Patch Tuesday Archive
Patch Tuesday September 2020
Total CVEs
129
Critical
23
Important
105
Exploited
0
Publicly Disclosed
0
All CVEs this month 129
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2020-1345 | Microsoft Office SharePoint XSS Vulnerability | Important | 7.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1460 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Critical | 8.6 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1532 | Windows InstallService Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-16856 | Visual Studio Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio | - | - | - |
| CVE-2020-16857 | Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability | Critical | 7.1 |
Microsoft Dynamics | - | - | - |
| CVE-2020-16858 | Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2020-16859 | Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2020-16860 | Microsoft Dynamics 365 (on-premises) Remote Code Execution Vulnerability | Important | 6.8 |
Microsoft Dynamics | - | - | - |
| CVE-2020-16861 | Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2020-16862 | Microsoft Dynamics 365 (on-premises) Remote Code Execution Vulnerability | Critical | 7.1 |
Microsoft Dynamics | - | - | - |
| CVE-2020-16864 | Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2020-16872 | Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability | Important | 7.6 |
Microsoft Dynamics | - | - | - |
| CVE-2020-16878 | Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2020-16879 | Projected Filesystem Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Windows | - | - | - |
| CVE-2020-16881 | Visual Studio JSON Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio | - | - | - |
| CVE-2020-1376 | Windows Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1452 | Microsoft SharePoint Remote Code Execution Vulnerability | Critical | 8.6 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1453 | Microsoft SharePoint Remote Code Execution Vulnerability | Critical | 8.6 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1471 | Windows CloudExperienceHost Elevation of Privilege Vulnerability | Important | 7.3 |
Microsoft Windows | - | - | - |
| CVE-2020-1491 | Windows Function Discovery Service Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1506 | Windows Start-Up Application Elevation of Privilege Vulnerability | Important | 6.1 |
Internet Explorer | - | - | - |
| CVE-2020-1507 | Microsoft COM for Windows Elevation of Privilege Vulnerability | Important | 7.9 |
Microsoft Windows | - | - | - |
| CVE-2020-1508 | Windows Media Audio Decoder Remote Code Execution Vulnerability | Critical | 7.6 |
Microsoft Windows | - | - | - |
| CVE-2020-1559 | Windows Storage Services Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1575 | Microsoft Office SharePoint XSS Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1576 | Microsoft SharePoint Remote Code Execution Vulnerability | Critical | 8.5 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1589 | Windows Kernel Information Disclosure Vulnerability | Important | 4.4 |
Windows Kernel | - | - | - |
| CVE-2020-1590 | Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability | Important | 6.6 |
Microsoft Windows | - | - | - |
| CVE-2020-1592 | Windows Kernel Information Disclosure Vulnerability | Important | 4.4 |
Windows Kernel | - | - | - |
| CVE-2020-1593 | Windows Media Audio Decoder Remote Code Execution Vulnerability | Critical | 7.6 |
Microsoft Windows | - | - | - |
| CVE-2020-1596 | TLS Information Disclosure Vulnerability | Important | 5.4 |
Microsoft Windows | - | - | - |
| CVE-2020-1598 | Windows UPnP Service Elevation of Privilege Vulnerability | Important | 6.1 |
Microsoft Windows | - | - | - |
| CVE-2020-0648 | Windows RSoP Service Application Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-0664 | Active Directory Information Disclosure Vulnerability | Important | 6.5 |
Windows Active Directory | - | - | - |
| CVE-2020-0718 | Active Directory Remote Code Execution Vulnerability | Important | 8.8 |
Windows Active Directory | - | - | - |
| CVE-2020-0761 | Active Directory Remote Code Execution Vulnerability | Important | 8.8 |
Windows Active Directory | - | - | - |
| CVE-2020-0766 | Microsoft Store Runtime Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-0782 | Windows Cryptographic Catalog Services Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-0790 | Microsoft splwow64 Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-0805 | Projected Filesystem Security Feature Bypass Vulnerability | Important | 5.3 |
Microsoft Windows | - | - | - |
| CVE-2020-0836 | Windows DNS Denial of Service Vulnerability | Important | 7.5 |
Microsoft Windows DNS | - | - | - |
| CVE-2020-0837 | ADFS MFA Elevation of Privilege Vulnerability | Important | 5 |
Active Directory Federation Services | - | - | - |
| CVE-2020-0838 | NTFS Elevation of Privilege Vulnerability | Important | 7.8 |
Windows NTFS | - | - | - |
| CVE-2020-0839 | Windows dnsrslvr.dll Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows DNS | - | - | - |
| CVE-2020-0856 | Active Directory Information Disclosure Vulnerability | Important | 6.5 |
Windows Active Directory | - | - | - |
