CSIRT Panamá Aviso 2020-04-15 Actualizaciones de Microsoft corrigen 3 vulnerabilidades de tipo día cero y 15 fallas criticas.

CSIRT Panamá Aviso 2020-04-15 Actualizaciones de Microsoft corrigen 3 vulnerabilidades de tipo día cero y 15 fallas criticas.
Gravedad: Alta
Fecha de publicación: abril 15, 2020
Última revisión: abril 14, 2020
https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/2020-Apr

Sistemas Afectados:
Microsoft Windows
Microsoft Edge (EdgeHTML-based)
Microsoft Edge (Chromium-based)
ChakraCore
Internet Explorer
Microsoft Office and Microsoft Office Services and Web Apps
Windows Defender
Visual Studio
Microsoft Dynamics
Microsoft Apps for Android
Microsoft Apps for Mac

I. Descripción
Microsoft lanzó correcciones para 113 vulnerabilidades en los productos de Microsoft.
De estas vulnerabilidades, 15 se clasifican como críticas, 93 como importantes, 3 como moderadas y 2 como bajas.

II. Problemas Conocidos

TagCVE IDCVE TitleSeverity
Android AppCVE-2020-0943Microsoft YourPhone Application for Android Authentication Bypass VulnerabilityImportant
AppsCVE-2020-1019Microsoft RMS Sharing App for Mac Elevation of Privilege VulnerabilityImportant
Microsoft DynamicsCVE-2020-1050Microsoft Dynamics 365 (On-Premise) Cross Site Scripting VulnerabilityImportant
Microsoft DynamicsCVE-2020-1018Microsoft Dynamics Business Central/NAV Information DisclosureImportant
Microsoft DynamicsCVE-2020-1049Microsoft Dynamics 365 (On-Premise) Cross Site Scripting VulnerabilityImportant
Microsoft DynamicsCVE-2020-1022Dynamics Business Central Remote Code Execution VulnerabilityCritical
Microsoft Graphics ComponentCVE-2020-0952Windows GDI Information Disclosure VulnerabilityImportant
Microsoft Graphics ComponentCVE-2020-0938Adobe Font Manager Library Remote Code Execution VulnerabilityImportant
Microsoft Graphics ComponentCVE-2020-0687Microsoft Graphics Remote Code Execution VulnerabilityCritical
Microsoft Graphics ComponentCVE-2020-0987Microsoft Graphics Component Information Disclosure VulnerabilityImportant
Microsoft Graphics ComponentCVE-2020-1004Windows Graphics Component Elevation of Privilege VulnerabilityImportant
Microsoft Graphics ComponentCVE-2020-1005Microsoft Graphics Component Information Disclosure VulnerabilityImportant
Microsoft Graphics ComponentCVE-2020-0958Win32k Elevation of Privilege VulnerabilityImportant
Microsoft Graphics ComponentCVE-2020-0907Microsoft Graphics Components Remote Code Execution VulnerabilityCritical
Microsoft Graphics ComponentCVE-2020-0982Microsoft Graphics Component Information Disclosure VulnerabilityImportant
Microsoft Graphics ComponentCVE-2020-0964GDI+ Remote Code Execution VulnerabilityImportant
Microsoft Graphics ComponentCVE-2020-1020Adobe Font Manager Library Remote Code Execution VulnerabilityImportant
Microsoft Graphics ComponentCVE-2020-0784DirectX Elevation of Privilege VulnerabilityImportant
Microsoft JET Database EngineCVE-2020-0995Jet Database Engine Remote Code Execution VulnerabilityImportant
Microsoft JET Database EngineCVE-2020-0999Jet Database Engine Remote Code Execution VulnerabilityImportant
Microsoft JET Database EngineCVE-2020-0988Jet Database Engine Remote Code Execution VulnerabilityImportant
Microsoft JET Database EngineCVE-2020-0992Jet Database Engine Remote Code Execution VulnerabilityImportant
Microsoft JET Database EngineCVE-2020-0994Jet Database Engine Remote Code Execution VulnerabilityImportant
Microsoft JET Database EngineCVE-2020-0953Jet Database Engine Remote Code Execution VulnerabilityImportant
Microsoft JET Database EngineCVE-2020-0889Jet Database Engine Remote Code Execution VulnerabilityImportant
Microsoft JET Database EngineCVE-2020-0959Jet Database Engine Remote Code Execution VulnerabilityImportant
Microsoft JET Database EngineCVE-2020-0960Jet Database Engine Remote Code Execution VulnerabilityImportant
Microsoft JET Database EngineCVE-2020-1008Jet Database Engine Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2020-0979Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2020-0980Microsoft Word Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2020-0984Microsoft (MAU) Office Elevation of Privilege VulnerabilityImportant
Microsoft OfficeCVE-2020-0760Microsoft Office Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2020-0991Microsoft Office Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2020-0961Microsoft Office Access Connectivity Engine Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2020-0931Microsoft SharePoint Remote Code Execution VulnerabilityCritical
Microsoft OfficeCVE-2020-0906Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2020-0935OneDrive for Windows Elevation of Privilege VulnerabilityImportant
Microsoft Office SharePointCVE-2020-0927Microsoft Office SharePoint XSS VulnerabilityCritical
Microsoft Office SharePointCVE-2020-0923Microsoft Office SharePoint XSS VulnerabilityImportant
Microsoft Office SharePointCVE-2020-0925Microsoft Office SharePoint XSS VulnerabilityImportant
Microsoft Office SharePointCVE-2020-0924Microsoft Office SharePoint XSS VulnerabilityImportant
Microsoft Office SharePointCVE-2020-0932Microsoft SharePoint Remote Code Execution VulnerabilityCritical
Microsoft Office SharePointCVE-2020-0930Microsoft Office SharePoint XSS VulnerabilityImportant
Microsoft Office SharePointCVE-2020-0933Microsoft Office SharePoint XSS VulnerabilityImportant
Microsoft Office SharePointCVE-2020-0920Microsoft SharePoint Remote Code Execution VulnerabilityImportant
Microsoft Office SharePointCVE-2020-0929Microsoft SharePoint Remote Code Execution VulnerabilityCritical
Microsoft Office SharePointCVE-2020-0971Microsoft SharePoint Remote Code Execution VulnerabilityImportant
Microsoft Office SharePointCVE-2020-0975Microsoft SharePoint Spoofing VulnerabilityImportant
Microsoft Office SharePointCVE-2020-0978Microsoft Office SharePoint XSS VulnerabilityImportant
Microsoft Office SharePointCVE-2020-0977Microsoft SharePoint Spoofing VulnerabilityImportant
Microsoft Office SharePointCVE-2020-0976Microsoft SharePoint Spoofing VulnerabilityImportant
Microsoft Office SharePointCVE-2020-0974Microsoft SharePoint Remote Code Execution VulnerabilityCritical
Microsoft Office SharePointCVE-2020-0973Microsoft Office SharePoint XSS VulnerabilityImportant
Microsoft Office SharePointCVE-2020-0972Microsoft SharePoint Spoofing VulnerabilityImportant
Microsoft Office SharePointCVE-2020-0954Microsoft Office SharePoint XSS VulnerabilityModerate
Microsoft Office SharePointCVE-2020-0926Microsoft Office SharePoint XSS VulnerabilityImportant
Microsoft Scripting EngineCVE-2020-0968Scripting Engine Memory Corruption VulnerabilityModerate
Microsoft Scripting EngineCVE-2020-0966VBScript Remote Code Execution VulnerabilityLow
Microsoft Scripting EngineCVE-2020-0895Windows VBScript Engine Remote Code Execution VulnerabilityLow
Microsoft Scripting EngineCVE-2020-0969Chakra Scripting Engine Memory Corruption VulnerabilityCritical
Microsoft Scripting EngineCVE-2020-0970Scripting Engine Memory Corruption VulnerabilityCritical
Microsoft Scripting EngineCVE-2020-0967VBScript Remote Code Execution VulnerabilityModerate
Microsoft WindowsCVE-2020-0942Connected User Experiences and Telemetry Service Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2020-0965Microsoft Windows Codecs Library Remote Code Execution VulnerabilityCritical
Microsoft WindowsCVE-2020-0940Windows Push Notification Service Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2020-0934Windows Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2020-1029Connected User Experiences and Telemetry Service Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2020-1011Windows Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2020-1094Windows Work Folder Service Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2020-1016Windows Push Notification Service Information Disclosure VulnerabilityImportant
Microsoft WindowsCVE-2020-0794Windows Denial of Service VulnerabilityImportant
Microsoft WindowsCVE-2020-1017Windows Push Notification Service Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2020-0944Connected User Experiences and Telemetry Service Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2020-1006Windows Push Notification Service Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2020-1009Windows Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2020-0981Windows Token Security Feature Bypass VulnerabilityImportant
Microsoft WindowsCVE-2020-1001Windows Push Notification Service Elevation of Privilege VulnerabilityImportant
Microsoft Windows DNSCVE-2020-0993Windows DNS Denial of Service VulnerabilityImportant
Open Source SoftwareCVE-2020-1026MSR JavaScript Cryptography Library Security Feature Bypass VulnerabilityImportant
Remote Desktop ClientCVE-2020-0919Microsoft Remote Desktop App for Mac Elevation of Privilege VulnerabilityImportant
Visual StudioCVE-2020-0899Microsoft Visual Studio Elevation of Privilege VulnerabilityImportant
Visual StudioCVE-2020-0900Visual Studio Extension Installer Service Elevation of Privilege VulnerabilityImportant
Windows DefenderCVE-2020-1002Microsoft Defender Elevation of Privilege VulnerabilityImportant
Windows DefenderCVE-2020-0835Windows Defender Antimalware Platform Hard Link Elevation of Privilege VulnerabilityImportant
Windows Hyper-VCVE-2020-0918Windows Hyper-V Elevation of Privilege VulnerabilityImportant
Windows Hyper-VCVE-2020-0910Windows Hyper-V Remote Code Execution VulnerabilityCritical
Windows Hyper-VCVE-2020-0917Windows Hyper-V Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2020-0699Win32k Information Disclosure VulnerabilityImportant
Windows KernelCVE-2020-1027Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2020-1003Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2020-0955Windows Kernel Information Disclosure in CPU Memory AccessImportant
Windows KernelCVE-2020-1015Windows Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2020-1000Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2020-1007Windows Kernel Information Disclosure VulnerabilityImportant
Windows KernelCVE-2020-0957Win32k Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2020-0936Windows Scheduled Task Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2020-0956Win32k Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2020-0962Win32k Information Disclosure VulnerabilityImportant
Windows KernelCVE-2020-0821Windows Kernel Information Disclosure VulnerabilityImportant
Windows KernelCVE-2020-0913Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2020-0888DirectX Elevation of Privilege VulnerabilityImportant
Windows MediaCVE-2020-0948Media Foundation Memory Corruption VulnerabilityCritical
Windows MediaCVE-2020-0937Media Foundation Information Disclosure VulnerabilityImportant
Windows MediaCVE-2020-0949Media Foundation Memory Corruption VulnerabilityCritical
Windows MediaCVE-2020-0939Media Foundation Information Disclosure VulnerabilityImportant
Windows MediaCVE-2020-0950Media Foundation Memory Corruption VulnerabilityCritical
Windows MediaCVE-2020-0946Media Foundation Information Disclosure VulnerabilityImportant
Windows MediaCVE-2020-0947Media Foundation Information Disclosure VulnerabilityImportant
Windows MediaCVE-2020-0945Media Foundation Information Disclosure VulnerabilityImportant
Windows Update StackCVE-2020-0996Windows Update Stack Elevation of Privilege VulnerabilityImportant
Windows Update StackCVE-2020-1014Microsoft Windows Update Client Elevation of Privilege VulnerabilityImportant
Windows Update StackCVE-2020-0983Windows Elevation of Privilege VulnerabilityImportant
Windows Update StackCVE-2020-0985Windows Update Stack Elevation of Privilege VulnerabilityImportant

III. Referencia a soluciones, herramientas e información
Actualizar utilizando Microsoft Windows Update o herramientas de administracion de actualizaciones centralizadas.

IV. Información de contacto
CSIRT PANAMA
Computer Security Incident Response Team Autoridad Nacional para la Innovacion Gubernamental
E-Mail: info@cert.pa
Phone: +507 520-CERT (2378)
Web: https://cert.pa
Twitter: @CSIRTPanama
Facebook: http://www.facebook.com/CSIRTPanama
Key ID: 16F2B124