Microsoft Updates
3672Warning Date
Severity Level
Warning Number
Target Sector
15 April, 2020
● High
2020-1143
All
Description:
Microsoft has released security update to address several vulnerabilities in the following products:
- Microsoft Windows
- Microsoft Edge (EdgeHTML-based)
- Microsoft Edge (Chromium-based)
- ChakraCore
- Internet Explorer
- Microsoft Office and Microsoft Office Services and Web Apps
- Windows Defender
- Visual Studio
- Microsoft Dynamics
- Microsoft Apps for Android
- Microsoft Apps for Mac
- Microsoft Graphics Component
- Microsoft JET Database Engine
- Microsoft Office SharePoint
- Microsoft Scripting Engine
- Microsoft Windows DNS
- Open Source Software
- Remote Desktop Client
- Windows Defender
- Windows Hyper-V
- Windows Kernel
- Windows Media
- Windows Update Stack
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- Elevation of Privilege.
- Authentication Bypass
- Cross-site scripting (XSS)
- Unauthorized disclosure of information
- Execute arbitrary code - remotely.
- Spoofing
- Memory Corruption.
- Denial of Service (DoS).
Best practice and Recommendations:
The CERT team encourages users to review Microsoft security advisory and apply the necessary updates:
https://portal.msrc.microsoft.com/en-us/security-guidance
Update instructions: