Security News > 2020 > October > Microsoft Patch Tuesday, October 2020 Edition

Microsoft Patch Tuesday, October 2020 Edition
2020-10-13 20:10

It's Cybersecurity Awareness Month! In keeping with that theme, if youuse Microsoft Windows computers you should be aware the company shipped a bevy of software updates today to fix at least 87 security problems in Windows and programs that run on top of the operating system.

Worst in terms of outright scariness is probably CVE-2020-16898, which is a nasty bug in Windows 10 and Windows Server 2019 that could be abused to install malware just by sending a malformed packet of data at a vulnerable system.

Trend Micro's Zero Day Initiative calls special attention to another critical bug quashed in this month's patch batch: CVE-2020-16947, which is a problem with Microsoft Outlook that could result in malware being loaded onto a system just by previewing a malicious email in Outlook.

Mercifully, Adobe is slated to retire Flash Player later this year, and Microsoft has said it plans to ship updates at the end of the year that will remove Flash from Windows machines.

It's a good idea for Windows users to get in the habit of updating at least once a month, but for regular users it's usually safe to wait a few days until after the patches are released, so that Microsoft has time to iron out any chinks in the new armor.


News URL

https://krebsonsecurity.com/2020/10/microsoft-patch-tuesday-october-2020-edition/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2020-10-16 CVE-2020-16898 Unspecified vulnerability in Microsoft products
<p>A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets.
low complexity
microsoft
8.8
2020-10-16 CVE-2020-16947 Out-of-bounds Write vulnerability in Microsoft 365 Apps, Office and Outlook
<p>A remote code execution vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory.
network
high complexity
microsoft CWE-787
7.5

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 723 805 4705 4715 3646 13871