8217;re an enterprise taking advantage of Microsoft&#8217;s <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4527878\/faq-about-extended-security-updates-for-windows-7\" target=\"_blank\" rel=\"noopener\">paid extended security updates program<\/a>, which is available to Windows 7 Professional and Windows 7 enterprise users).<\/p>\n<p>If you rely on Windows 7 for day-to-day use, it\u2019s probably time to think about upgrading to something newer. That might be a computer with Windows 10. Or maybe you have always wanted that shiny MacOS computer.<\/p>\n<p>If cost is a primary motivator and the user you have in mind doesn\u2019t do much with the system other than browsing the Web, perhaps a\u00a0<strong>Chromebook<\/strong>\u00a0or an older machine with a recent version of\u00a0<strong>Linux<\/strong>\u00a0is the answer (Ubuntu may be easiest for non-Linux natives). Whichever system you choose, it\u2019s important to pick one that fits the owner\u2019s needs and provides security updates on an ongoing basis.<\/p>\n<p>Keep in mind that while staying up-to-date on Windows patches is a must, it\u2019s important to make sure you\u2019re updating only after you\u2019ve backed up your important data and files. A reliable backup means you\u2019re not losing your mind when the odd buggy patch causes problems booting the system.<\/p>\n<p>So do yourself a favor and backup your files before installing any patches. Windows 10 even has\u00a0<a href=\"https:\/\/lifehacker.com\/how-to-back-up-your-computer-automatically-with-windows-1762867473\" target=\"_blank\" rel=\"noopener\">some built-in tools<\/a>\u00a0to help you do that, either on a per-file\/folder basis or by making a complete and bootable copy of your hard drive all at once.<\/p>\n<p>As always, if you experience glitches or problems installing any of these patches this month, please consider leaving a comment about it below; there\u2019s a better-than-even chance other readers have experienced the same and may chime in here with some helpful tips. Also, keep an eye on the <a href=\"https:\/\/www.askwoody.com\/2020\/february-2020-patch-tuesday-foibles\/\" target=\"_blank\" rel=\"noopener\">AskWoody blog<\/a> from <strong>Woody Leonhard<\/strong>, who keeps a close eye on buggy Microsoft updates each month.<\/p>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2020\/02\/microsoft-patch-tuesday-february-2020-edition\/\" target=\"bwo\" >https:\/\/krebsonsecurity.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2014\/07\/brokenwindows.png\"\/><\/p>\n<p><strong>Credit to Author: BrianKrebs| Date: Tue, 11 Feb 2020 23:13:57 +0000<\/strong><\/p>\n<p>Microsoft today released updates to plug nearly 100 security holes in various versions of its Windows operating system and related software, including a zero-day vulnerability in Internet Explorer\u00a0(IE) that is actively being exploited. Also, Adobe has issued a bevy of security updates for its various products, including Flash Player and Adobe Reader\/Acrobat.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,10642],"tags":[24210,24211,24212,24213,24214,13455,24215,13457,11753,16936],"class_list":["post-17709","post","type-post","status-publish","format-standard","hentry","category-independent","category-krebs","tag-alan-liska","tag-cve-2019-1280","tag-cve-2020-0618","tag-cve-2020-0674","tag-cve-2020-0688","tag-jimmy-graham","tag-microsoft-patch-tuesday-february-2020","tag-qualys","tag-recorded-future","tag-time-to-patch"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17709","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=17709"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17709\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=17709"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=17709"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=17709"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}