Security News > 2020 > October > Microsoft Fixes RCE Flaws in Out-of-Band Windows Update

Microsoft Fixes RCE Flaws in Out-of-Band Windows Update
2020-10-16 20:47

One flaw exists in Microsoft's Visual Studio Code is a free source-code editor made by Microsoft for Windows, Linux and macOS. The other is in the Microsoft Windows Codecs Library; the codecs module provides stream and file interfaces for transcoding data in Windows programs.

According to Microsoft, one "Important" severity flaw stems from the way that Microsoft Windows Codecs Library handles objects in memory.

"The update addresses the vulnerability by correcting how Microsoft Windows Codecs Library handles objects in memory," according to Microsoft.

"Affected customers will be automatically updated by Microsoft Store," according to Microsoft.

The fixes come days after Microsoft's October Patch Tuesday updates, during which it released fixes for 87 security vulnerabilities, 11 of them critical - and one potentially wormable.


News URL

https://threatpost.com/microsoft-rce-flaws-windows-update/160244/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 734 853 4869 4739 3660 14121