Microsoft’s October Patch Tuesday addresses 87 flaws

Microsoft’s October Patch Tuesday addresses 87 flaws

As part of its October Patch Tuesday, Microsoft has rolled out fixes for 87 vulnerabilities affecting Microsoft Windows, Office and Office Services and Web Apps, Azure Functions, Open Source Software, Exchange Server, Visual Studio, .NET Framework, Microsoft Dynamics, and the Windows Codecs Library. Of 87 flaws 11 are listed as critical, including one potentially wormable issue, while 75 bugs are classified as important.

One of the most severe bugs is a remote code-execution issue (CVE-2020-16898) in the TCP/IP stack, which allows attackers to execute arbitrary code with elevated privileges using a specially crafted ICMPv6 router advertisement.

Another notable flaw is an RCE vulnerability (CVE-2020-16947) impacting Microsoft Outlook. An attacker could use this flaw for remote code execution by tricking a user into viewing a specially crafted e-mail. The vulnerability exists due to a boundary error in the Microsoft Outlook software.

Meanwhile, a critical Windows Hyper-V RCE bug (CVE-2020-16891) allows an attacker to run a specially crafted program on an affected guest OS to execute arbitrary code on the host OS.

Other severe bugs include the issues in Windows Camera Codec (CVE-2020-16967 and CVE-2020-16968), RCE vulnerabilities in SharePoint Server (CVE-2020-16951 and CVE-2020-16952), Media Foundation Library (CVE-2020-16915), the Base3D rendering engine (CVE-2020-17003), Graphics components (CVE-2020-16923), and the Windows Graphics Device Interface (CVE-2020-16911).


Back to the list

Latest Posts

Cyber Security Week in Review: July 4, 2025

Cyber Security Week in Review: July 4, 2025

In brief: Google patches Chrome 0Day, the US is on the hunt for North Korean IT workers, and more.
4 July 2025
AI chatbots fall for phishing scams

AI chatbots fall for phishing scams

The models provided the correct URL only 66% of the time; nearly 30% of responses pointed users to dead or suspended domains.
3 July 2025
Chinese hackers exploited Ivanti flaws in attacks against French government

Chinese hackers exploited Ivanti flaws in attacks against French government

ANSSI believes that the Houken campaign is operated by ‘UNC5174’, an entity believed to act as an initial access broker for China’s Ministry of State Security.
2 July 2025