Microsoft Office April security updates fix critical RCE bugs
#1
Exclamation 
Quote:Microsoft released the April 2020 Office security updates on April 14, 2020, with a total of 55 security updates and 5 cumulative updates for 7 different products, and patching 5 critical bugs allowing attackers to run scripts as the current user and remotely execute arbitrary code on unpatched systems.
 
Out of the 55 Office security updates released by Microsoft today, 12 of them patch remote code execution (RCE) vulnerabilities (details in ​​​​​​CVE-2020-0931CVE-2020-0932CVE-2020-0929CVE-2020-0974CVE-2020-0979CVE-2020-0980CVE-2020-0760CVE-2020-0991CVE-2020-0961CVE-2020-0906CVE-2020-0920, and CVE-2020-0971) within Microsoft Office and Microsoft Office SharePoint products.
 
The RCE bugs are rated by Microsoft with Critical and Important severity ratings as they could allow attackers to execute arbitrary code in the context of the SharePoint app pool and the SharePoint server farm account after successfully exploiting Windows devices running unpatched Office products.
 
Attackers could then install programs, view, change, and delete data, as well as create new accounts with full user rights on the compromised computers.
 
10 cross-site-scripting (XSS) vulnerabilities (details in CVE-2020-0927CVE-2020-0923CVE-2020-0925CVE-2020-0924CVE-2020-0930CVE-2020-0933CVE-2020-0978CVE-2020-0973CVE-2020-0926, and CVE-2020-0954) were also fixed to prevent attackers from running scripts in the security context of the current user and impersonate the user, steal sensitive data, or read content without authorization.
 
Microsoft also patched two elevation of privilege security flaws (details in CVE-2020-0984 and CVE-2020-0935) and four spoofing vulnerabilities (CVE-2020-0975CVE-2020-0977CVE-2020-0976, and CVE-2020-0972).

Read more: https://www.bleepingcomputer.com/news/se...-rce-bugs/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 2 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
K-Lite Codec Pack 19.7.0 / 19.7.4 Update
Changes in 19.7.03...harlan4096 — 06:20
ESET 19.1.14.0
Changes in 19.1.14....harlan4096 — 06:18
Firefox’s free email mask service got a ...
Mozilla’s Firefox ...harlan4096 — 06:16
Tor Browser 15.0.15
Tor Browser 15.0.1...harlan4096 — 06:15
AMD to bring back Ryzen 7 5800X3D as AM...
AMD had to re-engine...harlan4096 — 06:10

[-]
Birthdays
Today's Birthdays
avatar (42)tapedDow
Upcoming Birthdays
avatar (48)BrantgoG
avatar (49)rapedDow
avatar (44)Johnsonsyday
avatar (49)Groktus
avatar (41)efodo
avatar (39)Tedscolo
avatar (46)brakasig
avatar (51)smudloquask
avatar (46)benchJem
avatar (45)JamesReshy
avatar (47)Francisemefe
avatar (40)leoniDup
avatar (39)Patrizaancem
avatar (39)biobdam
avatar (42)zacforat
avatar (47)NemrokReks
avatar (38)Barrackleve
avatar (40)Julioagopy
avatar (50)aolaupitt2558
avatar (48)vadimTob
avatar (38)leannauu4
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu
avatar (32)horancos

[-]
Online Staff
There are no staff members currently online.

>