Microsoft's 2020-0796 Goof

I linked to this a week or so ago Security News Ticker

This was kind of interesting, mainly in the fact that it was never intended to be released to the public at the time of patch Tuesday.

Essentially two companies (FortiGuard and Cisco Talos) had accidentally released information about a vulnerability in SMBv3 before it was officially announced by Microsoft thinking it was part of patch Tuesday.

That was caught before they deleted it and spread as you’d expect (L1 had info posted before media :smiley: )

Whats interesting is how it happened. Microsoft releases information early to security vendors through a program called MAPP, its thought that they may have updated the vulnerability here and then removed it but not before it some companies released the intimation to late to remove it from their publications.

Microsoft also have an API https://github.com/microsoft/MSRC-Microsoft-Security-Updates-API that anyone can use to get details of security patches. The other thought here is again that it was published thinking they would patch it but the patch was held back without removing the info from the API before people scraped the API.

In any case what seems like a miscommunication or failure in process essentially forced Microsofts hands to push out an out of band patch that was never meant to have been published and looks to have been set for a future patch Tuesday.

4 Likes