
Microsoft released Patch Tuesday for April 2020 yesterday. These are the security updates it releases every month.
This month's Patch Tuesday is quite large, 113 vulnerabilities in 11 products Microsoft fixing. Among those vulnerabilities are three zero-day bugs that were already being exploited by cybercriminals .
As always, not many details have been released about zero-day vulnerabilities. Details about these bugsare typically kept hidden for days or weeks to give users time to fix them and prevent attackers from developing proof-of-concept code.
The three zero-day vulnerabilities, fixed in Microsoft's Patch Tuesday, are:
CVE-2020-1020: A vulnerability in the Windows Adobe Type Manager Library, which could allow an attacker to run code on vulnerable systems. Attacks can be carried out remotely. The vulnerability does not affect Windows 10.Information about this zero-day was published last month. However, it is now fixed, with the April patch.
CVE-2020-0938: This vulnerability is also found in the Windows Adobe Type Manager Library. It is similar to CVE-2020-1020, but its existence was only revealed yesterday. Last month, Microsoft had given some advice to users on how they could mitigate the risk of the first vulnerability. It seems that these measures were effective for this vulnerability as well (CVE-2020-0938).
CVE-2020-1027: Patch Tuesday also fixes this bug in the Windows kernel, which allows attackers to gain more privileges and execute code.

According to Microsoft, the three zero-day vulnerabilities were discovered and reported by two Google security teams : Project Zero and the Threat Analysis Group (TAG).
As we mentioned earlier, there aren't many details. Therefore, we don't know if the three vulnerabilities were used by the same hacker (or hacking group) or if they were used in the same hacking campaign.
Patch Tuesday fixes the above zero-days, as well as 110 more vulnerabilities, which you can see here.
