{"id":16532,"date":"2020-11-01T02:35:56","date_gmt":"2020-11-01T01:35:56","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=16532"},"modified":"2022-10-09T22:23:54","modified_gmt":"2022-10-09T20:23:54","slug":"nachtrag-microsoft-sicherheitshinweise-oktober-2020","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2020\/11\/01\/nachtrag-microsoft-sicherheitshinweise-oktober-2020\/","title":{"rendered":"Addendum: Microsoft Security Advisories October 2020"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" align=\"left\" height=\"47\">[<a href=\"https:\/\/www.borncity.com\/blog\/2020\/11\/01\/nachtrag-microsoft-sicherheitshinweise-oktober-2020\/\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]Small addendum from October 2020: Microsoft had published some security advices for security updates. They have been left here, I will post them here for security reasons.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/vg06.met.vgwort.de\/na\/c360f6b1537e4c6e8df1686598c8182d\" width=\"1\" height=\"1\">**************************************************************************************<br \/>Title: Microsoft Security Update Releases<br \/>Issued: October 13, 2020<br \/>**************************************************************************************<\/p>\n<p>Summary<br \/>=======<\/p>\n<p>The following CVEs have undergone a major revision increment:<\/p>\n<p>* CVE-2019-1181<br \/>* CVE-2019-1182<br \/>* CVE-2020-1147<br \/>&nbsp;<\/p>\n<p>Revision Information:<br \/>=====================<\/p>\n<p>* CVE-2019-1181<\/p>\n<p>&#8211; <a href=\"https:\/\/web.archive.org\/web\/20200822151312\/https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-1181\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2019-1181<\/a> | Remote Desktop Services Remote Code Execution Vulnerability- <br \/>&#8211; Version 2.0<br \/>&#8211; Reason for Revision: Revised the Security Updates table to add Microsoft Remote <br \/>&nbsp;&nbsp; Desktop for Android, Microsoft Remote Desktop for Mac, and Microsoft Remote Desktop <br \/>&nbsp;&nbsp; for Mac IoS because these apps are affected by this vulnerability. Microsoft<br \/>&nbsp;&nbsp; recommends that customers running any of these apps install the latest security<br \/>&nbsp;&nbsp; update to be fully protected from this vulnerability. Please see the FAQ section<br \/>&nbsp;&nbsp; for information on how to get these updates.<br \/>&#8211; Originally posted: August 13, 2020<br \/>&#8211; Updated: October 13, 2020<br \/>&#8211; Aggregate CVE Severity Rating: Critical<\/p>\n<p>* CVE-2019-1182<\/p>\n<p>&#8211; <a href=\"https:\/\/web.archive.org\/web\/20201030125040\/https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/CVE-2019-1182\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2019-1182<\/a> | Remote Desktop Services Remote Code Execution Vulnerability<br \/>&#8211; Version 2.0<br \/>&#8211; Reason for Revision: Revised the Security Updates table to add Microsoft Remote <br \/>&nbsp;&nbsp; Desktop for Android, Microsoft Remote Desktop for Mac, and Microsoft Remote Desktop <br \/>&nbsp;&nbsp; for Mac IoS because these apps are affected by this vulnerability. Microsoft<br \/>&nbsp;&nbsp; recommends that customers running any of these apps install the latest security<br \/>&nbsp;&nbsp; update to be fully protected from this vulnerability. Please see the FAQ section<br \/>&nbsp;&nbsp; for information on how to get these updates.