
Microsoft has fixed a critical bug Outlook . The company has released the October 2020 updates security Office , patching 13 vulnerabilities that could allow remote attackers to execute malicious code on vulnerable systems.
The most significant vulnerability fixed with the new Microsoft Office security updates is CVE-2020-16947, a vulnerability that allows remote code execution when previewing or opening malicious emails with a vulnerable version of Microsoft Outlook.
The vulnerability can also be exploited through sites that host special filesdesigned to exploit CVE-2020-16947.
Successful exploitation of the flaw allows attackers to execute code as the System user. In addition, hackers can take control of the target system if the logged-in user has administrator privileges
The CVE-2020-16947 vulnerability affects multiple Office products, including Microsoft Outlook 2016, Microsoft Office 2019 , and Microsoft 365 Apps for Enterprise.
Office vulnerabilities that were fixed with the October security updates
The October 2020 Office Patch Tuesday fixes vulnerabilities that could allow remote code execution (RCE), bypass security, gain elevation of privilege on vulnerable systems, perform denial of service attacks, and disclose information workarounds . It also fixes cross-site scripting vulnerabilities on Windows systems running vulnerable Microsoft Installer (.msi) and Click-to-Run versions of Microsoft Office products.
Microsoft has rated the 11 RCE vulnerabilities it fixed in Office as “critical” or “serious,” as exploiting them could allow attackers to install malicious programs, view, change, and delete data, and create their own fake administrator accounts on compromised Windows devices.
| Tags | CVE ID | Title | Severity |
| Microsoft Office | CVE-2020-16933 | Micrοsoft Word Security Feature Bypass Vulnerability | Important |
| Microsoft Office | CVE-2020-16929 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2020-16934 | Microsoft Office Click-to-Run Elevation of Privilege Vulnerability | Important |
| Microsoft Office | CVE-2020-16932 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2020-16930 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2020-16955 | Microsoft Office Click-to-Run Elevation of Privilege Vulnerability | Important |
| Microsoft Office | CVE-2020-16928 | Microsoft Office Click-to-Run Elevation of Privilege Vulnerability | Important |
| Microsoft Office | CVE-2020-16957 | Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2020-16918 | Base3D Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2020-16949 | Microsoft Outlook Denial of Service Vulnerability | Moderate |
| Microsoft Office | CVE-2020-16947 | Microsoft Outlook Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2020-16931 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2020-16954 | Micrοsoft Office Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2020-17003 | Base3D Remote Code Execution Vulnerability | Critical |
| Microsoft Office SharePoint | CVE-2020-16948 | Microsoft SharePoint Information Disclosure Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2020-16953 | Microsoft SharePoint Information Disclosure Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2020-16942 | Microsoft SharePoint Information Disclosure Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2020-16951 | Micrοsoft SharePoint Remote Code Execution Vulnerability | Critical |
| Microsoft Office SharePoint | CVE-2020-16944 | Micrοsoft SharePoint Reflective XSS Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2020-16945 | Micrοsoft Office SharePoint XSS Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2020-16946 | Microsoft Office SharePoint XSS Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2020-16941 | Microsoft SharePoint Information Disclosure Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2020-16950 | Microsoft SharePoint Information Disclosure Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2020-16952 | Microsoft SharePoint Remote Code Execution Vulnerability | Critical |
October 2020: Security updates for Microsoft Office
According to Bleepingcomputer, this month's Microsoft Office security updates are being delivered via the Microsoft Update and through the Download Center.
More information is available in the tables below (as we found them on Bleepingcomputer):
Microsoft Office 2016
| Product | Knowledge Base article |
|---|---|
| Excel 2016 | Security update for Excel 2016 (KB4486678) |
| Office 2016 | Security update for Office 2016 (KB4486682) |
| Office 2016 | Security update for Office 2016 (KB4484417) |
| Outlook 2016 | Security update for Outlook 2016 (KB4486671) |
| Word 2016 | Security update for Word 2016 (KB4486679) |
Microsoft Office 2013
| Product | Knowledge Base article |
|---|---|
| Excel 2013 | Security update for Excel 2013 (KB4486695) |
| Office 2013 | Security update for Office 2013 (KB4486688) |
| Office 2013 | Security update for Office 2013 (KB4484435) |
| Outlook 2013 | Security update for Outlook 2013 (KB4484524) |
| Word 2013 | Security update for Word 2013 (KB4486692) |
Microsoft Office 2010
| Product | Knowledge Base article |
|---|---|
| Excel 2010 | Security update for Excel 2010 (KB4486707) |
| Office 2010 | Security update for Office 2010 (KB4486700) |
| Office 2010 | Security update for Office 2010 (KB4486701) |
| Outlook 2010 | Security update for Outlook 2010 (KB4486663) |
| Word 2010 | Security update for Word 2010 (KB4486703) |
Microsoft SharePoint Server 2019
| Product | Knowledge Base article |
|---|---|
| Office Online Server | Security update for Office Online Server (KB4486674) |
| SharePoint Server 2019 | Security update for SharePoint Server 2019 (KB4486676) |
Microsoft SharePoint Server 2016
| Product | Knowledge Base article |
|---|---|
| SharePoint Enterprise Server 2016 | Security update for SharePoint Enterprise Server 2016 (KB4486677) |
Microsoft SharePoint Server 2013
| Product | Knowledge Base article |
|---|---|
| Office Web Apps Server 2013 | Security update for Office Web Apps Server 2013 (KB4486689) |
| Project Server 2013 | Cumulative update for Project Server 2013 (KB4486691) |
| SharePoint Enterprise Server 2013 | Security update for SharePoint Enterprise Server 2013 (KB4486687) |
| SharePoint Enterprise Server 2013 | Cumulative update for SharePoint Enterprise Server 2013 (KB4486693) |
| SharePoint Foundation 2013 | Security update for SharePoint Foundation 2013 (KB4486694) |
| SharePoint Foundation 2013 | Cumulative update for SharePoint Foundation 2013 (KB4486690) |
Microsoft SharePoint Server 2010
| Product | Knowledge Base article |
|---|---|
| Project Server 2010 | Cumulative update for Project Server 2010 (KB4486702) |
| SharePoint Foundation 2010 | Security update for SharePoint Foundation 2010 (KB4486708) |
| SharePoint Server 2010 | Security update for SharePoint Server 2010 (KB4484531) |
| SharePoint Server 2010 | Cumulative update for SharePoint Server 2010 (KB4486705) |
| SharePoint Server 2010 Excel Web App | Security update for SharePoint Server 2010 Excel Web App (KB4462175) |
Microsoft Patch Tuesday October 2020
On Tuesday, Microsoft released its October 2020 Patch Tuesday, which includes all the vulnerability fixes across all of its products. The company patched a total of 87 vulnerabilities, with 12 of them rated critical, 74 serious, and one moderate.
Also, the non-security updates for Windows 10 (KB4579311 & KB4577671) were released.
