Geeks for your information
Microsoft Office April security updates fix critical RCE bugs - Printable Version

+- Geeks for your information (https://www.geeks.fyi)
+-- Forum: News (https://www.geeks.fyi/forumdisplay.php?fid=105)
+--- Forum: Microsoft Windows News (https://www.geeks.fyi/forumdisplay.php?fid=32)
+--- Thread: Microsoft Office April security updates fix critical RCE bugs (/showthread.php?tid=11088)



Microsoft Office April security updates fix critical RCE bugs - silversurfer - 15 April 20

Quote:Microsoft released the April 2020 Office security updates on April 14, 2020, with a total of 55 security updates and 5 cumulative updates for 7 different products, and patching 5 critical bugs allowing attackers to run scripts as the current user and remotely execute arbitrary code on unpatched systems.
 
Out of the 55 Office security updates released by Microsoft today, 12 of them patch remote code execution (RCE) vulnerabilities (details in ​​​​​​CVE-2020-0931CVE-2020-0932CVE-2020-0929CVE-2020-0974CVE-2020-0979CVE-2020-0980CVE-2020-0760CVE-2020-0991CVE-2020-0961CVE-2020-0906CVE-2020-0920, and CVE-2020-0971) within Microsoft Office and Microsoft Office SharePoint products.
 
The RCE bugs are rated by Microsoft with Critical and Important severity ratings as they could allow attackers to execute arbitrary code in the context of the SharePoint app pool and the SharePoint server farm account after successfully exploiting Windows devices running unpatched Office products.
 
Attackers could then install programs, view, change, and delete data, as well as create new accounts with full user rights on the compromised computers.
 
10 cross-site-scripting (XSS) vulnerabilities (details in CVE-2020-0927CVE-2020-0923CVE-2020-0925CVE-2020-0924CVE-2020-0930CVE-2020-0933CVE-2020-0978CVE-2020-0973CVE-2020-0926, and CVE-2020-0954) were also fixed to prevent attackers from running scripts in the security context of the current user and impersonate the user, steal sensitive data, or read content without authorization.
 
Microsoft also patched two elevation of privilege security flaws (details in CVE-2020-0984 and CVE-2020-0935) and four spoofing vulnerabilities (CVE-2020-0975CVE-2020-0977CVE-2020-0976, and CVE-2020-0972).

Read more: https://www.bleepingcomputer.com/news/security/microsoft-office-april-security-updates-fix-critical-rce-bugs/