October 2020 Patch Tuesday: Microsoft fixes potentially wormable Windows TCP/IP RCE flaw
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-12352 | Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access. Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access. NVD description · AI analysis pending | 6.5 | 6% | PoC |
| — | |
| CVE-2020-16898 +1 in the same advisory: …16909 | A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could gain the ability to execute code on the target server or client. To exploit this vulnerability, an attacker would have to send specially crafted ICMPv6 Router Advertisement packets to a remote Windows computer. The update addresses the vulnerability by correcting how the Windows TCP/IP stack handles ICMPv6 Router Advertisement packets. NVD description · AI analysis pending | 8.8 group max | 11% |
| — | ||
| CVE-2020-16947 | A remote code execution vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory. A remote code execution vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the targeted user. If the targeted user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Outlook software. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file designed to exploit the vulnerability. An attacker would have no way to force users to visit the website. Instead, an attacker would have to convince users to click a link, typically by way of an enticement in an email or instant message, and then convince them to open the specially crafted file. Note that where severity is indicated as Critical in the Affected Products table, the Preview Pane is an attack vector. The security update addresses the vulnerability by correcting how Outlook handles objects in memory. NVD description · AI analysis pending | 7.5 | 34% |
| — | ||
| CVE-2020-16952 +1 in the same advisory: …16951 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account. Exploitation of this vulnerability requires that a user uploads a specially crafted SharePoint application package to an affected version of SharePoint. The security update addresses the vulnerability by correcting how SharePoint checks the source markup of application packages. NVD description · AI analysis pending | 8.6 | 71% | PoC |
| — | |
| CVE-2020-24490 | Improper buffer restrictions in BlueZ may allow an unauthenticated user to potentially enable denial of service via adjacent access. Improper buffer restrictions in BlueZ may allow an unauthenticated user to potentially enable denial of service via adjacent access. This affects all Linux kernel versions that support BlueZ. NVD description · AI analysis pending | 6.5 | 2% |
| — | ||
| CVE-2020-6364 | SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a way that O SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a way that OS commands can be executed and potentially gain control over the host running the CA Introscope Enterprise Manager,leading to Code Injection. With this, the attacker is able to read and modify all system files and also impact system availability. NVD description · AI analysis pending | 10.0 | 6% |
| — | ||
| CVE-2020-6369 | SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an unauthenticated attackers to bypass the aut SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an unauthenticated attackers to bypass the authentication if the default passwords for Admin and Guest have not been changed by the administrator.This may impact the confidentiality of the service. NVD description · AI analysis pending | 5.9 | 3% |
| — | ||
| CVE-2020-9746 | Adobe Flash Player version 32.0.0.433 (and earlier) are affected by an exploitable NULL pointer dereference vulnerability that could result in a crash and arbit Adobe Flash Player version 32.0.0.433 (and earlier) are affected by an exploitable NULL pointer dereference vulnerability that could result in a crash and arbitrary code execution. Exploitation of this issue requires an attacker to insert malicious strings in an HTTP response that is by default delivered over TLS/SSL. NVD description · AI analysis pending | 8.8 | 4% |
| — |
Full article768 words · extracted from helpnetsecurity.com · click to collapse
On this October 2020 Patch Tuesday:
- Microsoft has plugged 87 security holes, including critical ones in the Windows TCP/IP stack and Microsoft Outlook and Microsoft 365 Apps for Enterprise
- Adobe has delivered security updates for Adobe Flash Player
- Intel warns about flaws in BlueZ, the official Linux Bluetooth protocol stack
- SAP has released 15 security notes and updates to 6 previously released ones.

Microsoft’s updates
Microsoft has released patches for 87 CVE-numbered flaws in a variety of its offerings: 11 critical, 75 important, and one of moderate severity. None of the fixed vulnerabilities are currently being exploited, though six of them were previously publicly known.
