Microsoft Logo Wikipedia

Microsoft held its February 2020 Patch Tuesday earlier this week and it was a full roll out. Indeed, the company addressed 99 security vulnerabilities this month, including 12 it deemed to be critical. Furthermore, there are also five previously disclosed bugs.

Perhaps the most noteworthy fix is a patch for a zero-day memory-corruption flaw that has already been exploited. Tracked as CVE-2020-0674 the vulnerability is denoted as critical and allows hackers to take over systems through remote code-execution attacks.

Microsoft says the exploit is a remote code execution that gives bad actors the ability to access a system with the same privileges as someone logged in. If that access is on an admin account, the access would be total.

“A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user,” Microsoft said in an advisory.

Sticking with browsers, February 2020 Patch Tuesday is something of a milestone. It is the first patch event since Microsoft launched Chromium Edge last month. The company says it has solved 41 vulnerabilities on the new browser. However, these were not bundled in the Patch Tuesday fixes.

Full Patch Log

Tag CVE ID CVE Title Severity
Adobe Flash Player ADV200003 February 2020 Adobe Flash Security Update Important
Internet Explorer CVE-2020-0674 Scripting Engine Memory Corruption Vulnerability Moderate
Internet Explorer CVE-2020-0673 Scripting Engine Memory Corruption Vulnerability Moderate
Microsoft Edge CVE-2020-0663 Microsoft Edge Elevation of Privilege Vulnerability Important
Microsoft Edge CVE-2020-0706 Microsoft Browser Information Disclosure Vulnerability Important
Microsoft Exchange Server CVE-2020-0692 Microsoft Exchange Server Elevation of Privilege Vulnerability Important
Microsoft Exchange Server CVE-2020-0688 Microsoft Exchange Memory Corruption Vulnerability Important
Microsoft Exchange Server CVE-2020-0696 Microsoft Outlook Security Feature Bypass Vulnerability Important
Microsoft Graphics Component CVE-2020-0744 Windows GDI Information Disclosure Vulnerability Important
Microsoft Graphics Component CVE-2020-0745 Windows Graphics Component Elevation of Privilege Vulnerability Important
Microsoft Graphics Component CVE-2020-0714 DirectX Information Disclosure Vulnerability Important
Microsoft Graphics Component CVE-2020-0715 Windows Graphics Component Elevation of Privilege Vulnerability Important
Microsoft Graphics Component CVE-2020-0746 Microsoft Graphics Components Information Disclosure Vulnerability Important
Microsoft Graphics Component CVE-2020-0709 DirectX Elevation of Privilege Vulnerability Important
Microsoft Graphics Component CVE-2020-0792 Windows Graphics Component Elevation of Privilege Vulnerability Important
Microsoft Malware Protection Engine CVE-2020-0733 Windows Malicious Software Removal Tool Elevation of Privilege Vulnerability Important
Microsoft Office CVE-2020-0697 Microsoft Office Tampering Vulnerability Important
Microsoft Office CVE-2020-0759 Microsoft Excel Remote Code Execution Vulnerability Important
Microsoft Office CVE-2020-0695 Microsoft Office Online Server Spoofing Vulnerability Important
Microsoft Office SharePoint CVE-2020-0694 Microsoft Office SharePoint XSS Vulnerability Important
Microsoft Office SharePoint CVE-2020-0693 Microsoft Office SharePoint XSS Vulnerability Important
Microsoft Scripting Engine CVE-2020-0713 Scripting Engine Memory Corruption Vulnerability Critical
Microsoft Scripting Engine CVE-2020-0711 Scripting Engine Memory Corruption Vulnerability Critical
Microsoft Scripting Engine CVE-2020-0710 Scripting Engine Memory Corruption Vulnerability Critical
Microsoft Scripting Engine CVE-2020-0712 Scripting Engine Memory Corruption Vulnerability Critical
Microsoft Scripting Engine CVE-2020-0767 Scripting Engine Memory Corruption Vulnerability Critical
Microsoft Windows CVE-2020-0741 Connected Devices Platform Service Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0742 Connected Devices Platform Service Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0740 Connected Devices Platform Service Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0658 Windows Common Log File System Driver Information Disclosure Vulnerability Important
Microsoft Windows CVE-2020-0737 Windows Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0659 Windows Data Sharing Service Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0739 Windows Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0757 Windows SSH Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0732 DirectX Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0753 Windows Error Reporting Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0755 Windows Key Isolation Service Information Disclosure Vulnerability Important
Microsoft Windows CVE-2020-0754 Windows Error Reporting Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0657 Windows Common Log File System Driver Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0667 Windows Search Indexer Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0743 Connected Devices Platform Service Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0666 Windows Search Indexer Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0748 Windows Key Isolation Service Information Disclosure Vulnerability Important
