HomeSecurityMicrosoft fixes Outlook vulnerability and other Office bugs

Microsoft fixes Outlook vulnerability and other Office bugs

Microsoft Office Outlook

Microsoft has fixed a critical bug Outlook . The company has released the October 2020 updates security Office , patching 13 vulnerabilities that could allow remote attackers to execute malicious code on vulnerable systems.

The most significant vulnerability fixed with the new Microsoft Office security updates is CVE-2020-16947, a vulnerability that allows remote code execution when previewing or opening malicious emails with a vulnerable version of Microsoft Outlook.

The vulnerability can also be exploited through sites that host special filesdesigned to exploit CVE-2020-16947.

Successful exploitation of the flaw allows attackers to execute code as the System user. In addition, hackers can take control of the target system if the logged-in user has administrator privileges

The CVE-2020-16947 vulnerability affects multiple Office products, including Microsoft Outlook 2016, Microsoft Office 2019 , and Microsoft 365 Apps for Enterprise.

Office vulnerabilities that were fixed with the October security updates

The October 2020 Office Patch Tuesday fixes vulnerabilities that could allow remote code execution (RCE), bypass security, gain elevation of privilege on vulnerable systems, perform denial of service attacks, and disclose information workarounds . It also fixes cross-site scripting vulnerabilities on Windows systems running vulnerable Microsoft Installer (.msi) and Click-to-Run versions of Microsoft Office products.

Microsoft has rated the 11 RCE vulnerabilities it fixed in Office as “critical” or “serious,” as exploiting them could allow attackers to install malicious programs, view, change, and delete data, and create their own fake administrator accounts on compromised Windows devices.

TagsCVE IDTitleSeverity
Microsoft OfficeCVE-2020-16933Micrοsoft Word Security Feature Bypass VulnerabilityImportant
Microsoft OfficeCVE-2020-16929Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2020-16934Microsoft Office Click-to-Run Elevation of Privilege VulnerabilityImportant
Microsoft OfficeCVE-2020-16932Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2020-16930Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2020-16955Microsoft Office Click-to-Run Elevation of Privilege VulnerabilityImportant
Microsoft OfficeCVE-2020-16928Microsoft Office Click-to-Run Elevation of Privilege VulnerabilityImportant
Microsoft OfficeCVE-2020-16957Microsoft Office Access Connectivity Engine Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2020-16918Base3D Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2020-16949Microsoft Outlook Denial of Service VulnerabilityModerate
Microsoft OfficeCVE-2020-16947Microsoft Outlook Remote Code Execution VulnerabilityCritical
Microsoft OfficeCVE-2020-16931Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2020-16954Micrοsoft Office Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2020-17003Base3D Remote Code Execution VulnerabilityCritical
Microsoft Office SharePointCVE-2020-16948Microsoft SharePoint Information Disclosure VulnerabilityImportant
Microsoft Office SharePointCVE-2020-16953Microsoft SharePoint Information Disclosure VulnerabilityImportant
Microsoft Office SharePointCVE-2020-16942Microsoft SharePoint Information Disclosure VulnerabilityImportant
Microsoft Office SharePointCVE-2020-16951Micrοsoft SharePoint Remote Code Execution VulnerabilityCritical
Microsoft Office SharePointCVE-2020-16944Micrοsoft SharePoint Reflective XSS VulnerabilityImportant
Microsoft Office SharePointCVE-2020-16945Micrοsoft Office SharePoint XSS VulnerabilityImportant
Microsoft Office SharePointCVE-2020-16946Microsoft Office SharePoint XSS VulnerabilityImportant
Microsoft Office SharePointCVE-2020-16941Microsoft SharePoint Information Disclosure VulnerabilityImportant
Microsoft Office SharePointCVE-2020-16950Microsoft SharePoint Information Disclosure VulnerabilityImportant
Microsoft Office SharePointCVE-2020-16952Microsoft SharePoint Remote Code Execution VulnerabilityCritical

October 2020: Security updates for Microsoft Office

According to Bleepingcomputer, this month's Microsoft Office security updates are being delivered via the Microsoft Update and through the Download Center.

More information is available in the tables below (as we found them on Bleepingcomputer):

Microsoft Office 2016

ProductKnowledge Base article
Excel 2016Security update for Excel 2016 (KB4486678)
Office 2016Security update for Office 2016 (KB4486682)
Office 2016Security update for Office 2016 (KB4484417)
Outlook 2016Security update for Outlook 2016 (KB4486671)
Word 2016Security update for Word 2016 (KB4486679)

Microsoft Office 2013

ProductKnowledge Base article
Excel 2013Security update for Excel 2013 (KB4486695)
Office 2013Security update for Office 2013 (KB4486688)
Office 2013Security update for Office 2013 (KB4484435)
Outlook 2013Security update for Outlook 2013 (KB4484524)
Word 2013Security update for Word 2013 (KB4486692)

Microsoft Office 2010

ProductKnowledge Base article
Excel 2010Security update for Excel 2010 (KB4486707)
Office 2010Security update for Office 2010 (KB4486700)
Office 2010Security update for Office 2010 (KB4486701)
Outlook 2010Security update for Outlook 2010 (KB4486663)
Word 2010Security update for Word 2010 (KB4486703)

Microsoft SharePoint Server 2019

ProductKnowledge Base article
Office Online ServerSecurity update for Office Online Server (KB4486674)
SharePoint Server 2019Security update for SharePoint Server 2019 (KB4486676)

Microsoft SharePoint Server 2016

ProductKnowledge Base article
SharePoint Enterprise Server 2016Security update for SharePoint Enterprise Server 2016 (KB4486677)

Microsoft SharePoint Server 2013

ProductKnowledge Base article
Office Web Apps Server 2013Security update for Office Web Apps Server 2013 (KB4486689)
Project Server 2013Cumulative update for Project Server 2013 (KB4486691)
SharePoint Enterprise Server 2013Security update for SharePoint Enterprise Server 2013 (KB4486687)
SharePoint Enterprise Server 2013Cumulative update for SharePoint Enterprise Server 2013 (KB4486693)
SharePoint Foundation 2013Security update for SharePoint Foundation 2013 (KB4486694)
SharePoint Foundation 2013Cumulative update for SharePoint Foundation 2013 (KB4486690)

Microsoft SharePoint Server 2010

ProductKnowledge Base article
Project Server 2010Cumulative update for Project Server 2010 (KB4486702)
SharePoint Foundation 2010Security update for SharePoint Foundation 2010 (KB4486708)
SharePoint Server 2010Security update for SharePoint Server 2010 (KB4484531)
SharePoint Server 2010Cumulative update for SharePoint Server 2010 (KB4486705)
SharePoint Server 2010 Excel Web AppSecurity update for SharePoint Server 2010 Excel Web App (KB4462175)

Microsoft Patch Tuesday October 2020

On Tuesday, Microsoft released its October 2020 Patch Tuesday, which includes all the vulnerability fixes across all of its products. The company patched a total of 87 vulnerabilities, with 12 of them rated critical, 74 serious, and one moderate.

Also, the non-security updates for Windows 10 (KB4579311 & KB4577671) were released.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS