Microsoft Patch Tuesday Fixes 123 Flaws Including Critical Wormable DNS Bug
Microsoft releases fixes for 123 vulnerabilities during its July 2020 Patch Tuesday, including 18 critical flaws and a highly dangerous wormable DNS Server bug. Administrators strongly advise installing these updates immediately to secure Windows systems.
Microsoft releases its July 2020 Patch Tuesday updates to address a massive total of 123 vulnerabilities across its product line. This collection of security fixes includes 18 critical ratings and 105 important ratings, making it the second-largest Patch Tuesday release in the company's history. Alongside these fixes, Microsoft publishes a separate advisory to address a tampering vulnerability in Internet Information Services (IIS).
The most significant fix in this update targets a critical 10.0 rated wormable vulnerability in Windows DNS Server known as SigRed. Discovered by Check Point researchers and tracked as CVE-2020-1350, this flaw allows attackers to execute remote code and potentially create self-spreading malware across a network. Microsoft provides specific mitigations for this severe threat while users work to deploy the official patch.
Additional critical vulnerabilities addressed in this release include remote code execution flaws in Microsoft Edge, the VBScript engine, and the Windows Font Library. Attackers exploit these remaining critical issues by tricking users into visiting maliciously crafted websites or downloading specially crafted files through phishing campaigns. Because these exploits execute code with the same privileges as the current user, administrators strongly recommend installing all available security updates as soon as possible.