{"id":9964,"date":"2020-01-31T01:24:59","date_gmt":"2020-01-31T01:24:59","guid":{"rendered":"https:\/\/nsfocusglobal.com\/?p=9964"},"modified":"2026-04-17T18:07:50","modified_gmt":"2026-04-17T18:07:50","slug":"microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities","status":"publish","type":"post","link":"https:\/\/nsfocusglobal.com\/pt-br\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\/","title":{"rendered":"Microsoft Security Update for January 2020 Fixes 49 Security Vulnerabilities"},"content":{"rendered":"<p><!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\"><br \/>\n<html><body><\/p>\n<h2><strong>Overview<\/strong><\/h2>\n<p>Microsoft released the January security update on Tuesday, fixing 49 security issues ranging from simple spoofing attacks to remote code execution, discovered in products like .NET Framework, Apps, ASP.NET, Common Log File System Driver, Microsoft Dynamics, Microsoft Graphics Component, Microsoft Office, Microsoft Scripting Engine, Microsoft Windows, Microsoft Windows Search Component, Windows Hyper-V, Windows Media, Windows RDP, Windows Subsystem for Linux, and Windows Update Stack.<br \/>\n<!--more--><\/p>\n<p>Of the vulnerabilities fixed by Microsoft&#8217;s this monthly update, a total of eight critical vulnerabilities exist in the .NET Framework, ASP.NET, Microsoft Scripting Engine, and Windows RDP. In addition, there are 41 important vulnerabilities.<\/p>\n<h2><strong>Critical Vulnerabilities<\/strong><\/h2>\n<p>The following are eight critical vulnerabilities covered in this update.<\/p>\n<h3><strong>Windows RDP<\/strong><\/h3>\n<ul>\n<li><strong>CVE-2020-0609&atilde;&euro;CVE-2020-0610<\/strong><\/li>\n<\/ul>\n<p>These two remote code execution vulnerabilities in the Windows Remote Desktop Gateway (RD Gateway) could be exploited by unauthenticated attackers.<\/p>\n<p>If the two vulnerabilities are exploited successfully, arbitrary code may be executed on the target system, allowing the attacker to install the program, view, change or delete data, or create a new account with full user rights.<\/p>\n<p>To exploit this vulnerability, an attacker needs to send a specially crafted request to the RD gateway of the target system via RDP.<\/p>\n<p>This update addresses these issues by correcting the way the RD gateway handles connection requests.<\/p>\n<p>For more details about the vulnerabilities and download updates, please refer to Microsoft&#8217;s official security advisories:<\/p>\n<p>https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0609<\/p>\n<p>https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0610<\/p>\n<ul>\n<li><strong>CVE-2020-0611<\/strong><\/li>\n<\/ul>\n<p>This is a remote code execution vulnerability in Windows Remote Desktop clients.<\/p>\n<p>An attacker who successfully exploited this vulnerability could execute arbitrary code on a user&#8217;s computer connected to a malicious server. After that, an attacker could install a malicious program, view, change, or delete data, or create a new account with full user rights.<\/p>\n<p>To exploit this vulnerability, an attacker needs to take control of the server and then convinces a user to connect to the server. This vulnerability could be triggered if a user accesses a malicious server. Although attackers cannot force users to connect to malicious servers, they may entice users to connect through social engineering, DNS poisoning, or man-in-the-middle (MITM) technology. An attacker could also compromise a legitimate server, host malicious code on it, and wait for users to connect.<\/p>\n<p>For more details about the vulnerabilities and download updates, please refer to Microsoft&#8217;s official security advisories:<\/p>\n<p>https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0611<\/p>\n<h3><strong>Microsoft Scripting Engine<\/strong><\/h3>\n<ul>\n<li><strong>CVE-2020-0640<\/strong><\/li>\n<\/ul>\n<p>This is a memory corruption vulnerability in the way Internet Explorer handles objects in memory. The vulnerability allows an attacker to execute arbitrary code in the context of the current user.<\/p>\n<p>An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. If the current user logs in with administrative privileges, an attacker could take control of the affected system and may then install a malicious program, view, change or delete data, or create a new account with full user privileges.<\/p>\n<p>An attacker could build a specially crafted website and then convince users to visit the website. However, attackers cannot force users to view malicious contents, but entice users by email or instant messaging instead.