Welcome to the new year, and welcome to the first Patch Tuesday of 2020. Take a break from your regularly scheduled activities and join us as we review the details for security patches for this month.
Adobe Patches for January 2020
Adobe begins the year with only two patches addressing a total of nine CVEs. The update for fixes three Important and one Moderate-rated information disclosure bugs. None of these vulnerabilities are listed as publicly known or under active attack at the time of release.
Citrix Patches for January 2020
We don’t normally discuss Citrix patches on this blog, but a recent bug ( and look to apply patches as soon as they become available.
Microsoft Patches for January 2020
Before we get into this month’s patches, I briefly wanted to remind everyone that support for Windows 7 . It does not appear that bug is addressed by any of these patches.
Let’s take a closer look at some of the more interesting updates for this month, starting with a crypto-related bug that has the rumor mill swirling:
- – Windows RDP Gateway Server Remote Code Execution Vulnerability
I could just as easily listed – Remote Desktop Client Remote Code Execution Vulnerability
While not quite as severe as the previously mentioned RDP bugs, this client-side vulnerability deserves some attention. An attacker could take over an affected system if they can convince a user to connect to a malicious RDP server. Because of that requirement, this may not seem as critical. However, combine this client-side bug with two server-side bugs released in this same month, and an entire exploit chain becomes clear.
Here’s the full list of CVEs released by Microsoft for January 2020:
| CVE | Title | Severity | Public | Exploited | XI - Latest | XI - Older | Type |
| .NET Framework Remote Code Execution Vulnerability | Critical | No | No | 2 | 2 | RCE | |
| Windows RDP Gateway Server Remote Code Execution Vulnerability | Critical | No | No | N/A | 1 | RCE | |
| Remote Desktop Client Remote Code Execution Vulnerability | Critical | No | No | 2 | 2 | RCE | |
| .NET Framework Remote Code Execution Injection Vulnerability | Critical | No | No | 2 | 2 | RCE | |
| ASP.NET Core Denial of Service Vulnerability | Important | No | No | 2 | 2 | DoS | |
| Win32k Information Disclosure Vulnerability | Important | No | No | 2 | 2 | Info | |
| Windows Search Indexer Elevation of Privilege Vulnerability | Important | No | No | 2 | 2 | EoP | |
| Windows Common Log File System Driver Information Disclosure Vulnerability | Important | No | No | 2 | 2 | Info | |
| Hyper-V Denial of Service Vulnerability | Important | No | No | N/A | 2 | DoS | |
| Windows Security Feature Bypass Vulnerability | Important | No | No | N/A | 2 | SFB | |
| Windows Search Indexer Elevation of Privilege Vulnerability | Important | No | No | 2 | 2 | EoP | |
| Windows Search Indexer Elevation of Privilege Vulnerability | Important | No | No | 2 | 2 | EoP | |
| Windows Search Indexer Elevation of Privilege Vulnerability | Important | No | No | 2 | 2 | EoP | |
| Windows Search Indexer Elevation of Privilege Vulnerability | Important | No | No | 2 | 2 | EoP | |
| Windows Search Indexer Elevation of Privilege Vulnerability | Important | No | No | 2 | 2 | EoP | |
| Windows Search Indexer Elevation of Privilege Vulnerability | Important | No | No | 2 | 2 | EoP | |
| Windows Elevation of Privilege Vulnerability | Important | No | No | 2 | 2 | EoP | |
| Remote Desktop Web Access Information Disclosure Vulnerability | Important | No | No | N/A | 2 | Info | |
| Windows Common Log File System Driver Information Disclosure Vulnerability | Important | No | No | 2 | 2 | Info | |
| Win32k Elevation of Privilege Vulnerability | Important | No | No | 2 | 2 | EoP | |
| Windows Elevation of Privilege Vulnerability | Important | No | No | 2 | 2 | EoP | |
| Microsoft Excel Remote Code Execution Vulnerability | Important | No | No | 2 | 2 | RCE | |
| Microsoft Office Memory Corruption Vulnerability | Important | No | No | 2 | 2 | RCE | |
| Microsoft OneDrive for Android Security Feature Bypass Vulnerability | Important | No | No | 2 | 2 | SFB | |
| CVE-2020-0656 | Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability | Important | No | No | 2 | 2 | XSS |
Of the remaining Critical-rated patches, one is for IE, but again, this is not listed as publicly known or under active attack. There are also three Critical patches for .NET Framework and one for ASP.NET. Most of these require a user open a specially crafted file on an affected system. However, in CVE-2020-0646, an attacker could pass specific input to an application utilizing susceptible .NET methods to gain code execution. The code execution would occur at the level of the logged-on user, which brings us to another time to remind you not to log on with admin privileges to do your day-to-day work.
Looking at the Important-rated updates, the 12 updates for the Windows Search Indexer immediately stand out. The write-ups for these dozen bugs are all identical, and they were all reported by the same researcher. All list improper handling of objects in memory as a cause. In each case, a local user could run a specially crafted application to escalate privileges. In all, 21 January patches relate to a local privilege escalation in some form. Affected components include the Windows Subsystem for Linux, the Update Notification Manager, the Windows Kernel, and Microsoft Cryptographic Services.
There are two security feature bypass bugs this month, and both deserve mention. The first involves password creation, and it sounds like some creativity would be needed to exploit it as well. An attacker could create a password filter when creating a new password, which would result in a password that should have been blocked. I would love to hear the story of how the researchers discovered this scenario. The other bypass is for the OneDrive for Android app could allow an attacker to bypass the passcode or fingerprint requirements of the application. For this bug, you’ll need to download the update through the Google Play store.
There are a few RCE bugs fixed in Excel and Office. None of these bugs involve the Preview Pane and all require user interaction. There are also a handful of information disclosure bugs addressed in various Windows components. There are four Denial-of-Service (DoS) bugs fixed this month. A problem with hard links could make an affected Windows server unresponsive. RDP Gateway Servers also get a patch to fix a vulnerability that would allow a remote attacker to shut down an RDP Gateway Server. There’s also patches to address DoS bugs in Hyper-V and ASP.NET Core.
Wrapping up this release, there’s a spoofing bug in Office that could allow for cross-origin attacks on affected systems. The final patch from Microsoft for January fixes a cross-site scripting (XSS) bug in Microsoft Dynamics 365 (On-Premise).
No security advisories were released this month.
Looking Ahead
The next Patch Tuesday falls on February 11, and we’ll return with details and patch analysis then. Until then, happy patching and may all your reboots be smooth and clean!
SOCIAL SHARE CARD GENERATOR