Microsoft Updates
4003Warning Date
Severity Level
Warning Number
Target Sector
15 July, 2020
● Critical
2020-1489
All
Description:
Microsoft has released security updates to address multiple vulnerabilities in the following products:
- Microsoft Windows
- Microsoft Edge (EdgeHTML-based)
- Microsoft Edge (Chromium-based) in IE Mode
- Microsoft ChakraCore
- Internet Explorer
- Microsoft SharePoint
- Microsoft Office and Microsoft Office Services and Web Apps
- Windows Defender
- Skype for Business
- Visual Studio
- Microsoft OneDrive
- Open Source Software
- Azure DevOps
- .NET Framework
- Microsoft Graphics Component
- Microsoft Scripting Engine
- Windows DNS Server
- Windows Hyper-V
- Windows Kernel
- Windows Shell
- Windows Subsystem for Linux
- Windows Update Stack
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- Elevation of Privilege.
- Information disclosure.
- Cross-site scripting (XSS) attack, which could allow the attacker to read content that the attacker is not authorized to read.
- Remote code execution.
- Denial of Service (DoS)
Best practice and Recommendations:
The CERT team encourages users to review Microsoft security advisory and apply the necessary updates:
Update instructions: