ΑρχικήsecurityMicrosoft: Κυκλοφόρησε το Patch Tuesday για το Νοέμβριο 2020

Microsoft: Κυκλοφόρησε το Patch Tuesday για το Νοέμβριο 2020

Η Microsoft κυκλοφόρησε χθες τις καθιερωμένες μηνιαίες ενημερώσεις ασφαλείας, γνωστές ως Patch Tuesday. Το Patch Tuesday για το Νοέμβριο του 2020 διορθώνει 112 ευπάθειες ασφαλείας σε ένα ευρύ φάσμα προϊόντων.

Microsoft Patch Tuesday
Microsoft: Κυκλοφόρησε το Patch Tuesday για το Νοέμβριο 2020

Η εταιρεία διορθώνει, επίσης, μια zero-day ευπάθεια των Windows που αποκαλύφθηκε στις 30 Οκτωβρίου από τις ομάδες ασφαλείας της Google, Google Project Zero και TAG. Σύμφωνα με τους ερευνητές, η ευπάθεια χρησιμοποιούνταν ήδη από εγκληματίες.

Είναι γνωστή ως CVE-2020-17087 και σύμφωνα με τη Google, χρησιμοποιούνταν μαζί με ένα άλλο zero-day σφάλμα στο Chrome για να στοχεύσει χρήστες Windows 7 και Windows 10.

Οι ερευνητές της Google ενημέρωσαν τη Microsoft για τη zero-day ευπάθεια και η εταιρεία τη διόρθωσε χθες με την κυκλοφορία του Patch Tuesday Νοεμβρίου 2020.

Σύμφωνα με τη Microsoft, η ευπάθεια CVE-2020-17087 βρίσκεται στο Windows kernel και επηρεάζει όλες τις υποστηριζόμενες εκδόσεις του λειτουργικού συστήματος των Windows. Αυτό περιλαμβάνει όλες τις εκδόσεις μετά τα Windows 7 και όλες τις διανομές Windows Server.

Πέρα, όμως, από το παραπάνω σφάλμα, το Patch Tuesday διορθώνει άλλες 111 ευπάθειες, συμπεριλαμβανομένων 24 σφαλμάτων που επιτρέπουν την εκτέλεση κώδικα απομακρυσμένα (RCE) σε εφαρμογές όπως το Excel, το Microsoft Sharepoint, το Microsoft Exchange Server, το Windows Network File System, το Windows GDI+ component, την υπηρεσία Windows printing spooler και το Microsoft Teams.

Microsoft: Κυκλοφόρησε το Patch Tuesday για το Νοέμβριο 2020

Στον παρακάτω πίνακα, μπορείτε να βρείτε όλες τις ευπάθειες που διορθώνονται στο Patch Tuesday Νοεμβρίου 2020:

TagCVE IDCVE TitleSeverity
Azure DevOpsCVE-2020-1325Azure DevOps Server and Team Foundation Services Spoofing VulnerabilityImportant
Azure SphereCVE-2020-16985Azure Sphere Information Disclosure VulnerabilityImportant
Azure SphereCVE-2020-16986Azure Sphere Denial of Service VulnerabilityImportant
Azure SphereCVE-2020-16987Azure Sphere Unsigned Code Execution VulnerabilityImportant
Azure SphereCVE-2020-16984Azure Sphere Unsigned Code Execution VulnerabilityImportant
Azure SphereCVE-2020-16981Azure Sphere Elevation of Privilege VulnerabilityImportant
Azure SphereCVE-2020-16982Azure Sphere Unsigned Code Execution VulnerabilityImportant
Azure SphereCVE-2020-16983Azure Sphere Tampering VulnerabilityImportant
Azure SphereCVE-2020-16988Azure Sphere Elevation of Privilege VulnerabilityCritical
Azure SphereCVE-2020-16993Azure Sphere Elevation of Privilege VulnerabilityImportant
Azure SphereCVE-2020-16994Azure Sphere Unsigned Code Execution VulnerabilityImportant
Azure SphereCVE-2020-16970Azure Sphere Unsigned Code Execution VulnerabilityImportant
Azure SphereCVE-2020-16992Azure Sphere Elevation of Privilege VulnerabilityImportant
Azure SphereCVE-2020-16989Azure Sphere Elevation of Privilege VulnerabilityImportant
Azure SphereCVE-2020-16990Azure Sphere Information Disclosure VulnerabilityImportant
Azure SphereCVE-2020-16991Azure Sphere Unsigned Code Execution VulnerabilityImportant
Common Log File System DriverCVE-2020-17088Windows Common Log File System Driver Elevation of Privilege VulnerabilityImportant
Micrοsoft BrowsersCVE-2020-17058Microsoft Browser Memory Corruption VulnerabilityCritical
Micrοsoft DynamicsCVE-2020-17005Microsoft Dynamics 365 (on-premises) Cross-site Scripting VulnerabilityImportant
Micrοsoft DynamicsCVE-2020-17018Micrοsoft Dynamics 365 (on-premises) Cross-site Scripting VulnerabilityImportant
Micrοsoft DynamicsCVE-2020-17021Micrοsoft Dynamics 365 (on-premises) Cross-site Scripting VulnerabilityImportant
Microsoft DynamicsCVE-2020-17006Micrοsoft Dynamics 365 (on-premises) Cross-site Scripting VulnerabilityImportant
Microsoft Exchange ServerCVE-2020-17083Micrοsoft Exchange Server Remote Code Execution VulnerabilityImportant
Microsoft Exchange ServerCVE-2020-17085Micrοsoft Exchange Server Denial of Service VulnerabilityImportant
Micrοsoft Exchange ServerCVE-2020-17084Micrοsoft Exchange Server Remote Code Execution VulnerabilityImportant
Micrοsoft Graphics ComponentCVE-2020-16998DirectX Elevation of Privilege VulnerabilityImportant
Micrοsoft Graphics ComponentCVE-2020-17029Windows Canonical Display Driver Information Disclosure VulnerabilityImportant
Micrοsoft Graphics ComponentCVE-2020-17004Windows Graphics Component Information Disclosure VulnerabilityImportant
Micrοsoft Graphics ComponentCVE-2020-17038Win32k Elevation of Privilege VulnerabilityImportant
Micrοsoft Graphics ComponentCVE-2020-17068Windows GDI+ Remote Code Execution VulnerabilityImportant
Micrοsoft OfficeCVE-2020-17065Microsoft Excel Remote Code Execution VulnerabilityImportant
Micrοsoft OfficeCVE-2020-17064Microsoft Excel Remote Code Execution VulnerabilityImportant
Micrοsoft OfficeCVE-2020-17066Microsoft Excel Remote Code Execution VulnerabilityImportant
Micrοsoft OfficeCVE-2020-17019Micrοsoft Excel Remote Code Execution VulnerabilityImportant
Micrοsoft OfficeCVE-2020-17067Micrοsoft Excel Security Feature Bypass VulnerabilityImportant
Microsoft OfficeCVE-2020-17062Microsoft Office Access Connectivity Engine Remote Code Execution VulnerabilityImportant
Micrοsoft OfficeCVE-2020-17063Micrοsoft Office Online Spoofing VulnerabilityImportant
Microsoft OfficeCVE-2020-17020Microsoft Word Security Feature Bypass VulnerabilityImportant
Micrοsoft Office SharePointCVE-2020-17016Micrοsoft SharePoint Spoofing VulnerabilityImportant
Microsoft Office SharePointCVE-2020-16979Micrοsoft SharePoint Information Disclosure VulnerabilityImportant
Micrοsoft Office SharePointCVE-2020-17015Micrοsoft SharePoint Spoofing VulnerabilityLow
Microsoft Office SharePointCVE-2020-17017Microsoft SharePoint Information Disclosure VulnerabilityImportant
Micrοsoft Office SharePointCVE-2020-17061Microsoft SharePoint Remote Code Execution VulnerabilityImportant
Microsoft Office SharePointCVE-2020-17060Micrοsoft SharePoint Spoofing VulnerabilityImportant
Micrοsoft Scripting EngineCVE-2020-17048Chakra Scripting Engine Memory Corruption VulnerabilityCritical
Microsoft Scripting EngineCVE-2020-17053Internet Explorer Memory Corruption VulnerabilityCritical
Micrοsoft Scripting EngineCVE-2020-17052Scripting Engine Memory Corruption VulnerabilityCritical
Microsoft Scripting EngineCVE-2020-17054Chakra Scripting Engine Memory Corruption VulnerabilityImportant
Microsoft TeamsCVE-2020-17091Microsoft Teams Remote Code Execution VulnerabilityImportant
Micrοsoft WindowsCVE-2020-17032Windows Remote Access Elevation of Privilege VulnerabilityImportant
Micrοsoft WindowsCVE-2020-17033Windows Remote Access Elevation of Privilege VulnerabilityImportant
Micrοsoft WindowsCVE-2020-17026Windows Remote Access Elevation of Privilege VulnerabilityImportant
Micrοsoft WindowsCVE-2020-17031Windows Remote Access Elevation of Privilege VulnerabilityImportant
Micrοsoft WindowsCVE-2020-17027Windows Remote Access Elevation of Privilege VulnerabilityImportant
Micrοsoft WindowsCVE-2020-17030Windows MSCTF Server Information Disclosure VulnerabilityImportant
Micrοsoft WindowsCVE-2020-17028Windows Remote Access Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2020-17044Windows Remote Access Elevation of Privilege VulnerabilityImportant
Micrοsoft WindowsCVE-2020-17045Windows KernelStream Information Disclosure VulnerabilityImportant
Microsoft WindowsCVE-2020-17046Windows Error Reporting Denial of Service VulnerabilityLow
Micrοsoft WindowsCVE-2020-17043Windows Remote Access Elevation of Privilege VulnerabilityImportant
Micrοsoft WindowsCVE-2020-17042Windows Print Spooler Remote Code Execution VulnerabilityCritical
Micrοsoft WindowsCVE-2020-17041Windows Print Configuration Elevation of Privilege VulnerabilityImportant
Micrοsoft WindowsCVE-2020-17034Windows Remote Access Elevation of Privilege VulnerabilityImportant
Micrοsoft WindowsCVE-2020-17049Kerberos Security Feature Bypass VulnerabilityImportant
Micrοsoft WindowsCVE-2020-17051Windows Network File System Remote Code Execution VulnerabilityCritical
Microsoft WindowsCVE-2020-17040Windows Hyper-V Security Feature Bypass VulnerabilityImportant
Micrοsoft WindowsCVE-2020-17047Windows Network File System Denial of Service VulnerabilityImportant
Microsoft WindowsCVE-2020-17036Windows Function Discovery SSDP Provider Information Disclosure VulnerabilityImportant
Microsoft WindowsCVE-2020-17000Remote Desktop Protocol Client Information Disclosure VulnerabilityImportant
Microsoft WindowsCVE-2020-1599Windows Spoofing VulnerabilityImportant
Microsoft WindowsCVE-2020-16997Remote Desktop Protocol Server Information Disclosure VulnerabilityImportant
Microsoft WindowsCVE-2020-17001Windows Print Spooler Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2020-17057Windows Win32k Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2020-17056Windows Network File System Information Disclosure VulnerabilityImportant