Microsoft Windows CVE-2020-0747 Windows Data Sharing Service Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0668 Windows Kernel Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0704 Windows Wireless Network Manager Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0685 Windows COM Server Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0676 Windows Key Isolation Service Information Disclosure Vulnerability Important
Microsoft Windows CVE-2020-0678 Windows Error Reporting Manager Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0703 Windows Backup Service Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0680 Windows Function Discovery Service Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0679 Windows Function Discovery Service Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0681 Remote Desktop Client Remote Code Execution Vulnerability Critical
Microsoft Windows CVE-2020-0677 Windows Key Isolation Service Information Disclosure Vulnerability Important
Microsoft Windows CVE-2020-0682 Windows Function Discovery Service Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0756 Windows Key Isolation Service Information Disclosure Vulnerability Important
Microsoft Windows CVE-2020-0670 Windows Kernel Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0675 Windows Key Isolation Service Information Disclosure Vulnerability Important
Microsoft Windows CVE-2020-0669 Windows Kernel Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0727 Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0671 Windows Kernel Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0672 Windows Kernel Elevation of Privilege Vulnerability Important
Microsoft Windows CVE-2020-0698 Windows Information Disclosure Vulnerability Important
Microsoft Windows CVE-2020-0701 Windows Client License Service Elevation of Privilege Vulnerability Important
Microsoft Windows Search Component CVE-2020-0735 Windows Search Indexer Elevation of Privilege Vulnerability Important
Remote Desktop Client CVE-2020-0734 Remote Desktop Client Remote Code Execution Vulnerability Critical
Secure Boot CVE-2020-0689 Microsoft Secure Boot Security Feature Bypass Vulnerability Important
SQL Server CVE-2020-0618 Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability Important
Windows Authentication Methods CVE-2020-0665 Active Directory Elevation of Privilege Vulnerability Important
Windows COM CVE-2020-0752 Windows Search Indexer Elevation of Privilege Vulnerability Important
Windows COM CVE-2020-0749 Connected Devices Platform Service Elevation of Privilege Vulnerability Important
Windows COM CVE-2020-0750 Connected Devices Platform Service Elevation of Privilege Vulnerability Important
Windows Hyper-V CVE-2020-0751 Windows Hyper-V Denial of Service Vulnerability Important
Windows Hyper-V CVE-2020-0662 Windows Remote Code Execution Vulnerability Critical
Windows Hyper-V CVE-2020-0661 Windows Hyper-V Denial of Service Vulnerability Important
Windows Installer CVE-2020-0686 Windows Installer Elevation of Privilege Vulnerability Important
Windows Installer CVE-2020-0683 Windows Installer Elevation of Privilege Vulnerability Important
Windows Installer CVE-2020-0728 Windows Modules Installer Service Information Disclosure Vulnerability Important
Windows Kernel CVE-2020-0722 Win32k Elevation of Privilege Vulnerability Important
Windows Kernel CVE-2020-0721 Win32k Elevation of Privilege Vulnerability Important
Windows Kernel CVE-2020-0719 Win32k Elevation of Privilege Vulnerability Important
Windows Kernel CVE-2020-0720 Win32k Elevation of Privilege Vulnerability Important
Windows Kernel CVE-2020-0723 Win32k Elevation of Privilege Vulnerability Important
Windows Kernel CVE-2020-0731 Win32k Elevation of Privilege Vulnerability Important
Windows Kernel CVE-2020-0726 Win32k Elevation of Privilege Vulnerability Important
Windows Kernel CVE-2020-0724 Win32k Elevation of Privilege Vulnerability Important
Windows Kernel CVE-2020-0725 Win32k Elevation of Privilege Vulnerability Important
Windows Kernel CVE-2020-0717 Win32k Information Disclosure Vulnerability Important
Windows Kernel CVE-2020-0736 Windows Kernel Information Disclosure Vulnerability Important
Windows Kernel CVE-2020-0716 Win32k Information Disclosure Vulnerability Important
Windows Kernel-Mode Drivers CVE-2020-0691 Win32k Elevation of Privilege Vulnerability Important
Windows Media CVE-2020-0738 Media Foundation Memory Corruption Vulnerability Critical
Windows NDIS CVE-2020-0705 Windows Network Driver Interface Specification (NDIS) Information Disclosure Vulnerability Important
Windows RDP CVE-2020-0660 Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability Important
Windows Shell CVE-2020-0702 Surface Hub Security Feature Bypass Vulnerability Important
Windows Shell CVE-2020-0655 Remote Desktop Services Remote Code Execution Vulnerability Important
Windows Shell CVE-2020-0730 Windows User Profile Service Elevation of Privilege Vulnerability Important
Windows Shell CVE-2020-0729 LNK Remote Code Execution Vulnerability Critical
Windows Shell CVE-2020-0707 Windows IME Elevation of Privilege Vulnerability Important
Windows Update Stack CVE-2020-0708 Windows Imaging Library Remote Code Execution Vulnerability Important