<\/p>\n<p>Internet Explorer 9, 10, and 11 are affected.<\/p>\n<p>For more details about the vulnerabilities and download updates, please refer to Microsoft&#8217;s official security advisories:<\/p>\n<p>https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0640<\/p>\n<h3><strong>ASP.NET and .NET Framework<\/strong><\/h3>\n<ul>\n<li><strong>CVE-2020-0603, CVE-2020-0605, CVE-2020-0606, and CVE-2020-0646<\/strong><\/li>\n<\/ul>\n<p>The above vulnerabilities are remote code execution vulnerabilities in .NET and ASP.NET Core software. These vulnerabilities can be triggered if a user opens a maliciously crafted file while using an affected .NET or ASP.NET Core version. With a successful exploitation, an attacker could execute arbitrary code in the context of the current user. These errors exist in the way the software handles memory objects.<\/p>\n<p>For more details about the vulnerabilities and download updates, please refer to Microsoft&#8217;s official security advisories:<\/p>\n<p>https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0603<\/p>\n<p>https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0605<\/p>\n<p>https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0606<\/p>\n<p>https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0646<\/p>\n<h2><strong>Important Vulnerabilities<\/strong><\/h2>\n<p>In addition to critical vulnerabilities, this update also fixes 41 important vulnerabilities, three of which require more attention as follows.<\/p>\n<h3><strong>CVE-2020-0601<\/strong><\/h3>\n<p>This is a spoofing vulnerability in Windows CryptoAPI. As the Elliptic Curve Cryptography certificate was incorrectly verified by crypt32.dll, an attacker could use this error to spoof a code signing certificate and secretly sign a file, making the file appear to come from a trusted source. Attackers could also use this vulnerability to conduct man-in-the-middle attacks and decrypt confidential information.<\/p>\n<p>For more details about the vulnerabilities and download updates, please refer to Microsoft&#8217;s official security advisories:<\/p>\n<p>https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0601<\/p>\n<h3><strong>CVE-2020-0616<\/strong><\/h3>\n<p>This is a Microsoft Windows denial-of-service vulnerability. The vulnerability exists when Windows cannot properly handle hard links. An attacker who successfully exploits this vulnerability could cause the target system to stop responding.<\/p>\n<p>An attacker must log in to the victim&#8217;s computer to exploit this vulnerability and then run a specially designed application that could allow the attacker to overwrite system files.<\/p>\n<p>For more details about the vulnerabilities and download updates, please refer to Microsoft&#8217;s official security advisories:<\/p>\n<p>https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0616<\/p>\n<h3><strong>CVE-2020-0654<\/strong><\/h3>\n<p>A security feature bypass vulnerability exists in Android&#8217;s Microsoft OneDrive application. This could allow an attacker to bypass the password or fingerprint of the application.<\/p>\n<p>For more details about the vulnerabilities and download updates, please refer to Microsoft&#8217;s official security advisories:<\/p>\n<p>https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0654<\/p>\n<h2><strong>Remediation<\/strong><\/h2>\n<p>Bugs fixed in this update are shown in the following table:<\/p>\n<table width=\"930\">\n<tbody>\n<tr>\n<td><strong>Product<\/strong><\/td>\n<td><strong>CVE ID<\/strong><\/td>\n<td width=\"245\"><strong>CVE Title<\/strong><\/td>\n<td width=\"155\"><strong>Severity Level<\/strong><\/td>\n<\/tr>\n<tr>\n<td><strong>.NET Framework<\/strong><\/td>\n<td>CVE-2020-0605<\/td>\n<td width=\"245\">.NET Framework Remote code execution vulnerability<\/td>\n<td width=\"155\">Critical<\/td>\n<\/tr>\n<tr>\n<td><strong>.NET Framework<\/strong><\/td>\n<td>CVE-2020-0606<\/td>\n<td width=\"245\">.NET Framework Remote code execution vulnerability<\/td>\n<td width=\"155\">Critical<\/td>\n<\/tr>\n<tr>\n<td><strong>.NET Framework<\/strong><\/td>\n<td>CVE-2020-0646<\/td>\n<td width=\"245\">.NET Framework Remote Code Execution Injection Vulnerability<\/td>\n<td width=\"155\">Critical<\/td>\n<\/tr>\n<tr>\n<td><strong>Apps<\/strong><\/td>\n<td>CVE-2020-0654<\/td>\n<td width=\"245\">Microsoft OneDrive for Android Security feature bypass vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>ASP.NET<\/strong><\/td>\n<td>CVE-2020-0602<\/td>\n<td width=\"245\">ASP.NET Core Denial of service vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>ASP.NET<\/strong><\/td>\n<td>CVE-2020-0603<\/td>\n<td width=\"245\">ASP.NET Core Remote code execution vulnerability<\/td>\n<td width=\"155\">Critical<\/td>\n<\/tr>\n<tr>\n<td><strong>Common Log File System Driver<\/strong><\/td>\n<td>CVE-2020-0615<\/td>\n<td width=\"245\">Windows Common Log File System Driver Information Disclosure Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Common Log File System Driver<\/strong><\/td>\n<td>CVE-2020-0639<\/td>\n<td width=\"245\">Windows Common Log File System Driver Information Disclosure Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Common Log File System Driver<\/strong><\/td>\n<td>CVE-2020-0634<\/td>\n<td width=\"245\">Windows Common Log File System Driver Elevation of Privilege Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Dynamics<\/strong><\/td>\n<td>CVE-2020-0656<\/td>\n<td width=\"245\">Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Graphics Component<\/strong><\/td>\n<td>CVE-2020-0607<\/td>\n<td width=\"245\">Microsoft Graphics Components Information Disclosure Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Graphics Component<\/strong><\/td>\n<td>CVE-2020-0622<\/td>\n<td width=\"245\">Microsoft Graphics Component Information Disclosure Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Graphics Component<\/strong><\/td>\n<td>CVE-2020-0642<\/td>\n<td width=\"245\">Win32k Elevation of Privilege Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Graphics Component<\/strong><\/td>\n<td>CVE-2020-0643<\/td>\n<td width=\"245\">Windows GDI+ Information Disclosure Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Office<\/strong><\/td>\n<td>CVE-2020-0647<\/td>\n<td width=\"245\">Microsoft Office Online Fraud<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Office<\/strong><\/td>\n<td>CVE-2020-0650<\/td>\n<td width=\"245\">Microsoft Excel Remote code execution vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Office<\/strong><\/td>\n<td>CVE-2020-0651<\/td>\n<td width=\"245\">Microsoft Excel Remote code execution vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Office<\/strong><\/td>\n<td>CVE-2020-0652<\/td>\n<td width=\"245\">Microsoft Office Memory corruption<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Office<\/strong><\/td>\n<td>CVE-2020-0653<\/td>\n<td width=\"245\">Microsoft Excel Remote code execution vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Scripting Engine<\/strong><\/td>\n<td>CVE-2020-0640<\/td>\n<td width=\"245\">Internet Explorer Memory corruption<\/td>\n<td width=\"155\">Critical<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Windows<\/strong><\/td>\n<td>CVE-2020-0601<\/td>\n<td width=\"245\">Windows CryptoAPI Fraud<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Windows<\/strong><\/td>\n<td>CVE-2020-0608<\/td>\n<td width=\"245\">Win32k Information Disclosure Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Windows<\/strong><\/td>\n<td>CVE-2020-0616<\/td>\n<td width=\"245\">Microsoft Windows Denial of service vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Windows<\/strong><\/td>\n<td>CVE-2020-0620<\/td>\n<td width=\"245\">Microsoft Cryptographic Services Elevation of Privilege Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Windows<\/strong><\/td>\n<td>CVE-2020-0621<\/td>\n<td width=\"245\">Windows Security feature bypass vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Windows<\/strong><\/td>\n<td>CVE-2020-0624<\/td>\n<td width=\"245\">Win32k Elevation of Privilege Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Windows<\/strong><\/td>\n<td>CVE-2020-0635<\/td>\n<td width=\"245\">Windows Elevation of Privilege Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Windows<\/strong><\/td>\n<td>CVE-2020-0644<\/td>\n<td width=\"245\">Windows Elevation of Privilege Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Windows Search Component<\/strong><\/td>\n<td>CVE-2020-0613<\/td>\n<td width=\"245\">Windows Search Indexer Elevation of Privilege Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Windows Search Component<\/strong><\/td>\n<td>CVE-2020-0614<\/td>\n<td width=\"245\">Windows Search Indexer Elevation of Privilege Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Windows Search Component<\/strong><\/td>\n<td>CVE-2020-0623<\/td>\n<td width=\"245\">Windows Search Indexer Elevation of Privilege Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Windows Search Component<\/strong><\/td>\n<td>CVE-2020-0625<\/td>\n<td width=\"245\">Windows Search Indexer Elevation of Privilege Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Windows Search Component<\/strong><\/td>\n<td>CVE-2020-0626<\/td>\n<td width=\"245\">Windows Search Indexer Elevation of Privilege Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Windows Search Component<\/strong><\/td>\n<td>CVE-2020-0627<\/td>\n<td width=\"245\">Windows Search Indexer Elevation of Privilege Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Windows Search Component<\/strong><\/td>\n<td>CVE-2020-0628<\/td>\n<td width=\"245\">Windows Search Indexer Elevation of Privilege Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Windows Search Component<\/strong><\/td>\n<td>CVE-2020-0629<\/td>\n<td width=\"245\">Windows Search Indexer Elevation of Privilege Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Windows Search Component<\/strong><\/td>\n<td>CVE-2020-0630<\/td>\n<td width=\"245\">Windows Search Indexer Elevation of Privilege Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Windows Search Component<\/strong><\/td>\n<td>CVE-2020-0631<\/td>\n<td width=\"245\">Windows Search Indexer Elevation of Privilege Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Windows Search Component<\/strong><\/td>\n<td>CVE-2020-0632<\/td>\n<td width=\"245\">Windows Search Indexer Elevation of Privilege Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Microsoft Windows Search Component<\/strong><\/td>\n<td>CVE-2020-0633<\/td>\n<td width=\"245\">Windows Search Indexer Elevation of Privilege Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Windows Hyper-V<\/strong><\/td>\n<td>CVE-2020-0617<\/td>\n<td width=\"245\">Hyper-V Denial of service vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Windows Media<\/strong><\/td>\n<td>CVE-2020-0641<\/td>\n<td width=\"245\">Microsoft Windows Elevation of Privilege Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Windows RDP<\/strong><\/td>\n<td>CVE-2020-0609<\/td>\n<td width=\"245\">Windows Remote Desktop Gateway (RD Gateway) Remote code execution vulnerability<\/td>\n<td width=\"155\">Critical<\/td>\n<\/tr>\n<tr>\n<td><strong>Windows RDP<\/strong><\/td>\n<td>CVE-2020-0610<\/td>\n<td width=\"245\">Windows Remote Desktop Gateway (RD Gateway) Remote code execution vulnerability<\/td>\n<td width=\"155\">Critical<\/td>\n<\/tr>\n<tr>\n<td><strong>Windows RDP<\/strong><\/td>\n<td>CVE-2020-0611<\/td>\n<td width=\"245\">Remote Desktop Client Remote code execution vulnerability<\/td>\n<td width=\"155\">Critical<\/td>\n<\/tr>\n<tr>\n<td><strong>Windows RDP<\/strong><\/td>\n<td>CVE-2020-0612<\/td>\n<td width=\"245\">Windows Remote Desktop Gateway (RD Gateway) Denial of service vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Windows RDP<\/strong><\/td>\n<td>CVE-2020-0637<\/td>\n<td width=\"245\">Remote Desktop Web Access Information Disclosure Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Windows Subsystem for Linux<\/strong><\/td>\n<td>CVE-2020-0636<\/td>\n<td width=\"245\">Windows Subsystem for Linux Elevation of Privilege Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Windows Update Stack<\/strong><\/td>\n<td>CVE-2020-0638<\/td>\n<td width=\"245\">Update Notification Manager Elevation of Privilege Vulnerability<\/td>\n<td width=\"155\">Important<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h2><strong>Recommended Mitigation Measures<\/strong><\/h2>\n<p>Microsoft has released security updates to fix these issues. Please download and install them as soon as possible.<\/p>\n<h2><strong>Affected Software<\/strong><\/h2>\n<p>The following tables list the affected software details for the vulnerability.<\/p>\n<table width=\"99%\">\n<thead>\n<tr>\n<td colspan=\"7\"><strong>CVE-2020-0654<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Product<\/strong><\/td>\n<td><strong>KB Article<\/strong><\/td>\n<td><strong>Severity<\/strong><\/td>\n<td><strong>Impact<\/strong><\/td>\n<td><strong>Supersedence<\/strong><\/td>\n<td><strong>CVSS Score Set<\/strong><\/td>\n<td><strong>Restart Required<\/strong><\/td>\n<\/tr>\n<tr>\n<td>One Drive for Android<\/td>\n<td><a href=\"https:\/\/play.google.com\/store\/apps\/details?id=com.microsoft.skydrive&amp;hl=en_US\">Release Notes Security Update<\/a><\/td>\n<td>Important<\/td>\n<td>Security Feature Bypass<\/td>\n<td><\/td>\n<td>Base: N\/A<br \/>\nTemporal: N\/A<br \/>\nVector: N\/A<\/td>\n<td>Maybe<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2><strong>Affected Software<\/strong><\/h2>\n<p>The following tables list the affected software details for the vulnerability.