Microsoft WindowsCVE-2020-17055Windows Remote Access Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2020-17010Win32k Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2020-17007Windows Error Reporting Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2020-17014Windows Print Spooler Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2020-17025Windows Remote Access Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2020-17024Windows Client Side Rendering Print Provider Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2020-17013Win32k Information Disclosure VulnerabilityImportant
Microsoft WindowsCVE-2020-17011Windows Port Class Library Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2020-17012Windows Bind Filter Driver Elevation of Privilege VulnerabilityImportant
Microsoft Windows Codecs LibraryCVE-2020-17106HEVC Video Extensions Remote Code Execution VulnerabilityCritical
Microsoft Windows Codecs LibraryCVE-2020-17101HEIF Image Extensions Remote Code Execution VulnerabilityCritical
Microsoft Windows Codecs LibraryCVE-2020-17105AV1 Video Extension Remote Code Execution VulnerabilityCritical
Microsoft Windows Codecs LibraryCVE-2020-17102WebP Image Extensions Information Disclosure VulnerabilityImportant
Microsoft Windows Codecs LibraryCVE-2020-17082Raw Image Extension Remote Code Execution VulnerabilityCritical
Microsoft Windows Codecs LibraryCVE-2020-17086Raw Image Extension Remote Code Execution VulnerabilityImportant
Microsoft Windows Codecs LibraryCVE-2020-17081Microsoft Raw Image Extension Information Disclosure VulnerabilityImportant
Microsoft Windows Codecs LibraryCVE-2020-17079Raw Image Extension Remote Code Execution VulnerabilityCritical
Microsoft Windows Codecs LibraryCVE-2020-17078Raw Image Extension Remote Code Execution VulnerabilityCritical
Microsoft Windows Codecs LibraryCVE-2020-17107HEVC Video Extensions Remote Code Execution VulnerabilityCritical
Microsoft Windows Codecs LibraryCVE-2020-17110HEVC Video Extensions Remote Code Execution VulnerabilityCritical
Microsoft Windows Codecs LibraryCVE-2020-17113Windows Camera Codec Information Disclosure VulnerabilityImportant
Microsoft Windows Codecs LibraryCVE-2020-17108HEVC Video Extensions Remote Code Execution VulnerabilityCritical
Microsoft Windows Codecs LibraryCVE-2020-17109HEVC Video Extensions Remote Code Execution VulnerabilityCritical
Visual StudioCVE-2020-17104Visual Studio Code JSHint Extension Remote Code Execution VulnerabilityImportant
Visual StudioCVE-2020-17100Visual Studio Tampering VulnerabilityImportant
Windows DefenderCVE-2020-17090Microsoft Defender for Endpoint Security Feature Bypass VulnerabilityImportant
Windows KernelCVE-2020-17035Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2020-17087Windows Kernel Local Elevation of Privilege VulnerabilityImportant
Windows NDISCVE-2020-17069Windows NDIS Information Disclosure VulnerabilityImportant
Windows Update StackCVE-2020-17074Windows Update Orchestrator Service Elevation of Privilege VulnerabilityImportant
Windows Update StackCVE-2020-17073Windows Update Orchestrator Service Elevation of Privilege VulnerabilityImportant
Windows Update StackCVE-2020-17071Windows Delivery Optimization Information Disclosure VulnerabilityImportant
Windows Update StackCVE-2020-17075Windows USO Core Worker Elevation of Privilege VulnerabilityImportant
Windows Update StackCVE-2020-17070Windows Update Medic Service Elevation of Privilege VulnerabilityImportant
Windows Update StackCVE-2020-17077Windows Update Stack Elevation of Privilege VulnerabilityImportant
Windows Update StackCVE-2020-17076Windows Update Orchestrator Service Elevation of Privilege VulnerabilityImportant
Windows WalletServiceCVE-2020-16999Windows WalletService Information Disclosure VulnerabilityImportant
Windows WalletServiceCVE-2020-17037Windows WalletService Elevation of Privilege VulnerabilityImportant

Πηγή: ZDNet


Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

Εγγραφή στο Newsletter

* indicates required

FOLLOW US

LIVE NEWS