• About
  • Advertise
  • Careers
  • Contact
Friday, March 31, 2023
No Result
View All Result
NEWSLETTER
Cyber360 News
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us
No Result
View All Result
Cyber360 News
No Result
View All Result
Home Security

Microsoft Fixes 115 ‘Security Holes’ In Latest Patch Tuesday Update

by Cyber360 News
March 11, 2020
in Security
0
Microsoft Fixes 115 ‘Security Holes’ In Latest Patch Tuesday Update
0
SHARES
4
VIEWS
Share on FacebookShare on Twitter

You may forget about a Tuesday chore, but Microsoft never forgets to release an update on Tuesday. It’s a new month, so another Patch Tuesday update has arrived for Windows 10 and other products.

This time, Redmond has managed to fix 115 security loopholes that might have affected users otherwise.

Out of these, Microsoft has flagged 26 vulnerabilities as critical that could have allowed attackers to leverage remote code executions. Hence, it is important to install the new Microsoft update. March 2020 Patch Tuesday is possibly the biggest Patch Tuesday the company has ever released.

The update fixes a flaw (CVE-2020-0852) in Microsoft Word, where the software fails to handle objects in the memory. This allows the attacker to run arbitrary code without needing the user to open a malicious file. That’s because the MS Outlook preview pane (that loads documents automatically) can be used as an attack vector.

Application Inspector is a relatively new Windows component that got affected by an RCE vulnerability (CVE-2020-0872). Although exploitation is less likely, the vulnerability exists in the way “the tool reflects example code snippets from third-party source files into its HTML output.”

An attacker can convince the user to run the Application Inspector on a source code that includes a malicious third-party component. Apparently, the Application Inspector is a source code analyzer tool that, among other jobs, can help in the detection of malicious backdoors and increased attack surface in a given code.

Now, as always, you don’t need to do anything as Windows Update will automatically install the update on your machine, provided you haven’t paused it.

Microsoft SMBv3 wormable bug (unpatched)

A big highlight of March Patch Tuesday is a remote code execution vulnerability in Microsoft Server Message Block 3.1.1 (SMBv3) that kicks in when it handles certain requests.

Upon successful exploitation, it can be used to target an SMB Client or Server. According to ZDNet, it’s being warned that the vulnerability could bring about another havoc to the likes of EternalBlue.

Microsoft released a separate advisory detailing how an attacker will have to configure a malicious SMBv3 Server and convince the target client to connect to it. On the other hand, an SMB Server can be compromised by sending a specially crafted packet based on the exploit.

As of writing this, Microsoft hasn’t issued a patch for the critical SMBv3 RCE vulnerability. However, it confirmed that the vulnerability isn’t publicly disclosed or exploited yet.

LEARN MACHINE LEARNING SQUARE AD

Cyber360 News

Cyber360 News

Next Post
Office network at the European Network of Transmission System Operators for Electricity (ENTSO-E) breached

Office network at the European Network of Transmission System Operators for Electricity (ENTSO-E) breached

Recent Posts

Twitch’s Entire Critical Data Leaked, Includes Streamer Earnings, Source Code

Twitch’s Entire Critical Data Leaked, Includes Streamer Earnings, Source Code

October 6, 2021
Former U.S. Security Firm Helped The UAE Carry Out “Karma” iMessage Hack: MIT Tech Review

Former U.S. Security Firm Helped The UAE Carry Out “Karma” iMessage Hack: MIT Tech Review

October 1, 2021
Facing “This App Has Been Blocked For Your Protection” Issue? Here’s How You Can Fix It

Facing “This App Has Been Blocked For Your Protection” Issue? Here’s How You Can Fix It

October 1, 2021

Whats New in Kali Linux?

September 14, 2021

Kali Linux 2019.3 Release (CloudFlare, Kali-status, metapackages, Helper-Scripts & LXD)

September 14, 2021

Kali Linux 2021.3 Release (OpenSSL, Kali-Tools, Kali Live VM Support, Kali NetHunter Smartwatch)

September 14, 2021

Kali Linux 2018.4 Release

September 14, 2021

Kali Linux 1.0.5 and Software Defined Radio

September 14, 2021

Kali Tools Website Launched, 1.0.9 Release

September 14, 2021

Kali Linux Dojo at Black Hat Vegas 2016

September 14, 2021

Category

Site Links

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

About Us

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

© 2019 Cyber360 News - Powered by WebSensePro

No Result
View All Result
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us

© 2019 Cyber360 News - Powered by WebSensePro

Login to your account below

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In