As I’m sure you’ve heard, there were a handful of critical vulnerabilities announced in this week’s Patch Tuesday. Included in the list of vulnerabilities is a flaw within CryptoAPI that would allow an attacker to digitally sign malicious software updates as the legitimate creator of the software. While Microsoft lists this vulnerability with a severity level of Critical, an attacker would need to first insert themselves as a Man in The Middle to be able to intercept a device’s software update request and return back a digitally signed malicious executable.
Table of Contents
– Affected Operating Systems
– KB’s Needed to Patch Vulnerability
If you have the time, I’d highly recommend the below Webcast on this topic from the SANS Institute’s YouTube page. It goes above any beyond any level of detail I would be able to.
Affected Operating Systems
- Windows 10
- Windows Server 2016
- Windows Server 2019
Note: Windows 7 and older are NOT vulnerable. The Windows Update Service itself is NOT vulnerable.
Patching CVE-2020-0601
Microsoft’s official documentation on this topic can be found at the below link. https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601
The exact patch that you need depends on the exact OS Build of Windows 10 you’re running. Below is a list of the related KBs and which Operating System they patch. This list is current as of this blog’s posted date.
I recommend searching for your Build of Windows 10 by using Ctrl+F and typing the version (I.E 1909, 1903, etc.)
Article | KB4528760 |
Download Link | https://www.catalog.update.microsoft.com/Search.aspx?q=KB4528760 |
Operating System(s) | Windows Server, version 1903 (Server Core installation) |
Windows Server, version 1909 (Server Core installation) | |
Windows 10 Version 1903 for 32-bit Systems | |
Windows 10 Version 1903 for ARM64-based Systems | |
Windows 10 Version 1903 for x64-based Systems | |
Windows 10 Version 1909 for 32-bit Systems | |
Windows 10 Version 1909 for ARM64-based Systems | |
Windows 10 Version 1909 for x64-based Systems |
Article | KB4534273 |
Download Link | https://www.catalog.update.microsoft.com/Search.aspx?q=KB4534273 |
Operating System(s) | Windows Server 2019 |
Windows Server 2019 (Server Core installation) | |
Windows 10 Version 1809 for 32-bit Systems | |
Windows 10 Version 1809 for ARM64-based Systems | |
Windows 10 Version 1809 for x64-based Systems |
Article | KB4534293 |
Download Link | https://www.catalog.update.microsoft.com/Search.aspx?q=KB4534293 |
Operating System(s) | Windows Server 2016, version 1803 (Server Core Installation) |
Windows 10 Version 1803 for 32-bit Systems | |
Windows 10 Version 1803 for ARM64-based Systems | |
Windows 10 Version 1803 for x64-based Systems |
Article | KB4534276 |
Download Link | https://www.catalog.update.microsoft.com/Search.aspx?q=KB4534276 |
Operating System(s) | Windows 10 Version 1709 for 32-bit Systems |
Windows 10 Version 1709 for ARM64-based Systems | |
Windows 10 Version 1709 for x64-based Systems |
Article | KB4534271 |
Download Link | https://www.catalog.update.microsoft.com/Search.aspx?q=KB4534271 |
Affected O/S | Windows Server 2016 |
Windows Server 2016 (Server Core installation) | |
Windows 10 Version 1607 for 32-bit Systems | |
Windows 10 Version 1607 for x64-based Systems |