Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • August 2020 Patch Tuesday current page
Link copied

August 2020 Patch Tuesday

Aug 11, 2020
Author:
400x400 Linkedin X Profile
Phantom Labs™
BeyondTrust
Blog banner default
August 2020 Patch Tuesday
400x400 Linkedin X Profile
Phantom Labs™
BeyondTrust

Welcome back to this month’s Patch Tuesday. This month’s salvo of patches fix 120 vulnerabilities, 17 of which have been declared ‘Critical’ by Microsoft, and 2 of which have been exploited in the wild.

Windows

The first zero-day patched this month is a bug in the Windows OS. This vulnerability allows attackers to fool the OS into validating invalid file signatures, which allows them to bypass security features and load malicious files as if they came from a trusted source.

Internet Explorer Scripting Engine

Internet Explorer comes with a scripting engine to run online scripts in real time. The engine is also leveraged by Office products, such as rendering web pages in Word documents. An attacker who took advantage of this engine would be able to remotely execute code with the same security context of the current user. So if a victim were running an office product or Internet Explorer as an administrator, the attacker could gain complete control over the system.

Microsoft Office

Microsoft Office products got their usual attention this month. As mentioned above, Office products that leverage the IE scripting engine were vulnerable to maliciously crafted files. Attackers exploiting these vulnerabilities would be able to execute code within the security context of the current user. This once again reminds us to exercise the principle of least privilege.

Windows Server

Windows Server received a partial fix for CVE-2020-1472, which could allow an unauthenticated attacker to gain administrative access to a Windows domain controller and execute arbitrary commands. Since domain controllers hold the keys to the corporate network kingdom, this is a highly severe vulnerability.

Latest Posts
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
  • Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First
    May 11, 2026 Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First
    Blog
    4m
Related
  • Introducing the Gartner Market Guide for Privileged Account Management
    Jul 29, 2014 Introducing the Gartner Market Guide for Privileged Account Management
    Blog
    1m
  • 8 Ways to Ensure Your Privileged Password Management Strategy is a Success
    Jul 19, 2016 8 Ways to Ensure Your Privileged Password Management Strategy is a Success
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.