<\/p>\n<table width=\"99%\">\n<thead>\n<tr>\n<td colspan=\"7\"><strong>CVE-2020-0656<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Product<\/strong><\/td>\n<td><strong>KB Article<\/strong><\/td>\n<td><strong>Severity<\/strong><\/td>\n<td><strong>Impact<\/strong><\/td>\n<td><strong>Supersedence<\/strong><\/td>\n<td><strong>CVSS Score Set<\/strong><\/td>\n<td><strong>Restart Required<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Dynamics 365 Field Service (on-premises) v7 series<\/td>\n<td><a href=\"https:\/\/mbs.microsoft.com\/customersource\/Global\/365Enterprise\/downloads\/product-releases\/365fieldservice7\">Relelase Notes Security Update<\/a><\/td>\n<td>Important<\/td>\n<td>Spoofing<\/td>\n<td><\/td>\n<td>Base: N\/A<br \/>\nTemporal: N\/A<br \/>\nVector: N\/A<\/td>\n<td>Maybe<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h2><strong>Statement<\/strong><\/h2>\n<p>This advisory is only used to describe a potential risk. NSFOCUS does not provide any commitment or promise on this advisory. NSFOCUS and the author will not bear any liability for any direct and\/or indirect consequences and losses caused by transmitting and\/or using this advisory. NSFOCUS reserves all the rights to modify and interpret this advisory. Please include this statement paragraph when reproducing or transferring this advisory. Do not modify this advisory, add\/delete any information to\/from it, or use this advisory for commercial purposes without permission from NSFOCUS.<\/p>\n<h2><strong>About NSFOCUS<\/strong><\/h2>\n<p>NSFOCUS, Inc., a global network and cyber security leader, protects enterprises and carriers from advanced cyber attacks. The company&#8217;s Intelligent Hybrid Security strategy utilizes both cloud and on-premises security platforms, built on a foundation of real-time global threat intelligence, to provide multi-layered, unified and dynamic protection against advanced cyber attacks.<\/p>\n<p>NSFOCUS works with Fortune Global 500 companies, including four of the world&#8217;s five largest financial institutions, organizations in insurance, retail, healthcare, critical infrastructure industries as well as government agencies. NSFOCUS has technology and channel partners in more than 60 countries, is a member of both the Microsoft Active Protections Program (MAPP), and the Cloud Security Alliance (CSA).<\/p>\n<p>A wholly owned subsidiary of NSFOCUS Information Technology Co. Ltd., the company has operations in the Americas, Europe, the Middle East and Asia Pacific.<\/p>\n<p>Download:&Acirc;&nbsp;<a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2020\/01\/Microsoft-Security-Update-for-January-2020-Fixes-49-Security-Vulnerabilities.pdf\">Microsoft Security Update for January 2020 Fixes 49 Security Vulnerabilities<\/a><\/body><\/html><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview Microsoft released the January security update on Tuesday, fixing 49 security issues ranging from simple spoofing attacks to remote code execution, discovered in products like .NET Framework, Apps, ASP.NET, Common Log File System Driver, Microsoft Dynamics, Microsoft Graphics Component, Microsoft Office, Microsoft Scripting Engine, Microsoft Windows, Microsoft Windows Search Component, Windows Hyper-V, Windows Media, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":32333,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","footnotes":""},"categories":[6],"tags":[523],"class_list":["post-9964","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-emergency-response","tag-microsoft-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Microsoft Security Update for January 2020 Fixes 49 Security Vulnerabilities - NSFOCUS<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/nsfocusglobal.com\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\/\" \/>\n<meta property=\"og:locale\" content=\"pt_BR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Microsoft Security Update for January 2020 Fixes 49 Security Vulnerabilities - NSFOCUS\" \/>\n<meta property=\"og:description\" content=\"Overview Microsoft released the January security update on Tuesday, fixing 49 security issues ranging from simple spoofing attacks to remote code\" \/>\n<meta property=\"og:url\" content=\"https:\/\/nsfocusglobal.com\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\/\" \/>\n<meta property=\"og:site_name\" content=\"NSFOCUS\" \/>\n<meta property=\"article:published_time\" content=\"2020-01-31T01:24:59+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-17T18:07:50+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2025\/07\/AIscan7.png\" \/>\n<meta name=\"author\" content=\"NSFOCUS\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Microsoft Security Update for January 2020 Fixes 49 Security Vulnerabilities - NSFOCUS\" \/>\n<meta name=\"twitter:description\" content=\"Overview Microsoft released the January security update on Tuesday, fixing 49 