Security News > 2020 > April > Microsoft Patch Tuesday, April 2020 Edition

Microsoft today released updates to fix 113 security vulnerabilities in its various Windows operating systems and related software.
Many security news sites are reporting that Microsoft addressed a total of four zero-day flaws this month, but it appears the advisory for a critical Internet Explorer flaw has been revised to indicate Microsoft has not yet received reports of it being used in active attacks.
Researchers at security firm Recorded Future zeroed in on CVE-2020-0796, a critical vulnerability dubbed "SMBGhost" that was rumored to exist in last month's Patch Tuesday but for which an out-of-band patch wasn't released until March 12.
Recorded Future's Allan Liska notes that one reason these past few months have seen so many patches from Microsoft is the company recently hired "SandboxEscaper," a nickname used by the security researcher responsible for releasing more than a half-dozen zero-day flaws against Microsoft products last year.
Just a friendly reminder that while many of the vulnerabilities fixed in today's Microsoft patch batch affect Windows 7 operating systems - including all three of the zero-day flaws - this OS is no longer being supported with security updates.
News URL
https://krebsonsecurity.com/2020/04/microsoft-patch-tuesday-april-2020-edition/
Related news
- Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws (source)
- Patch Tuesday: Microsoft Fixes 57 Security Flaws – Including Active Zero-Days (source)
- April 2025 Patch Tuesday forecast: More AI security introduced by Microsoft (source)
- Microsoft April 2025 Patch Tuesday fixes exploited zero-day, 134 flaws (source)
- Patch Tuesday: Microsoft Fixes 134 Vulnerabilities, Including 1 Zero-Day (source)
- March 2025 Patch Tuesday forecast: A return to normalcy (source)
- Choose your own Patch Tuesday adventure: Start with six zero day fixes, or six critical flaws (source)
- Week in review: Probing activity on Palo Alto Networks GlobalProtect portals, Patch Tuesday forecast (source)
- April's Patch Tuesday leaves unlucky Windows Hello users unable to login (source)
- Microsoft pitches pay-to-patch reboot reduction subscription for Windows Server 2025 (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-03-12 | CVE-2020-0796 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft products A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'. | 10.0 |