Microsoft Office September Security Updates Fix Critical RCE Bugs
Microsoft has released the September 2020 Office security updates with a total of 30 security updates and 5 cumulative updates for 7 different products, fixing 13 vulnerabilities that could enable remote attackers to execute arbitrary code on vulnerable systems.
Redmond also issued the September 2020 Patch Tuesday security updates, with security updates for 129 vulnerabilities, 23 rated of them as Critical and 105 as Important.
Non-security Windows updates with fixes and improvements were also released yesterday with the Windows 10 KB4571756 & KB4574727 cumulative updates.
Microsoft published the September 2020 non-security Microsoft Office updates on September 2 changing the default fallback encryption for Microsoft Outlook 2016 from 3DES to AES256.
Microsoft Office security issues addressed in this month
Some of the Office security update published by Microsoft as part of the September 2020 Patch Tuesday address security issues that could allow remote code execution (RCE) on Windows systems running vulnerable Click to Run and Microsoft Installer (.msi)-based editions of Microsoft Office products.
The 13 RCE vulnerabilities patched this month are rated by Microsoft as Critical or Important severity issues since they may enable attackers to execute arbitrary code in the context of the current user following successful exploitation.
The attackers could then install malicious programs, view, change, and delete data, as well as create their own rogue Windows admin accounts on the compromised Windows devices.
All September 2020 Patch Tuesday Microsoft Office security advisories:
Tag | CVE ID | Title | Severity |
Microsoft Office | CVE-2020-1594 | Microsoft Excel Remote Code Execution Vulnerability | Important |
Microsoft Office | CVE-2020-1335 | Microsoft Excel Remote Code Execution Vulnerability | Important |
Microsoft Office | CVE-2020-16855 | Microsoft Office Information Disclosure Vulnerability | Important |
Microsoft Office | CVE-2020-1338 | Microsoft Word Remote Code Execution Vulnerability | Important |
Microsoft Office | CVE-2020-1332 | Microsoft Excel Remote Code Execution Vulnerability | Important |
Microsoft Office | CVE-2020-1224 | Microsoft Excel Information Disclosure Vulnerability | Important |
Microsoft Office | CVE-2020-1218 | Microsoft Word Remote Code Execution Vulnerability | Important |
Microsoft Office | CVE-2020-1193 | Microsoft Excel Remote Code Execution Vulnerability | Important |
Microsoft Office SharePoint | CVE-2020-1345 | Microsoft Office SharePoint XSS Vulnerability | Important |
Microsoft Office SharePoint | CVE-2020-1205 | Microsoft SharePoint Spoofing Vulnerability | Important |
Microsoft Office SharePoint | CVE-2020-1210 | Microsoft SharePoint Remote Code Execution Vulnerability | Critical |
Microsoft Office SharePoint | CVE-2020-1514 | Microsoft Office SharePoint XSS Vulnerability | Important |
Microsoft Office SharePoint | CVE-2020-1595 | Microsoft SharePoint Remote Code Execution Vulnerability | Critical |
Microsoft Office SharePoint | CVE-2020-1523 | Microsoft SharePoint Server Tampering Vulnerability | Important |
Microsoft Office SharePoint | CVE-2020-1440 | Microsoft SharePoint Server Tampering Vulnerability | Important |
Microsoft Office SharePoint | CVE-2020-1200 | Microsoft SharePoint Remote Code Execution Vulnerability | Critical |
Microsoft Office SharePoint | CVE-2020-1482 | Microsoft Office SharePoint XSS Vulnerability | Important |
Microsoft Office SharePoint | CVE-2020-1198 | Microsoft Office SharePoint XSS Vulnerability | Important |
Microsoft Office SharePoint | CVE-2020-1227 | Microsoft Office SharePoint XSS Vulnerability | Important |
Microsoft Office SharePoint | CVE-2020-1576 | Microsoft SharePoint Remote Code Execution Vulnerability | Critical |
Microsoft Office SharePoint | CVE-2020-1452 | Microsoft SharePoint Remote Code Execution Vulnerability | Critical |
Microsoft Office SharePoint | CVE-2020-1575 | Microsoft Office SharePoint XSS Vulnerability | Important |
Microsoft Office SharePoint | CVE-2020-1453 | Microsoft SharePoint Remote Code Execution Vulnerability | Critical |
Microsoft Office SharePoint | CVE-2020-1460 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Critical |
September 2020 Microsoft Office security updates
This month’s Microsoft Office security updates are delivered via the Download Center and through the Microsoft Update platform.