| CVE-2020-0870 | Shell infrastructure component Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Shell | - | - | - |
| CVE-2020-0875 | Microsoft splwow64 Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Windows | - | - | - |
| CVE-2020-0878 | Microsoft Browser Memory Corruption Vulnerability | Critical | 4.2 |
Microsoft Browsers | - | - | - |
| CVE-2020-0886 | Windows Storage Services Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-0890 | Windows Hyper-V Denial of Service Vulnerability | Important | 6.5 |
Windows Hyper-V | - | - | - |
| CVE-2020-0904 | Windows Hyper-V Denial of Service Vulnerability | Important | 6.5 |
Windows Hyper-V | - | - | - |
| CVE-2020-0908 | Windows Text Service Module Remote Code Execution Vulnerability | Critical | 7.5 |
Microsoft Windows | - | - | - |
| CVE-2020-0911 | Windows Modules Installer Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-0912 | Windows Function Discovery SSDP Provider Elevation of Privilege Vulnerability | Important | 7 |
Microsoft Windows | - | - | - |
| CVE-2020-0914 | Windows State Repository Service Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Windows | - | - | - |
| CVE-2020-0921 | Microsoft Graphics Component Denial of Service Vulnerability | Important | 5.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-0922 | Microsoft COM for Windows Remote Code Execution Vulnerability | Critical | 8.8 |
Microsoft Windows | - | - | - |
| CVE-2020-0928 | Windows Kernel Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2020-0941 | Win32k Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2020-0951 | Windows Defender Application Control Security Feature Bypass Vulnerability | Important | 6.7 |
Microsoft Windows | - | - | - |
| CVE-2020-0989 | Windows Mobile Device Management Diagnostics Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Windows | - | - | - |
| CVE-2020-0997 | Windows Camera Codec Pack Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2020-0998 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-1012 | WinINet API Elevation of Privilege Vulnerability | Important | 8.8 |
Internet Explorer | - | - | - |
| CVE-2020-1013 | Group Policy Elevation of Privilege Vulnerability | Important | 7.5 |
Microsoft Windows | - | - | - |
| CVE-2020-1030 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Print Spooler Components | - | - | - |
| CVE-2020-1031 | Windows DHCP Server Information Disclosure Vulnerability | Important | 7.5 |
Windows DHCP Server | - | - | - |
| CVE-2020-1033 | Windows Kernel Information Disclosure Vulnerability | Important | 4 |
Windows Kernel | - | - | - |
| CVE-2020-1034 | Windows Kernel Elevation of Privilege Vulnerability | Important | 6.8 |
Windows Kernel | - | - | - |
| CVE-2020-1038 | Windows Routing Utilities Denial of Service | Important | 5.5 |
Microsoft Windows | - | - | - |
| CVE-2020-1039 | Jet Database Engine Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft JET Database Engine | - | - | - |
| CVE-2020-1044 | SQL Server Reporting Services Security Feature Bypass Vulnerability | Moderate | 4.3 |
SQL Server | - | - | - |
| CVE-2020-1045 | Microsoft ASP.NET Core Security Feature Bypass Vulnerability | Important | 7.5 |
ASP.NET | - | - | - |
| CVE-2020-1052 | Windows Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1053 | DirectX Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-1057 | Scripting Engine Memory Corruption Vulnerability | Critical | 4.2 |
Microsoft Scripting Engine | - | - | - |
| CVE-2020-1074 | Jet Database Engine Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft JET Database Engine | - | - | - |
| CVE-2020-1083 | Microsoft Graphics Component Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-1091 | Windows Graphics Component Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-1097 | Windows Graphics Component Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-1098 | Windows Shell Infrastructure Component Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1115 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | - | - | - |
| CVE-2020-1119 | Windows Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Windows | - | - | - |
| CVE-2020-1122 | Windows Language Pack Installer Elevation of Privilege Vulnerability | Important | 5.5 |
Microsoft Windows | - | - | - |
| CVE-2020-1129 | Microsoft Windows Codecs Library Remote Code Execution Vulnerability | Critical | 8.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2020-1130 | Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Diagnostic Hub | - | - | - |
| CVE-2020-1133 | Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability | Important | 5.5 |
Windows Diagnostic Hub | - | - | - |
| CVE-2020-1146 | Microsoft Store Runtime Elevation of Privilege Vulnerability | Important | 6.6 |
Microsoft Windows | - | - | - |
| CVE-2020-1152 | Windows Win32k Elevation of Privilege Vulnerability | Important | 5.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-1159 | Windows Elevation of Privilege Vulnerability | Important | 6.6 |
Microsoft Windows | - | - | - |
| CVE-2020-1169 | Windows Runtime Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1172 | Scripting Engine Memory Corruption Vulnerability | Critical | 4.2 |
Microsoft Scripting Engine | - | - | - |
| CVE-2020-1180 | Scripting Engine Memory Corruption Vulnerability | Important | 4.2 |
Microsoft Scripting Engine | - | - | - |
| CVE-2020-1193 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2020-1198 | Microsoft Office SharePoint XSS Vulnerability | Important | 7.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1200 | Microsoft SharePoint Remote Code Execution Vulnerability | Critical | 8.6 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1205 | Microsoft SharePoint Spoofing Vulnerability | Important | 4.6 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1210 | Microsoft SharePoint Remote Code Execution Vulnerability | Critical | 9.9 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1218 | Microsoft Word Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2020-1224 | Microsoft Excel Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Office | - | - | - |
| CVE-2020-1227 | Microsoft Office SharePoint XSS Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1228 | Windows DNS Denial of Service Vulnerability | Important | 7.5 |
Microsoft Windows DNS | - | - | - |
| CVE-2020-1245 | Win32k Elevation of Privilege Vulnerability | Important | 7 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-1250 | Win32k Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-1252 | Windows Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-1256 | Windows GDI Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-1285 | GDI+ Remote Code Execution Vulnerability | Critical | 8.4 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-1303 | Windows Runtime Elevation of Privilege Vulnerability | Important | 5.5 |
Microsoft Windows | - | - | - |
| CVE-2020-1308 | DirectX Elevation of Privilege Vulnerability | Important | 7 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-1319 | Microsoft Windows Codecs Library Remote Code Execution Vulnerability | Critical | 7.3 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2020-1332 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2020-1335 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2020-1338 | Microsoft Word Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2020-1440 | Microsoft SharePoint Server Tampering Vulnerability | Important | 6.3 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1482 | Microsoft Office SharePoint XSS Vulnerability | Important | 6.3 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1514 | Microsoft Office SharePoint XSS Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1523 | Microsoft SharePoint Server Tampering Vulnerability | Important | 8.9 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-1594 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2020-1595 | Microsoft SharePoint Remote Code Execution Vulnerability | Critical | 9.9 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-16851 | OneDrive for Windows Elevation of Privilege Vulnerability | Important | 7.1 |
Microsoft OneDrive | - | - | - |
| CVE-2020-16852 | OneDrive for Windows Elevation of Privilege Vulnerability | Important | 7.1 |
Microsoft OneDrive | - | - | - |
| CVE-2020-16853 | OneDrive for Windows Elevation of Privilege Vulnerability | Important | 7.1 |
Microsoft OneDrive | - | - | - |
| CVE-2020-16854 | Windows Kernel Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2020-16855 | Microsoft Office Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Office | - | - | - |
| CVE-2020-16871 | Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2020-16873 | Xamarin.Forms Spoofing Vulnerability | Important | 4.7 |
Open Source Software | - | - | - |
| CVE-2020-16874 | Visual Studio Remote Code Execution Vulnerability | Critical | 7.8 |
Visual Studio | - | - | - |
| CVE-2020-16875 | Microsoft Exchange Server Remote Code Execution Vulnerability | Critical | 8.4 |
Microsoft Exchange Server | - | - | - |
| CVE-2020-16884 | Internet Explorer Browser Helper Object (BHO) Memory Corruption Vulnerability | Important | 4.2 |
Internet Explorer | - | - | - |
Threat Categories 7
| Threat Category | CVEs | Critical |
|---|---|---|
| Elevation of Privilege | 42 | - |
| Remote Code Execution | 38 | 23 |
| Information Disclosure | 23 | - |
| Spoofing | 15 | - |
| Denial of Service | 5 | - |
| Security Feature Bypass | 4 | - |
| Tampering | 2 | - |
Affected Products 27
| Product | CVEs | Exploited |
|---|---|---|
| Microsoft Windows | 37 | - |
| Microsoft Office SharePoint | 16 | - |
| Microsoft Graphics Component | 12 | - |
| Microsoft Dynamics | 10 | - |
| Microsoft Office | 8 | - |
| Windows Kernel | 7 | - |
| Windows Active Directory | 4 | - |
| Internet Explorer | 3 | - |
| Microsoft OneDrive | 3 | - |
| Microsoft Scripting Engine | 3 | - |
| Microsoft Windows Codecs Library | 3 | - |
| Microsoft Windows DNS | 3 | - |
| Visual Studio | 3 | - |
| Microsoft JET Database Engine | 2 | - |
| Windows Diagnostic Hub | 2 | - |
| Windows Hyper-V | 2 | - |
| ASP.NET | 1 | - |
| Active Directory Federation Services | 1 | - |
| Microsoft Browsers | 1 | - |
| Microsoft Exchange Server | 1 | - |
| Open Source Software | 1 | - |
| SQL Server | 1 | - |
| Windows Common Log File System Driver | 1 | - |
| Windows DHCP Server | 1 | - |
| Windows NTFS | 1 | - |
| Windows Print Spooler Components | 1 | - |
| Windows Shell | 1 | - |