{"id":342289,"date":"2020-03-12T09:19:21","date_gmt":"2020-03-12T07:19:21","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=342289"},"modified":"2020-03-12T09:20:58","modified_gmt":"2020-03-12T07:20:58","slug":"microsoft-patches-critical-vulnerabilities-update-now","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/342289-microsoft-patches-critical-vulnerabilities-update-now.html","title":{"rendered":"Microsoft patches critical vulnerabilities &#8211; Update now"},"content":{"rendered":"<p>Microsoft&#8217;s March 2020 <a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2020-Mar\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Patch Tuesday<\/strong><\/a> provides updates for 115 vulnerabilities &#8211; 26 of which have been flagged as &#8220;critical&#8221;.<\/p>\n<p>17 of these vulnerabilities are related to browsers and scripting engines &#8211; making these updates particularly important for those using Edge or Internet Explorer.<\/p>\n<p>All of the critical bugs are related to remote code execution (RCE) flaws. These include:<\/p>\n<ul>\n<li>A <a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0852\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>vulnerability<\/strong><\/a> in Microsoft Word that allowed attackers to craft a file that, if opened by the user, let the attacker run malicious code on the victim&#8217;s device.<\/li>\n<li>A <a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/CVE-2020-0872\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>vulnerability<\/strong><\/a> in Application Inspector where &#8220;a tool reflects example code snippets from third-party source files into its HTML output,&#8221; said Microsoft. &#8220;An attacker who exploited it could send sections of the report containing code snippets to an external server.&#8221;<\/li>\n<li>A <a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0905\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>vulnerability<\/strong><\/a> in Dynamics Business Central where attackers who compromise a host can execute shell commands on the target&#8217;s server.<\/li>\n<\/ul>\n<p>However, Microsoft did not patch a flaw in Microsoft SMB servers which is exploited with a specially-crafted data packet sent to an SMBv3 server.<\/p>\n<p>It <a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/adv200005\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>said<\/strong><\/a> that in the interim, those affected can disable compression as a workaround with the following PowerShell command:<\/p>\n<blockquote><p>Set-ItemProperty -Path &#8220;HKLM:\\SYSTEM\\CurrentControlSet\\Services\\LanmanServer\\Parameters&#8221; DisableCompression -Type DWORD -Value 1 -Force<\/p><\/blockquote>\n<p>All of the new patches are available via Windows Update in Windows 10, and there are no reports of issues with the implementation of these patches.<\/p>\n<h3 class=\"my-4\">Microsoft update issues<\/h3>\n<p>A lack of complaints regarding failed installations is good news &#8211; particularly following Microsoft&#8217;s <a href=\"https:\/\/mybroadband.co.za\/news\/security\/339180-botched-windows-10-update-uninstall-now.html\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>botched<\/strong><\/a> February update.<\/p>\n<p>The update resulted in many users being unable to reset their PCs, while some suffered installation failure errors.<\/p>\n<p>\u201cUsing the \u2018Reset this PC\u2019 feature, also called \u2018Push Button Reset\u2019 or PBR, might fail. You might restart into recovery with \u2018Choose an option\u2019 at the top of the screen with various options or you might restart to desktop and receive the error \u2018There was a problem resetting your PC,&#8217;\u201d said Microsoft.<\/p>\n<p>For these reasons, it removed the patch and recommended that users who were suffering issues with the patch uninstall it.<\/p>\n<p>\u201cThis standalone security update has been removed and will not be re-offered from Windows Update, Windows Server Update Services (WSUS) or Microsoft Update Catalog,\u201d <a href=\"https:\/\/support.microsoft.com\/en-za\/help\/4524244\/security-update-for-windows-10-february-11-2020\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>said<\/strong><\/a>\u00a0Microsoft.<\/p>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/software\/342283-microsoft-office-price-increase-postponed.html\" rel=\"bookmark\">Microsoft Office South African price increase postponed<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft&#8217;s Match 2020 patch Tuesday has provided updates for 115 vulnerabilities &#8211; 26 of which have been flagged as &#8220;critical.&#8221;<\/p>\n","protected":false},"author":341039,"featured_media":322910,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[123,12505,46045,26970],"class_list":["post-342289","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-microsoft","tag-microsoft-windows","tag-patch-tuesday","tag-windows-10"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/342289"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341039"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=342289"}],"version-history":[{"count":2,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/342289\/revisions"}],"predecessor-version":[{"id":342317,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/342289\/revisions\/342317"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/322910"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=342289"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=342289"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=342289"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}