security issues ranging from simple spoofing attacks to remote code\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2025\/07\/AIscan7.png\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"NSFOCUS\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. tempo de leitura\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\\\/\"},\"author\":{\"name\":\"NSFOCUS\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#\\\/schema\\\/person\\\/fd9ab61c9c77a81bbd870f725cc0c61d\"},\"headline\":\"Microsoft Security Update for January 2020 Fixes 49 Security Vulnerabilities\",\"datePublished\":\"2020-01-31T01:24:59+00:00\",\"dateModified\":\"2026-04-17T18:07:50+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\\\/\"},\"wordCount\":1961,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/AIscan7.png\",\"keywords\":[\"Microsoft Vulnerabilities\"],\"articleSection\":[\"Emergency Response\"],\"inLanguage\":\"pt-BR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/nsfocusglobal.com\\\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\\\/\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\\\/\",\"name\":\"Microsoft Security Update for January 2020 Fixes 49 Security Vulnerabilities - NSFOCUS\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/AIscan7.png\",\"datePublished\":\"2020-01-31T01:24:59+00:00\",\"dateModified\":\"2026-04-17T18:07:50+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\\\/#breadcrumb\"},\"inLanguage\":\"pt-BR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/nsfocusglobal.com\\\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\\\/#primaryimage\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/AIscan7.png\",\"contentUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/AIscan7.png\",\"width\":2076,\"height\":864,\"caption\":\"Screenshot of an advanced security template creation screen with fields for name and description.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/nsfocusglobal.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Microsoft Security Update for January 2020 Fixes 49 Security Vulnerabilities\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#website\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/\",\"name\":\"NSFOCUS\",\"description\":\"Security Made Smart and Simple\",\"publisher\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/nsfocusglobal.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"pt-BR\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#organization\",\"name\":\"NSFOCUS\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/logo-ns.png\",\"contentUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/logo-ns.png\",\"width\":248,\"height\":36,\"caption\":\"NSFOCUS\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#\\\/schema\\\/person\\\/fd9ab61c9c77a81bbd870f725cc0c61d\",\"name\":\"NSFOCUS\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g\",\"caption\":\"NSFOCUS\"},\"sameAs\":[\"https:\\\/\\\/nsfocusglobal.com\"],\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/author\\\/admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Microsoft Security Update for January 2020 Fixes 49 Security Vulnerabilities - NSFOCUS","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/nsfocusglobal.com\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\/","og_locale":"pt_BR","og_type":"article","og_title":"Microsoft Security Update for January 2020 Fixes 49 Security Vulnerabilities - NSFOCUS","og_description":"Overview Microsoft released the January security update on Tuesday, fixing 49 security issues ranging from simple spoofing attacks to remote code","og_url":"https:\/\/nsfocusglobal.com\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\/","og_site_name":"NSFOCUS","article_published_time":"2020-01-31T01:24:59+00:00","article_modified_time":"2026-04-17T18:07:50+00:00","og_image":[{"url":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2025\/07\/AIscan7.png","type":"","width":"","height":""}],"author":"NSFOCUS","twitter_card":"summary_large_image","twitter_title":"Microsoft Security Update for January 2020 Fixes 49 Security Vulnerabilities - NSFOCUS","twitter_description":"Overview Microsoft released the January security update on Tuesday, fixing 49 security issues ranging from simple spoofing attacks to remote code","twitter_image":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2025\/07\/AIscan7.png","twitter_misc":{"Escrito por":"NSFOCUS","Est. tempo de leitura":"10 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/nsfocusglobal.com\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\/#article","isPartOf":{"@id":"https:\/\/nsfocusglobal.com\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\/"},"author":{"name":"NSFOCUS","@id":"https:\/\/nsfocusglobal.com\/#\/schema\/person\/fd9ab61c9c77a81bbd870f725cc0c61d"},"headline":"Microsoft Security Update for January 2020 Fixes 49 Security Vulnerabilities","datePublished":"2020-01-31T01:24:59+00:00","dateModified":"2026-04-17T18:07:50+00:00","mainEntityOfPage":{"@id":"https:\/\/nsfocusglobal.com\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\/"},"wordCount":1961,"commentCount":0,"publisher":{"@id":"https:\/\/nsfocusglobal.com\/#organization"},"image":{"@id":"https:\/\/nsfocusglobal.com\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\/#primaryimage"},"thumbnailUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2025\/07\/AIscan7.png","keywords":["Microsoft Vulnerabilities"],"articleSection":["Emergency Response"],"inLanguage":"pt-BR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/nsfocusglobal.com\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/nsfocusglobal.com\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\/","url":"https:\/\/nsfocusglobal.com\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\/","name":"Microsoft Security Update for January 2020 Fixes 49 Security Vulnerabilities - NSFOCUS","isPartOf":{"@id":"https:\/\/nsfocusglobal.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/nsfocusglobal.com\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\/#primaryimage"},"image":{"@id":"https:\/\/nsfocusglobal.com\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\/#primaryimage"},"thumbnailUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2025\/07\/AIscan7.png","datePublished":"2020-01-31T01:24:59+00:00","dateModified":"2026-04-17T18:07:50+00:00","breadcrumb":{"@id":"https:\/\/nsfocusglobal.com\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\/#breadcrumb"},"inLanguage":"pt-BR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/nsfocusglobal.com\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\/"]}]},{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/nsfocusglobal.com\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\/#primaryimage","url":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2025\/07\/AIscan7.png","contentUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2025\/07\/AIscan7.png","width":2076,"height":864,"caption":"Screenshot of an advanced security template creation screen with fields for name and description."},{"@type":"BreadcrumbList","@id":"https:\/\/nsfocusglobal.com\/microsoft-security-update-for-january-2020-fixes-49-security-vulnerabilities\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/nsfocusglobal.com\/"},{"@type":"ListItem","position":2,"name":"Microsoft Security Update for January 2020 Fixes 49 Security Vulnerabilities"}]},{"@type":"WebSite","@id":"https:\/\/nsfocusglobal.com\/#website","url":"https:\/\/nsfocusglobal.com\/","name":"NSFOCUS","description":"Security Made Smart and Simple","publisher":{"@id":"https:\/\/nsfocusglobal.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/nsfocusglobal.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"pt-BR"},{"@type":"Organization","@id":"https:\/\/nsfocusglobal.com\/#organization","name":"NSFOCUS","url":"https:\/\/nsfocusglobal.com\/","logo":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/nsfocusglobal.com\/#\/schema\/logo\/image\/","url":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/08\/logo-ns.png","contentUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/08\/logo-ns.png","width":248,"height":36,"caption":"NSFOCUS"},"image":{"@id":"https:\/\/nsfocusglobal.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/nsfocusglobal.com\/#\/schema\/person\/fd9ab61c9c77a81bbd870f725cc0c61d","name":"NSFOCUS","image":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/secure.gravatar.com\/avatar\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g","caption":"NSFOCUS"},"sameAs":["https:\/\/nsfocusglobal.com"],"url":"https:\/\/nsfocusglobal.com\/pt-br\/author\/admin\/"}]}},"_links":{"self":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts\/9964","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/comments?post=9964"}],"version-history":[{"count":0,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts\/9964\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/media\/32333"}],"wp:attachment":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/media?parent=9964"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/categories?post=9964"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/tags?post=9964"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}