<br \/>&#8211; Originally posted: August 13, 2020<br \/>&#8211; Updated: October 13, 2020<br \/>&#8211; Aggregate CVE Severity Rating: Critical<\/p>\n<p>* CVE-2020-1147<\/p>\n<p>&#8211; <a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/CVE-2020-1147\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2020-1147<\/a> | .NET Framework, SharePoint Server, and Visual Studio Remote Code<br \/>&nbsp;&nbsp; Execution Vulnerability<br \/>&#8211; Version 2.0<br \/>&#8211; Reason for Revision: To comprehensively address CVE-2020-1147, Microsoft has released<br \/>&nbsp;&nbsp; the following: October Security Updates for all affected versions of .NET Framework<br \/>&nbsp;&nbsp; installed on Windows 10; October 2020 Monthly Rollup updates AND updated versions of<br \/>&nbsp;&nbsp; the Security Only updates released in July 2020 for all affected versions of .NET<br \/>&nbsp;&nbsp; Framework installed on Windows 8.1, Windows Server 2012 R2, Windows Server 2012,<br \/>&nbsp;&nbsp; Windows 7, Windows Server 2008 R2, and Windows Server 2008. Microsoft strongly<br \/>&nbsp;&nbsp; recommends that customers install the updates to be fully protected from the<br \/>&nbsp;&nbsp; vulnerability. Customers who install the Security Only updates should ensure that<br \/>&nbsp;&nbsp; they re-install the updates after October 13. Customers whose systems are configured<br \/>&nbsp;&nbsp; to receive automatic updates do not need to take any further action.<br \/>&#8211; Originally posted: July 14, 2020<br \/>&#8211; Updated: October 13, 2020<br \/>&#8211; Aggregate CVE Severity Rating: Critical<\/p>\n<p>**************************************************************************************<br \/>Title: Microsoft Security Update Releases<br \/>Issued: October 15, 2020<br \/>**************************************************************************************<\/p>\n<p>Summary<br \/>=======<\/p>\n<p>The following CVEs have undergone a major revision increment:<\/p>\n<p>* CVE-2020-16943<br \/>* CVE-2020-17022<br \/>* CVE-2020-17023<br \/>&nbsp;<\/p>\n<p>Revision Information:<br \/>=====================<\/p>\n<p>* CVE-2020-16943<\/p>\n<p>&#8211; <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2020-16943\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2020-16943<\/a> | Dynamics 365 Commerce Elevation of Privilege Vulnerability<br \/>&#8211; Version 2.0<br \/>&#8211; Reason for Revision: In the Security Updates table, removed the Article and Download<br \/>&nbsp;&nbsp; links because an update is not yet available for Dynamics 365 Commerce. Customers<br \/>&nbsp;&nbsp; will be notified via a revision to this CVE information when an update becomes<br \/>&nbsp;&nbsp; available.<br \/>&#8211; Originally posted: October 13, 2020<br \/>&#8211; Updated: October 13, 2020<br \/>&#8211; Aggregate CVE Severity Rating: Important<\/p>\n<p>* CVE-2020-17022<\/p>\n<p>&#8211; <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\/vulnerability\/CVE-2020-17022CVE-2020-17022\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2020-17022<\/a> | Remote Desktop Services Remote Code Execution Vulnerability<br \/>&#8211; Version 1.0<br \/>&#8211; Reason for Revision: Information published.<br \/>&#8211; Originally posted: October 15, 2020<br \/>&#8211; Updated: N\/A<br \/>&#8211; Aggregate CVE Severity Rating: Important<\/p>\n<p>* CVE-2020-17023<\/p>\n<p>&#8211; <a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/CVE-2020-17023\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2020-17023<\/a> | Visual Studio JSON Remote Code Execution Vulnerability<br \/>&#8211; Version 1.0<br \/>&#8211; Reason for Revision: Information published.<br \/>&#8211; Originally posted: October 15, 2020<br \/>&#8211; Updated: N\/A<br \/>&#8211; Aggregate CVE Severity Rating: Important<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Small addendum from October 2020: Microsoft had published some security advices for security updates. They have been left here, I will post them here for security reasons.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580],"tags":[69],"class_list":["post-16532","post","type-post","status-publish","format-standard","hentry","category-security","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/16532","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=16532"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/16532\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=16532"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=16532"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=16532"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}