fbpx
Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Penetration Testing

          Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

Office November Security Updates Fix Remote Code Execution Bugs

Office November Security Updates Fix Remote Code Execution Bugs

Microsoft has released the November 2020 Office security updates with a total of 22 updates and 5 cumulative updates for 7 different products, fixing 14 vulnerabilities with five of them potentially enabling remote attackers to execute arbitrary code on vulnerable systems.

The highlight of this month’s Office security updates is CVE-2020-17061, a high severity Microsoft SharePoint vulnerability discovered by Oleksandr Mirosh from Micro Focus Fortify that leads to remote code execution (RCE).

Attackers could exploit this RCE bug remotely over the Internet in low complexity attacks, requiring only low user privileges and no user interaction for successful exploitation.

CVE-2020-17061 affects several Microsoft SharePoint versions including Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Foundation 2013 Service Pack 1, and Microsoft SharePoint Foundation 2010 Service Pack 2.

List of Office security issues fixed this month

The November 2020 Patch Tuesday Office security updates address remote code execution (RCE), security bypass, elevation of privilege, information disclosure, spoofing, and online spoofing vulnerabilities.

Also Read: 15 Best Tools For Your Windows 10 Privacy Settings Setup

The flaws impact Windows systems running vulnerable Microsoft Installer (.msi) and Click to Run editions of Microsoft Office products.

Microsoft rated the five RCE security flaws patched this month as Important severity issues given that they could enable attackers to execute arbitrary code in the context of the currently logged-in user.

Following successful exploitation, the attackers could install malicious programs, view, change, and delete data, as well as create their own admin accounts on compromised Windows devices.

TagCVE IDCVE TitleSeverity
Microsoft OfficeCVE-2020-17065Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2020-17064Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2020-17066Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2020-17019Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2020-17067Microsoft Excel Security Feature Bypass VulnerabilityImportant
Microsoft OfficeCVE-2020-17062Microsoft Office Access Connectivity Engine Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2020-17063Microsoft Office Online Spoofing VulnerabilityImportant
Microsoft OfficeCVE-2020-17020Microsoft Word Security Feature Bypass VulnerabilityImportant
Microsoft Office SharePointCVE-2020-17016Microsoft SharePoint Spoofing VulnerabilityImportant
Microsoft Office SharePointCVE-2020-16979Microsoft SharePoint Information Disclosure VulnerabilityImportant
Microsoft Office SharePointCVE-2020-17015Microsoft SharePoint Spoofing VulnerabilityLow
Microsoft Office SharePointCVE-2020-17017Microsoft SharePoint Information Disclosure VulnerabilityImportant
Microsoft Office SharePointCVE-2020-17061Microsoft SharePoint Remote Code Execution VulnerabilityImportant
Microsoft Office SharePointCVE-2020-17060Microsoft SharePoint Spoofing VulnerabilityImportant

November 2020 Microsoft Office security updates

This month’s Microsoft Office security updates are delivered through the Download Center and via the Microsoft Update platform.

To install one of the security updates, click on their corresponding knowledge base article below and then scroll down to the ‘How to download and install the update‘ section to download the updates for your Office product.

Additional information including CVE IDs assigned to each vulnerability is available within the knowledge base articles linked below.

Microsoft Office 2016

ProductKnowledge Base article
Excel 2016Security update for Excel 2016 (KB4486718)
Office 2016Security update for Office 2016 (KB4484508)
Office 2016Security update for Office 2016 (KB4486722)
Word 2016Security update for Word 2016 (KB4486719)

Microsoft Office 2013

ProductKnowledge Base article
Excel 2013Security update for Excel 2013 (KB4486734)
Office 2013Security update for Office 2013 (KB4486725)
Office 2013Security update for Office 2013 (KB4484520)
Word 2013Security update for Word 2013 (KB4486730)

Microsoft Office 2010

ProductKnowledge Base article
Excel 2010Security update for Excel 2010 (KB4486743)
Office 2010Security update for Office 2010 (KB4486737)
Office 2010Security update for Office 2010 (KB4486738)
Office 2010Security update for Office 2010 (KB4484534)
Office 2010Security update for Office 2010 (KB4484455)
Word 2010Security update for Word 2010 (KB4486740)

Microsoft SharePoint Server 2019

ProductKnowledge Base article
Office Online ServerSecurity update for Office Online Server (KB4486713)
SharePoint Server 2019Security update for SharePoint Server 2019 (KB4486714)

Microsoft SharePoint Server 2016

ProductKnowledge Base article
SharePoint Enterprise Server 2016Security update for SharePoint Enterprise Server 2016 (KB4486717)

Microsoft SharePoint Server 2013

ProductKnowledge Base article
Office Web Apps Server 2013Security update for Office Web Apps Server 2013 (KB4486733)
Project Server 2013Cumulative update for Project Server 2013 (KB4486729)
SharePoint Enterprise Server 2013Security update for SharePoint Enterprise Server 2013 (KB4486723)
SharePoint Enterprise Server 2013Cumulative update for SharePoint Enterprise Server 2013 (KB4486731)
SharePoint Foundation 2013Security update for SharePoint Foundation 2013 (KB4486733)
SharePoint Foundation 2013Cumulative update for SharePoint Foundation 2013 (KB4486728)

Microsoft SharePoint Server 2010

ProductKnowledge Base article title
Project Server 2010Cumulative update for Project Server 2010 (KB4486739)
SharePoint Foundation 2010Security update for SharePoint Foundation 2010 (KB4486744)
SharePoint Server 2010Security update for SharePoint Server 2010 (KB4486706)
SharePoint Server 2010Cumulative update for SharePoint Server 2010 (KB4486741)

Also Read: How To Secure Your WiFi Camera? 4 Points To Consider

November 2020 Patch Tuesday security updates

Yesterday, Microsoft also released the November 2020 Patch Tuesday security updates with security updates for 112 vulnerabilities, 17 of them being rated as critical, 93 as important, and two as moderate severity.

Non-security Windows updates containing bug fixes and feature improvements were also issued with the Windows 10 KB4586786 & KB4586781 Cumulative Updates.

As part of this month’s Patch Tuesday, Microsoft also addressed a Windows Kernel Cryptography Driver zero-day disclosed by Google last month and tracked as CVE-2020-17087.

The bug impacts computers running Windows 7 or later and it was detected last month by Google’s zero-day hunters while being exploited in targeted attacks.

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us