Additional information about each of them including CVE IDs is available within the knowledge base articles linked below.
To download the September 2020 Microsoft Office security updates, click on the corresponding knowledge base article below and then scroll down to the ‘How to download and install the update‘ section to grab the updates for your Office product.
Microsoft Office 2016
Product | Knowledge Base article title and number |
---|---|
Excel 2016 | Security update for Excel 2016: September 8, 2020 (KB4484507) |
Office 2016 | Security update for Office 2016: September 8, 2020 (KB4484513) |
Office 2016 | Security update for Office 2016: September 8, 2020 (KB4484466) |
Word 2016 | Security update for Word 2016: September 8, 2020 (KB4484510) |
Microsoft Office 2013
Product | Knowledge Base article title and number |
---|---|
Excel 2013 | Security update for Excel 2013: September 8, 2020 (KB4484526) |
Office 2013 | Security update for Office 2013: September 8, 2020 (KB4484517) |
Office 2013 | Security update for Office 2013: September 8, 2020 (KB4484469) |
Word 2013 | Security update for Word 2013: September 8, 2020 (KB4484522) |
Microsoft Office 2010
Product | Knowledge Base article title and number |
---|---|
Excel 2010 | Security update for Excel 2010: September 8, 2020 (KB4486665) |
Office 2010 | Security update for Office 2010: September 8, 2020 (KB4484532) |
Office 2010 | Security update for Office 2010: September 8, 2020 (KB4484530) |
Office 2010 | Security update for Office 2010: September 8, 2020 (KB4484533) |
Word 2010 | Security update for Word 2010: September 8, 2020 (KB4486660) |
Microsoft SharePoint Server 2019
Product | Knowledge Base article title and number |
---|---|
Office Online Server | Security update for Office Online Server: September 8, 2020 (KB4484503) |
SharePoint Server 2019 | Security update for SharePoint Server 2019: September 8, 2020 (KB4484505) |
SharePoint Server 2019 Language Pack | Security update for SharePoint Server 2019 Language Pack: September 8, 2020 (KB4484504) |
Microsoft SharePoint Server 2016
Product | Knowledge Base article title and number |
---|---|
SharePoint Enterprise Server 2016 | Security update for SharePoint Enterprise Server 2016: September 8, 2020 (KB4484506) |
SharePoint Enterprise Server 2016 | Security update for SharePoint Enterprise Server 2016: September 8, 2020 (KB4484512) |
Also read: 5 Self Assessment Tools To Find The Right Professional Fit
Microsoft SharePoint Server 2013
Microsoft SharePoint Server 2010
Product | Knowledge Base article title and number |
---|---|
Project Server 2010 | Cumulative update for Project Server 2010 (KB4484535) |
SharePoint Foundation 2010 | Security update for SharePoint Foundation 2010: September 8, 2020 (KB4486667) |
SharePoint Server 2010 | Security update for SharePoint Server 2010: September 8, 2020 (KB4486664) |
SharePoint Server 2010 | Security update for SharePoint Server 2010: September 8, 2020 (KB4484528) |
SharePoint Server 2010 | Security update for SharePoint Server 2010: September 8, 2020 (KB3101523) |
SharePoint Server 2010 | Cumulative update for SharePoint Server 2010 (KB4486662) |
SharePoint Server 2010 Office Web Apps | Security update for SharePoint Server 2010 Office Web Apps: September 8, 2020 (KB4486661) |
Also read: Data Centre Regulations Singapore: Does It Help To Progress?
0 Comments