Trend Micro Zero Day Initiative’s Dustin Childs has singled out a few that should be addressed quickly:
CVE-2020-16898 – A Windows TCP/IP vulnerability that could be remotely exploited by sending a specially crafted ICMPv6 router advertisement to an affected Windows server or client and could allow code execution. Researchers at McAfee have dubbed the flaw “Bad Neighbor” because it is located within an ICMPv6 Neighbor Discovery “Protocol”, and say that it “could be made wormable”.
“The only good news is that Microsoft’s internal security team unearthed the vulnerabilities, meaning PoC code likely won’t surface until someone reverse engineers the patch and discovers the source of these vulnerabilities,” noted Nicholas Colyer, Senior Product Marketing Manager at Automox.
CVE-2020-16947 – A remote code execution flaw affecting Microsoft Outlook and Microsoft 365 Apps for Enterprise. The flaw can be triggered by a specially crafted file that a target user is convinced/tricked into opening, but also by the user previewing the file via the Preview Pane (i.e., the user does not have to open the email with the attached file in order for the exploit to work).
CVE-2020-16909 – A bug in the Windows Error Reporting (WER) component that could be used by an authenticated attacker to execute arbitrary code with escalated privileges. “Although this CVE is not listed as being publicly exploited, bugs in this component have been reported as being used in the wild in fileless attacks. Regardless, this and the other bugs in the WER component being fixed this month should not be ignored,” Childs pointed out.
Animesh Jain, Vulnerability Signatures Product Manager at Qualys, advises prioritizing Windows Camera Codec, GDI+, Browser, Hyper-V, Outlook, Media Foundation and Graphics components vulnerabilities for workstations.
She also recommends admins to apply the Sharepoint Server updates to patch two RCEs (CVE-2020-16951 and CVE-2020-16952)
Exploitation of these vulnerabilities requires that a user (authenticated attacker) uploads a specially crafted SharePoint application package to an affected version of SharePoint, Microsoft explained, but if they succeed, they could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm.
Adobe’s updates
Adobe has published a single security bulletin this time, carrying news of security updates for Adobe Flash Player for Windows, macOS, Linux and Chrome OS.
A critical NULL pointer dereference flaw (CVE-2020-9746) has been fixed, which could lead to an exploitable crash and potentially allow arbitrary code execution in the context of the current user.
“Exploitation of CVE-2020-9746 requires an attacker to insert malicious strings in an HTTP response that is by default delivered over TLS/SSL,” Adobe shared. The vulnerability is not actively exploited.
Users should keep in mind that Flash will reach end-of-life (EOL) by the end of the year, and think about whether the time has finally come to stop using the popular (but often targeted) media player.
Intel’s updates
Intel has also released just one advisory, warning about three vulnerabilities in the BlueZ Bluetooth protocol stack.
One (CVE-2020-12352) could be exploited for privilege escalation, the second one (CVE-2020-24490) for information disclosure, and the third one (CVE-2020-24490) can lead to DoS.
Intel advises affected users to update the Linux kernel to version 5.9 or later, or install kernel fixes released by BlueZ if they can’t perform a kernel update.
SAP’s updates
SAP marked the October 2020 Patch Tuesday by releasing 15 security notes and updates to 6 previously released ones.
The most critical patches are for SAP Solution Manager (an integrated end-to-end platform intended to assist users in adopting new developments, managing the application lifecycle, and running SAP solutions) and SAP Focused Run (a high-volume system and application monitoring, alerting, and analytics solution for service providers). Both incorporate the CA Introscope Enterprise Manager, which features:
- CVE-2020-6364 – An OS command injection vulnerability, and
- CVE-2020-6369 – Hard-coded credentials
Other patches have been provided for newly fixed flaws in a variety of offerings, including SAP NetWeaver, SAP Business Objects Business Intelligence Platform, SAP Landscape Management, SAP NetWeaver AS Java, SAP Commerce Cloud, and others.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2020/10/13/october-2020-patch-tuesday/