Skip to main content

Patch Now! Two Out of Band Patches Fix RCE in Windows


Nic-Automox

Both are remote code execution vulnerabilities, one rated Critical.

10 replies

Nic-Automox
  • Author
  • Former Automox Employee
  • 832 replies
  • July 1, 2020

More info from Zdnet:


  • Novice
  • 38 replies
  • July 1, 2020

Hello - Will Automox be releasing a patch for this issue? ZDNet and the MS CVE both state customers don’t have to do anything. It will updated through MS Store.

FAQ

How do I get the updated Windows Media Codec?

Affected customers will be automatically updated by Microsoft Store. Customers do not need to take any action to receive the update.

Alternatively, customers who want to receive the update immediately can check for updates with the Microsoft Store App; more information on this process can be found here.


Nic-Automox
  • Author
  • Former Automox Employee
  • 832 replies
  • July 1, 2020

The new patches should show up automatically in Automox. If you don’t see them in your environment, please let us know! Btw, you can search by CVE on the Software page, as an easy way to verify.


Westyy
Forum|alt.badge.img
  • Pro
  • 25 replies
  • July 2, 2020

Just checking for the CVE myself but cannot seem to locate it in either Software or with the CVE ID filter via Devices. Any suggestions? I can PM you or contact support if you’d prefer? 🙂

Cheers!


Nic-Automox
  • Author
  • Former Automox Employee
  • 832 replies
  • July 2, 2020

I’m not seeing them either when I search. I’ll check in with the engineers and see if we can track down what’s going on.


Nic-Automox
  • Author
  • Former Automox Employee
  • 832 replies
  • July 2, 2020

Ok here’s what we found. While the two CVEs are coming in through the feed we use, there’s no patch payload attached. That’s why we initially thought the patches were live, but it looks like Microsoft hasn’t released them yet:
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-1457

If you look in the security section at the bottom of the page you’ll see all the download columns are blank.

Once the patches actually show up I’ll post back in here to let you know. Sorry about that!


Nic-Automox
  • Author
  • Former Automox Employee
  • 832 replies
  • July 2, 2020

Ok it looks like this one might have just been pushed out through the Microsoft Store rather than through Windows Update:

Which would explain why we’re not seeing it through the Windows Update feeds.


Forum|alt.badge.img
  • Power User
  • 58 replies
  • July 2, 2020

What about for people who block the windows store from their env? Any ideas how to grab this patch?


Nic-Automox
  • Author
  • Former Automox Employee
  • 832 replies
  • July 2, 2020

That is a very good question that I don’t know the answer to. Hopefully they’ll push it out via WU as well at some point. The vulnerability only affects devices that have the optional HEVC codec installed, so if you don’t have that on your systems then you don’t need the patches.

I believe that codec is only available through the MS Store, so they’re assuming that if you’ve downloaded it, you still have access to Store updates.


Westyy
Forum|alt.badge.img
  • Pro
  • 25 replies
  • July 3, 2020

Thanks for chasing up Nic; appreciate it. 👌


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings