Patch Tuesday Archive
Patch Tuesday May 2020
Total CVEs
113
Critical
13
Important
91
Exploited
0
Publicly Disclosed
0
All CVEs this month 113
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2020-0901 | Microsoft Excel Remote Code Execution Vulnerability | Important | 9.8 |
Microsoft Office | - | - | - |
| CVE-2020-0909 | Windows Hyper-V Denial of Service Vulnerability | Important | 7.5 |
Windows Hyper-V | - | - | - |
| CVE-2020-1021 | Windows Error Reporting Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1023 | Microsoft SharePoint Remote Code Execution Vulnerability | Critical | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1024 | Microsoft SharePoint Remote Code Execution Vulnerability | Critical | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1028 | Media Foundation Memory Corruption Vulnerability | Critical | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1192 | Visual Studio Code Python Extension Remote Code Execution Vulnerability | Critical | 7.8 |
Visual Studio | - | - | - |
| ADV200009 | Windows DNS Server Denial of Service Vulnerability | Unknown | - | Microsoft Windows DNS | - | - | - |
| CVE-2020-0963 | Windows GDI Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-1010 | Microsoft Windows Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1195 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Moderate | 5.9 |
Microsoft Edge on Chromium | - | - | - |
| CVE-2020-1035 | VBScript Remote Code Execution Vulnerability | Low | 7.5 |
Microsoft Scripting Engine | - | - | - |
| CVE-2020-1037 | Chakra Scripting Engine Memory Corruption Vulnerability | Critical | 7.5 |
Microsoft Scripting Engine | - | - | - |
| CVE-2020-1048 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1054 | Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-1055 | Microsoft Active Directory Federation Services Cross-Site Scripting Vulnerability | Important | 6.1 |
Active Directory | - | - | - |
| CVE-2020-1058 | VBScript Remote Code Execution Vulnerability | Low | 7.5 |
Microsoft Scripting Engine | - | - | - |
| CVE-2020-1059 | Microsoft Edge Spoofing Vulnerability | Important | 4.3 |
Microsoft Edge (HTML-based) | - | - | - |
| CVE-2020-1060 | VBScript Remote Code Execution Vulnerability | Low | 7.5 |
Microsoft Scripting Engine | - | - | - |
| CVE-2020-1061 | Microsoft Script Runtime Remote Code Execution Vulnerability | Important | 8.8 |
Windows Scripting | - | - | - |
| CVE-2020-1062 | Internet Explorer Memory Corruption Vulnerability | Moderate | 7.5 |
Internet Explorer | - | - | - |
| CVE-2020-1063 | Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2020-1064 | MSHTML Engine Remote Code Execution Vulnerability | Moderate | 7.5 |
Internet Explorer | - | - | - |
| CVE-2020-1065 | Scripting Engine Memory Corruption Vulnerability | Critical | 7.5 |
Microsoft Scripting Engine | - | - | - |
| CVE-2020-1066 | .NET Framework Elevation of Privilege Vulnerability | Important | 7.8 |
.NET Framework | - | - | - |
| CVE-2020-1071 | Windows Remote Access Common Dialog Elevation of Privilege Vulnerability | Important | 6.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1076 | Windows Denial of Service Vulnerability | Important | 5.5 |
Microsoft Windows | - | - | - |
| CVE-2020-1078 | Windows Installer Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1084 | Connected User Experiences and Telemetry Service Denial of Service Vulnerability | Important | 5.5 |
Microsoft Windows | - | - | - |
| CVE-2020-1093 | VBScript Remote Code Execution Vulnerability | Moderate | 7.5 |
Internet Explorer | - | - | - |
| CVE-2020-1096 | Microsoft Edge PDF Remote Code Execution Vulnerability | Important | 7.5 |
Microsoft Edge (HTML-based) | - | - | - |
| CVE-2020-1099 | Microsoft Office SharePoint XSS Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1101 | Microsoft Office SharePoint XSS Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1107 | Microsoft SharePoint Spoofing Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1110 | Windows Update Stack Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Update Stack | - | - | - |
| CVE-2020-1113 | Windows Task Scheduler Security Feature Bypass Vulnerability | Important | 7.5 |
Windows Task Scheduler | - | - | - |
| CVE-2020-1114 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2020-1116 | Windows CSRSS Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Windows | - | - | - |
| CVE-2020-1118 | Microsoft Windows Transport Layer Security Denial of Service Vulnerability | Important | 7.5 |
Microsoft Windows | - | - | - |
| CVE-2020-1124 | Windows State Repository Service Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1126 | Media Foundation Memory Corruption Vulnerability | Critical | 8.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1134 | Windows State Repository Service Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1135 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-1137 | Windows Push Notification Service Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1138 | Windows Storage Service Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1140 | DirectX Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-1143 | Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1144 | Windows State Repository Service Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1149 | Windows Runtime Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1150 | Media Foundation Memory Corruption Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1151 | Windows Runtime Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1154 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Common Log File System Driver | - | - | - |
| CVE-2020-1155 | Windows Runtime Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1156 | Windows Runtime Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1157 | Windows Runtime Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1158 | Windows Runtime Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1175 | Jet Database Engine Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft JET Database Engine | - | - | - |
| CVE-2020-1179 | Windows GDI Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-1186 | Windows State Repository Service Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1189 | Windows State Repository Service Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1190 | Windows State Repository Service Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1051 | Jet Database Engine Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft JET Database Engine | - | - | - |
| CVE-2020-1056 | Microsoft Edge Elevation of Privilege Vulnerability | Critical | 8.1 |
Microsoft Edge (HTML-based) | - | - | - |
| CVE-2020-1067 | Windows Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1068 | Microsoft Windows Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1069 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Critical | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1070 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1072 | Windows Kernel Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Windows | - | - | - |
| CVE-2020-1075 | Windows Subsystem for Linux Information Disclosure Vulnerability | Important | 5.5 |
Windows Subsystem for Linux | - | - | - |
| CVE-2020-1077 | Windows Runtime Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1079 | Microsoft Windows Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1081 | Windows Printer Service Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1082 | Windows Error Reporting Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1086 | Windows Runtime Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1087 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2020-1088 | Windows Error Reporting Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1090 | Windows Runtime Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1092 | Internet Explorer Memory Corruption Vulnerability | Low | 7.5 |
Internet Explorer | - | - | - |
| CVE-2020-1100 | Microsoft Office SharePoint XSS Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1102 | Microsoft SharePoint Remote Code Execution Vulnerability | Critical | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1103 | Microsoft SharePoint Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1104 | Microsoft SharePoint Spoofing Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1105 | Microsoft SharePoint Spoofing Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1106 | Microsoft Office SharePoint XSS Vulnerability | Important | 6.1 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1108 | .NET Core & .NET Framework Denial of Service Vulnerability | Important | 7.5 |
.NET Core | - | - | - |
| CVE-2020-1109 | Windows Update Stack Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Update Stack | - | - | - |
| CVE-2020-1111 | Windows Clipboard Service Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1112 | Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability | Important | 9.9 |
Microsoft Windows | - | - | - |
| CVE-2020-1117 | Microsoft Color Management Remote Code Execution Vulnerability | Critical | 8.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-1121 | Windows Clipboard Service Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1123 | Connected User Experiences and Telemetry Service Denial of Service Vulnerability | Important | 5.5 |
Microsoft Windows | - | - | - |
| CVE-2020-1125 | Windows Runtime Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1131 | Windows State Repository Service Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1132 | Windows Error Reporting Manager Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1136 | Media Foundation Memory Corruption Vulnerability | Critical | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1139 | Windows Runtime Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1141 | Windows GDI Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-1142 | Windows GDI Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-1145 | Windows GDI Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-1153 | Microsoft Graphics Components Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-1161 | ASP.NET Core Denial of Service Vulnerability | Important | 7.5 |
.NET Core | - | - | - |
| CVE-2020-1164 | Windows Runtime Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1165 | Windows Clipboard Service Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1166 | Windows Clipboard Service Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1171 | Visual Studio Code Python Extension Remote Code Execution Vulnerability | Important | 8.8 |
Python extension for Visual Studio Code | - | - | - |
| CVE-2020-1173 | Microsoft Power BI Report Server Spoofing Vulnerability | Important | 6.8 |
Power BI | - | - | - |
| CVE-2020-1174 | Jet Database Engine Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft JET Database Engine | - | - | - |
| CVE-2020-1176 | Jet Database Engine Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft JET Database Engine | - | - | - |
| CVE-2020-1184 | Windows State Repository Service Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1185 | Windows State Repository Service Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1187 | Windows State Repository Service Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1188 | Windows State Repository Service Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1191 | Windows State Repository Service Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
Threat Categories 7
| Threat Category | CVEs | Critical |
|---|---|---|
| Elevation of Privilege | 56 | 1 |
| Remote Code Execution | 29 | 12 |
| Spoofing | 11 | - |
| Information Disclosure | 8 | - |
| Denial of Service | 7 | - |
| Security Feature Bypass | 1 | - |
| Unknown | 1 | - |
Affected Products 24
| Product | CVEs | Exploited |
|---|---|---|
| Microsoft Windows | 55 | - |
| Microsoft Office SharePoint | 12 | - |
| Microsoft Graphics Component | 10 | - |
| Microsoft Scripting Engine | 5 | - |
| Internet Explorer | 4 | - |
| Microsoft JET Database Engine | 4 | - |
| Microsoft Edge (HTML-based) | 3 | - |
| .NET Core | 2 | - |
| Windows Kernel | 2 | - |
| Windows Update Stack | 2 | - |
| .NET Framework | 1 | - |
| Active Directory | 1 | - |
| Common Log File System Driver | 1 | - |
| Microsoft Dynamics | 1 | - |
| Microsoft Edge on Chromium | 1 | - |
| Microsoft Office | 1 | - |
| Microsoft Windows DNS | 1 | - |
| Power BI | 1 | - |
| Python extension for Visual Studio Code | 1 | - |
| Visual Studio | 1 | - |
| Windows Hyper-V | 1 | - |
| Windows Scripting | 1 | - |
| Windows Subsystem for Linux | 1 | - |
| Windows Task Scheduler | 1 | - |