article thumbnail

Microsoft Patch Tuesday, August 2020 Edition

Krebs on Security

Yes, good people of the Windows world, it’s time once again to backup and patch up! The most concerning of these appears to be CVE-2020-1380 , which is a weaknesses in Internet Explorer that could result in system compromise just by browsing with IE to a hacked or malicious website.

Backups 363
article thumbnail

Microsoft Patch Tuesday, June 2020 Edition

Krebs on Security

Perhaps most troubling of these ( CVE-2020-1301 ) is a remote code execution bug in SMB capabilities built into Windows 7 and Windows Server 2008 systems — both operating systems that Microsoft stopped supporting with security updates in January 2020. So do yourself a favor and backup before installing any patches.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Microsoft Patch Tuesday, May 2020 Edition

Krebs on Security

” For example, Satnam Narang from Tenable notes that two remote code execution flaws in Microsoft Color Management ( CVE-2020-1117 ) and Windows Media Foundation ( CVE-2020-1126 ) could be exploited by tricking a user into opening a malicious email attachment or visiting a website that contains code designed to exploit the vulnerabilities.

Backups 343
article thumbnail

Microsoft Patch Tuesday, February 2020 Edition

Krebs on Security

That vulnerability, assigned as CVE-2020-0674 , has been patched with this month’s release. lnk) files ( CVE-2020-0729 ) that affects Windows 8 and 10 systems, as well as Windows Server 2008-2012. A reliable backup means you’re not losing your mind when the odd buggy patch causes problems booting the system.

Backups 67
article thumbnail

Microsoft Patch Tuesday, March 2020 Edition

Krebs on Security

If you (ab)use Windows, please take a moment to read this post, backup your system(s), and patch your PCs. CVE-2020-0852 is one just four remote execution flaws Microsoft patched this month in versions of Word. A reliable backup means you’re not losing your mind when the odd buggy patch causes problems booting the system.

Backups 321
article thumbnail

Microsoft Patch Tuesday, April 2020 Edition

Krebs on Security

Near the top of the heap is CVE-2020-1020 , a remotely exploitable bug in the Adobe Font Manager library that was first detailed in late March when Microsoft said it had seen the flaw being used in active attacks. A reliable backup means you’re not losing your mind when the odd buggy patch causes problems booting the system.

Backups 323
article thumbnail

Microsoft Patch Tuesday, Sept. 2020 Edition

Krebs on Security

Among the chief concerns for enterprises this month is CVE-2020-16875 , which involves a critical flaw in the email software Microsoft Exchange Server 2016 and 2019. “We have seen the previously patched Exchange bug CVE-2020-0688 used in the wild, and that requires authentication. . We’ll likely see this one in the wild soon.

Software 319