HomeSecurityMicrosoft March 2020 Patch Tuesday fixes 115 vulnerabilities!

Microsoft March 2020 Patch Tuesday fixes 115 vulnerabilities!

Microsoft March 2020 Patch Tuesday - security updates for vulnerabilitiesAs part of Microsoft's March 2020 Patch Tuesday, which will feature security updates, Microsoft has released patches for 115 vulnerabilities found in its products. Of these vulnerabilities, 24 are rated critical, 88 are rated important, and 3 are rated moderate. Users should install the security updates recommended by Microsoft March 2020 Patch Tuesday as soon as possible to protect Windows from security risks.

Those interested in further information about non-security Windows updates can read Windows 10 updates KB4540673 and KB4538461.

There is, however, a strange case involving a bug identified as CVE-2020-0796. Specifically, BleepingComputer reported that Microsoft was planning to release fixes for a “wormable” SMBv3 RCE vulnerability, identified as CVE-2020-0796, but Microsoft never did.Microsoft March 2020 Patch Tuesday - security updates for vulnerabilities

There is not much information about this case, but the only thing that is certain is that it was a very serious vulnerability that resembled another type of vulnerability, EternalBlue . While Microsoft never published any information about it, security company websites , such as Fortinet and Cisco Talos, published information about this vulnerability. Cisco Talos has since removed it. According to Cisco Talos , this vulnerability leaves systems exposed to a possible worm attack . Furthermore, if hackers exploit this vulnerability, they will be able to easily target their victims, one after the other.

BleepingComputer has sent multiple emails to Microsoft about this issue, but has not received a response. Among the vulnerabilities that were reported this month that are of particular interest is a vulnerability identified as CVE-2020-0872, titled “ Remote Code Execution in Application Inspector , ” which can be exploited by a hacker to steal the source code of files opened in Application Inspector.

Finally, two new vulnerabilities have been fixed that could allow hackers to create specially crafted .LNK files or Word that can execute code when opened. The first vulnerability is identified as CVE-2020-0684 and is called “LNK Remote Code Execution Vulnerability”. This vulnerability allows a hacker to create malicious LNK files that can execute code. The second vulnerability is identified as CVE-2020-0852 and is called “Microsoft Word Remote Code Execution Vulnerability”. This vulnerability allows a hacker to create malicious Word documents that can execute code simply by opening them. What’s worse is that the vulnerability in question works in the Outlook.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS