Vulnerability Watch

Forum Discussion

scaveza's avatar
scaveza
Product Team
6 years ago

Microsoft's first Patch Tuesday of 2020 includes...

Microsoft's first Patch Tuesday of 2020 includes patches for 49 CVE's

Microsoft rang in 2020 with 49 CVEs addressed in the January 2020 Patch Tuesday release. This update contains 12 remote code execution flaws and eight vulnerabilities that are rated as critical. This month’s updates include patches for Microsoft Windows, Microsoft Office, Internet Explorer, .NET Framework, NET Core, ASP.NET Core and Microsoft Dynamics.

Two of the RCE's patched this month are in the Windows Remote Desktop Gateway. CVE-2019-0609 and CVE-2019-0610 are both pre-authentication remote code execution vulnerabilities, which can be exploited when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. Microsoft notes these flaws have not yet been exploited in the wild, but rates these both as ‘Exploitation More Likely.’ Patches have been released for Server 2012, Server 2012 R2, Server 2016 and Server 2019.

Additionally, another RDP related flaw was patched this month, CVE-2020-0611. CVE-2020-0611 is a remote code execution vulnerability that exists in the Windows Remote Desktop Client. Exploitation of this flaw would allow an attacker to execute arbitrary code on the machine of the connected client. To successfully exploit this flaw, an attacker would have to convince a user to connect to a malicious server, making exploitation of this flaw less likely according to Microsoft.

Follow along as we discuss some of most important vulnerabilities patched in the January 2020 Patch Tuesday release on our blog.

No RepliesBe the first to reply