ZeroHour
Security Affairspublished ()ingested @securityaffairs

Microsoft September 2020 Patch Tuesday addresses 129 flaws

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-0922
+2 in the same advisory: …1129 …0908
A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles objects in memory.

A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have to open a specially crafted file or lure the target to a website hosting malicious JavaScript. The security update addresses the vulnerability by correcting how Microsoft COM for Windows handles objects in memory.

NVD description · AI analysis pending
8.8
group max
5%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2020-16875
A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.

A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. Exploitation of the vulnerability requires an authenticated user in a certain Exchange role to be compromised. The security update addresses the vulnerability by correcting how Microsoft Exchange handles cmdlet arguments.

NVD description · AI analysis pending
8.447% PoC
  • microsoft exchange server
Full article308 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 09, 2020

Microsoft September 2020 Patch Tuesday security updates address 129 vulnerabilities, including twenty critical remote code execution issues.

Microsoft September 2020 Patch Tuesday security updates address 129 vulnerabilities in Microsoft products across 15 products (Microsoft Windows, Edge (EdgeHTML-based and Chromium-based), ChakraCore, Internet Explorer (IE), SQL Server, Office and Office Services and Web Apps, Microsoft Dynamics, Visual Studio, Exchange Server, ASP.NET, OneDrive, and Azure DevOps).

23 vulnerabilities are classified as Critical, and 105 are classified as Important, and one 1 as moderate, none of the addressed issues is a zero-day flaw.

Some of the most severe flaws are:

None of the vulnerabilities addressed by Microsoft under active attack at the time of release.

The full list of vulnerabilities addressed by the September 2020 Patch Tuesday Security Updates is available here.

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Microsoft September 2020 Patch Tuesday)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/108071/security/microsoft-sep-2020-patch-tuesday.html