{"id":19649,"date":"2020-07-04T07:33:02","date_gmt":"2020-07-04T11:33:02","guid":{"rendered":"https:\/\/www.thundercloud.net\/infoave\/new\/?p=19649"},"modified":"2020-07-04T07:41:40","modified_gmt":"2020-07-04T11:41:40","slug":"microsoft-issues-two-emergency-security-updates","status":"publish","type":"post","link":"https:\/\/www.thundercloud.net\/infoave\/new\/microsoft-issues-two-emergency-security-updates\/","title":{"rendered":"Microsoft Issues Two Emergency Security Updates"},"content":{"rendered":"<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 24pt;\"><strong>Microsoft Issues Two Emergency Security Updates<\/strong><\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-19653 alignnone\" src=\"https:\/\/www.thundercloud.net\/infoave\/new\/wp-content\/uploads\/2020\/07\/ms.png\" alt=\"Microsoft Corporation\" width=\"488\" height=\"366\" srcset=\"https:\/\/www.thundercloud.net\/infoave\/new\/wp-content\/uploads\/2020\/07\/ms.png 488w, https:\/\/www.thundercloud.net\/infoave\/new\/wp-content\/uploads\/2020\/07\/ms-300x225.png 300w\" sizes=\"(max-width: 488px) 100vw, 488px\" \/><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">On Tuesday, June 30, 2020, Microsoft released two &#8220;out-of-band&#8221; emergency security updates for Windows 10 users. These emergency security updates patched two vulnerabilities that could allow attackers to run remote code execution against victims. Out-of-band patches are patches that are released outside of the normal cumulative updates and security updates normally issued on the second Tuesday of each month (Patch Tuesday).\u00a0<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">The following is from cyberscoop&#8230;<\/span><\/p>\n<blockquote><p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">One of the flaws, catalogued as CVE-2020-1425, would allow attackers to gather information from victims about further compromising their targets. If attackers were to exploit another flaw, catalogued as CVE-2020-1457, they would be capable of executing arbitrary code, Microsoft said. To exploit the vulnerabilities, which affect Windows 10 and Windows Server distributions, they would have to use a \u201cspecially crafted image file,\u201d Microsoft said.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">The flaws were rated as \u201ccritical\u201d and \u201cimportant,\u201d respectively.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Microsoft has addressed the vulnerabilities by correcting how objects in memory are handled by Microsoft Windows Codecs Library. Customers don\u2019t have to take any action to receive the updates, Microsoft said.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Microsoft typically issues patches for vulnerabilities on the second Tuesday of each month. And although Microsoft said it hasn\u2019t seen any threat actors exploiting the vulnerabilities in the wild, the fact that the company issued an out-of-band update indicates it found them critical enough to raise alarm outside of its normally scheduled updates.<\/span><\/p><\/blockquote>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\"><a href=\"https:\/\/www.cyberscoop.com\/microsoft-security-updates-july-2020\/\" target=\"_blank\" rel=\"noopener noreferrer\">Read the rest of this cyberscoop article here<\/a>.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; &nbsp; Microsoft Issues Two Emergency Security Updates On Tuesday, June 30, 2020, Microsoft released two &#8220;out-of-band&#8221; emergency security updates for Windows 10 users. These emergency security updates patched two vulnerabilities that could allow attackers to run remote code execution against victims. Out-of-band patches are patches that are released outside of the normal cumulative updates and security updates\u2026 <span class=\"read-more\"><a href=\"https:\/\/www.thundercloud.net\/infoave\/new\/microsoft-issues-two-emergency-security-updates\/\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":14573,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3948,2366],"tags":[3978],"_links":{"self":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/19649"}],"collection":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/comments?post=19649"}],"version-history":[{"count":4,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/19649\/revisions"}],"predecessor-version":[{"id":19654,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/19649\/revisions\/19654"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/media\/14573"}],"wp:attachment":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/media?parent=19649"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/categories?post=19649"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/tags?post=19649"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}