{"id":230962,"date":"2020-04-22T11:32:35","date_gmt":"2020-04-22T09:32:35","guid":{"rendered":"https:\/\/www.borncity.com\/blog\/?p=230962"},"modified":"2022-01-26T05:23:05","modified_gmt":"2022-01-26T04:23:05","slug":"microsoft-security-advisories-zum-14-und-21-april-2020","status":"publish","type":"post","link":"https:\/\/borncity.com\/blog\/2020\/04\/22\/microsoft-security-advisories-zum-14-und-21-april-2020\/","title":{"rendered":"Microsoft Security Advisories zum 14. und 21. April 2020"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" src=\"https:\/\/borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" height=\"47\" align=\"left\" \/>[<a href=\"https:\/\/borncity.com\/win\/2020\/04\/22\/microsoft-security-advisories-zum-14-und-21-april-2020\/\" target=\"_blank\" rel=\"noopener noreferrer\">English<\/a>]Noch ein kurzer Hinweis f\u00fcr Administratoren, die Microsofts Dynamics Business Central einsetzen. In dieser gibt es als kritisch eingestufte RCE-Schwachstelle CVE-2020-0905. Zudem hat Microsoft Security Advisories f\u00fcr ein Update der Autodesk FBX Library und f\u00fcr eine OpenSSL Remote Denial of Service Schwachstelle ver\u00f6ffentlicht<\/p>\n<p><!--more--><\/p>\n<h2>RCE-Schwachstelle in Dynamics Business Central<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg07.met.vgwort.de\/na\/f4dc6ea9235a4ecf8756421481486f5c\" alt=\"\" width=\"1\" height=\"1\" \/>Das Ganze ist schon seit M\u00e4rz 2020 bekannt \u2013 Microsoft hat die Tage aber die Download-Links ge\u00e4ndert und das ist einem Security Advisory mitgeteilt. Hier die Information.<\/p>\n<p>Title: Microsoft Security Update Releases<br \/>\nIssued: April 14, 2020<br \/>\n***************************************<br \/>\nCVE CVE-2020-0905 has undergone a major revision increment:<br \/>\nRevision Information:<\/p>\n<p>&#8211; <a href=\"https:\/\/web.archive.org\/web\/20200424043206\/https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/CVE-2019-0905\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2020-0905<\/a> | Dynamics Business Central Remote Code Execution Vulnerability<br \/>\n&#8211;\u00a0 &#8211; Version: 2.0<br \/>\n&#8211; Reason for Revision: In the Security Updates table, corrected the Download links for<br \/>\nthe following products: Microsoft Dynamics NAV 2018, Microsoft Dynamics 365 BC On<br \/>\nPremise, Dynamics 365 Business Central 2019 Spring Update,<br \/>\nand Dynamics 365 Business<br \/>\nCentral 2019 Release Wave 2 (On-Premise). Customers who are running one of these<br \/>\naffected versions of Microsoft Dynamics should ensure that they have downloaded and<br \/>\ninstalled the most recent updates to be protected from this vulnerability.<br \/>\n&#8211; Originally posted: March 10, 2020<br \/>\n&#8211; Updated: April 14, 2020<br \/>\n&#8211; Aggregate CVE Severity Rating: Critical<\/p>\n<p>Administratoren sollten das Sicherheitsupdate installieren, um gegen die RCE-Schwachstelle gesch\u00fctzt zu sein.<\/p>\n<h2>Update der Autodesk FBX Library<\/h2>\n<p>In einer Security Advisory Notification vom 21. April 2020 weist Microsoft auf ein Update f\u00fcr seine Autodesk FBX-Bibliothek hin. Hier die Details:<\/p>\n<p>* Microsoft Security Advisory ADV200004<\/p>\n<p>&#8211; <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/ADV200004\" target=\"_blank\" rel=\"noopener noreferrer\">ADV200004<\/a> | Availability of updates for Microsoft software utilizing the<br \/>\nAutodesk FBX library<br \/>\n&#8211;\u00a0 &#8211; Reason for Revision: Information published.<br \/>\n&#8211; Originally posted: April 21, 2020<br \/>\n&#8211; Updated: N\/A<br \/>\n&#8211; Version: 1.0<\/p>\n<p>Es ist ein au\u00dferplanm\u00e4\u00dfiges Sicherheitsupdate, das Sicherheitsl\u00fccken bei der Remote-Codeausf\u00fchrung in einer Autodesk FBX-Bibliothek behebt, die in Microsoft Office und Paint 3D-Anwendungen integriert ist. Bleeping Computer hat <a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-releases-oob-security-updates-for-microsoft-office\/\" target=\"_blank\" rel=\"noopener noreferrer\">hier einen Artikel<\/a> zum Thema ver\u00f6ffentlicht.<\/p>\n<h2>OpenSSL Remote Denial of Service-Schwachstelle<\/h2>\n<p>In OpenSSL gibt es eine Remote ausnutzbare Denial of Service-Schwachstelle, auf die Microsoft in einem Security Advisory vom 21. April 2020 hinweist.<\/p>\n<p>* Microsoft Security Advisory ADV200007<\/p>\n<p>&#8211; <a href=\"https:\/\/web.archive.org\/web\/20200501054205\/https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/ADV200007\" target=\"_blank\" rel=\"noopener noreferrer\">ADV200007<\/a> | OpenSSL Remote Denial of Service Vulnerability-<br \/>\n&#8211; Reason for Revision: Information published.<br \/>\n&#8211; Originally posted: April 21, 2020<br \/>\n&#8211; Updated: N\/A<br \/>\n&#8211; Version: 1.0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[English]Noch ein kurzer Hinweis f\u00fcr Administratoren, die Microsofts Dynamics Business Central einsetzen. In dieser gibt es als kritisch eingestufte RCE-Schwachstelle CVE-2020-0905. Zudem hat Microsoft Security Advisories f\u00fcr ein Update der Autodesk FBX Library und f\u00fcr eine OpenSSL Remote Denial of &hellip; <a href=\"https:\/\/borncity.com\/blog\/2020\/04\/22\/microsoft-security-advisories-zum-14-und-21-april-2020\/\">Weiterlesen <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[426,7459],"tags":[8024,8025,8023,4328,3836],"class_list":["post-230962","post","type-post","status-publish","format-standard","hentry","category-sicherheit","category-software","tag-adv200004","tag-adv200007","tag-cve-2020-0905","tag-sicherheit","tag-software"],"_links":{"self":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/230962","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/comments?post=230962"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/230962\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/media?parent=230962"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/categories?post=230962"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/tags?post=230962"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}