Patch Tuesday Archive
Patch Tuesday November 2020
Total CVEs
112
Critical
17
Important
93
Exploited
1
Publicly Disclosed
1
All CVEs this month 112
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2020-16979 | Microsoft SharePoint Information Disclosure Vulnerability | Important | 5.3 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-16997 | Remote Desktop Protocol Server Information Disclosure Vulnerability | Important | 7.7 |
Microsoft Windows | - | - | - |
| CVE-2020-16998 | DirectX Elevation of Privilege Vulnerability | Important | 7 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-16999 | Windows WalletService Information Disclosure Vulnerability | Important | 5.5 |
Windows WalletService | - | - | - |
| CVE-2020-17000 | Remote Desktop Protocol Client Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Windows | - | - | - |
| CVE-2020-17001 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-17004 | Windows Graphics Component Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-17019 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2020-17020 | Microsoft Word Security Feature Bypass Vulnerability | Important | 3.3 |
Microsoft Office | - | - | - |
| CVE-2020-17055 | Windows Remote Access Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-17056 | Windows Network File System Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Windows | - | - | - |
| CVE-2020-17057 | Windows Win32k Elevation of Privilege Vulnerability | Important | 7 |
Microsoft Windows | - | - | - |
| CVE-2020-17068 | Windows GDI+ Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-17069 | Windows NDIS Information Disclosure Vulnerability | Important | 5.5 |
Windows NDIS | - | - | - |
| CVE-2020-17070 | Windows Update Medic Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Update Stack | - | - | - |
| CVE-2020-17071 | Windows Delivery Optimization Information Disclosure Vulnerability | Important | 5.5 |
Windows Update Stack | - | - | - |
| CVE-2020-17073 | Windows Update Orchestrator Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Update Stack | - | - | - |
| CVE-2020-17074 | Windows Update Orchestrator Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Update Stack | - | - | - |
| CVE-2020-17075 | Windows USO Core Worker Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Update Stack | - | - | - |
| CVE-2020-17076 | Windows Update Orchestrator Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Update Stack | - | - | - |
| CVE-2020-17077 | Windows Update Stack Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Update Stack | - | - | - |
| CVE-2020-17078 | Raw Image Extension Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2020-17079 | Raw Image Extension Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2020-17087 | Windows Kernel Local Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | Yes | Yes | Yes |
| CVE-2020-17088 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | - | - | - |
| CVE-2020-17090 | Microsoft Defender for Endpoint Security Feature Bypass Vulnerability | Important | 5.3 |
Windows Defender | - | - | - |
| CVE-2020-17100 | Visual Studio Tampering Vulnerability | Important | 5.5 |
Visual Studio | - | - | - |
| CVE-2020-17101 | HEIF Image Extensions Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2020-17102 | WebP Image Extensions Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2020-17105 | AV1 Video Extension Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2020-17106 | HEVC Video Extensions Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2020-17107 | HEVC Video Extensions Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2020-17108 | HEVC Video Extensions Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2020-17109 | HEVC Video Extensions Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2020-17110 | HEVC Video Extensions Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2020-17113 | Windows Camera Codec Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2020-1599 | Windows Spoofing Vulnerability | Important | 5.5 |
Microsoft Windows | - | - | - |
| CVE-2020-17005 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2020-17006 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2020-17007 | Windows Error Reporting Elevation of Privilege Vulnerability | Important | 7 |
Microsoft Windows | - | - | - |
| CVE-2020-17010 | Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-17011 | Windows Port Class Library Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-17012 | Windows Bind Filter Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-17013 | Win32k Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Windows | - | - | - |
| CVE-2020-17014 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-16970 | Azure Sphere Unsigned Code Execution Vulnerability | Important | 8.1 |
Azure Sphere | - | - | - |
| CVE-2020-16981 | Azure Sphere Elevation of Privilege Vulnerability | Important | 6.1 |
Azure Sphere | - | - | - |
| CVE-2020-16982 | Azure Sphere Unsigned Code Execution Vulnerability | Important | 6.1 |
Azure Sphere | - | - | - |
| CVE-2020-16983 | Azure Sphere Tampering Vulnerability | Important | 5.7 |
Azure Sphere | - | - | - |
| CVE-2020-16984 | Azure Sphere Unsigned Code Execution Vulnerability | Important | 7.3 |
Azure Sphere | - | - | - |
| CVE-2020-16985 | Azure Sphere Information Disclosure Vulnerability | Important | 6.2 |
Azure Sphere | - | - | - |
| CVE-2020-16986 | Azure Sphere Denial of Service Vulnerability | Important | 6.2 |
Azure Sphere | - | - | - |
| CVE-2020-16987 | Azure Sphere Unsigned Code Execution Vulnerability | Important | 7.3 |
Azure Sphere | - | - | - |
| CVE-2020-16988 | Azure Sphere Elevation of Privilege Vulnerability | Critical | 6.9 |
Azure Sphere | - | - | - |
| CVE-2020-16989 | Azure Sphere Elevation of Privilege Vulnerability | Important | 5.4 |
Azure Sphere | - | - | - |
| CVE-2020-16990 | Azure Sphere Information Disclosure Vulnerability | Important | 6.2 |
Azure Sphere | - | - | - |
| CVE-2020-16991 | Azure Sphere Unsigned Code Execution Vulnerability | Important | 7.3 |
Azure Sphere | - | - | - |
| CVE-2020-16992 | Azure Sphere Elevation of Privilege Vulnerability | Important | 7.5 |
Azure Sphere | - | - | - |
| CVE-2020-16994 | Azure Sphere Unsigned Code Execution Vulnerability | Important | 7.3 |
Azure Sphere | - | - | - |
| CVE-2020-16993 | Azure Sphere Elevation of Privilege Vulnerability | Important | 5.4 |
Azure Sphere | - | - | - |
| CVE-2020-17015 | Microsoft SharePoint Server Spoofing Vulnerability | Low | 4.3 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-17016 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-17017 | Microsoft SharePoint Information Disclosure Vulnerability | Important | 5.3 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-17018 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2020-17021 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2020-17024 | Windows Client Side Rendering Print Provider Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-17025 | Windows Remote Access Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-17026 | Windows Remote Access Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-17027 | Windows Remote Access Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-17028 | Windows Remote Access Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-17029 | Windows Canonical Display Driver Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-17030 | Windows MSCTF Server Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Windows | - | - | - |
| CVE-2020-17031 | Windows Remote Access Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-17032 | Windows Remote Access Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-17033 | Windows Remote Access Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-17034 | Windows Remote Access Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-17035 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2020-17036 | Windows Function Discovery SSDP Provider Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Windows | - | - | - |
| CVE-2020-17037 | Windows WalletService Elevation of Privilege Vulnerability | Important | 7.8 |
Windows WalletService | - | - | - |
| CVE-2020-17038 | Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2020-17040 | Windows Hyper-V Security Feature Bypass Vulnerability | Important | 6.5 |
Microsoft Windows | - | - | - |
| CVE-2020-17041 | Windows Print Configuration Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-17042 | Windows Print Spooler Remote Code Execution Vulnerability | Critical | 8.8 |
Microsoft Windows | - | - | - |
| CVE-2020-17043 | Windows Remote Access Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-17044 | Windows Remote Access Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2020-17045 | Windows KernelStream Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Windows | - | - | - |
| CVE-2020-17046 | Windows Error Reporting Denial of Service Vulnerability | Low | 5.5 |
Microsoft Windows | - | - | - |
| CVE-2020-17047 | Windows Network File System Denial of Service Vulnerability | Important | 7.5 |
Microsoft Windows | - | - | - |
| CVE-2020-17048 | Chakra Scripting Engine Memory Corruption Vulnerability | Critical | 4.2 |
Microsoft Scripting Engine | - | - | - |
| CVE-2020-17049 | Kerberos KDC Security Feature Bypass Vulnerability | Important | 6.6 |
Microsoft Windows | - | - | - |
| CVE-2020-17051 | Windows Network File System Remote Code Execution Vulnerability | Critical | 9.8 |
Microsoft Windows | - | - | - |
| CVE-2020-17052 | Scripting Engine Memory Corruption Vulnerability | Critical | 7.5 |
Microsoft Scripting Engine | - | - | - |
| CVE-2020-17053 | Internet Explorer Memory Corruption Vulnerability | Critical | 7.5 |
Microsoft Scripting Engine | - | - | - |
| CVE-2020-17054 | Chakra Scripting Engine Memory Corruption Vulnerability | Important | 4.2 |
Microsoft Scripting Engine | - | - | - |
| CVE-2020-17058 | Microsoft Browser Memory Corruption Vulnerability | Critical | 7.5 |
Microsoft Browsers | - | - | - |
| CVE-2020-17060 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-17061 | Microsoft SharePoint Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2020-17062 | Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2020-17063 | Microsoft Office Online Spoofing Vulnerability | Important | 6.8 |
Microsoft Office | - | - | - |
| CVE-2020-17064 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2020-17065 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2020-17066 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2020-17067 | Microsoft Excel Security Feature Bypass Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2020-17081 | Microsoft Raw Image Extension Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2020-17082 | Raw Image Extension Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2020-17083 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important | 5.5 |
Microsoft Exchange Server | - | - | - |
| CVE-2020-17084 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important | 8.5 |
Microsoft Exchange Server | - | - | - |
| CVE-2020-17085 | Microsoft Exchange Server Denial of Service Vulnerability | Important | 6.2 |
Microsoft Exchange Server | - | - | - |
| CVE-2020-17086 | Raw Image Extension Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2020-17091 | Microsoft Teams Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Teams | - | - | - |
| CVE-2020-17104 | Visual Studio Code JSHint Extension Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio | - | - | - |
| CVE-2020-1325 | Azure DevOps Server and Team Foundation Services Spoofing Vulnerability | Important | 5.4 |
Azure DevOps | - | - | - |
Threat Categories 7
| Threat Category | CVEs | Critical |
|---|---|---|
| Elevation of Privilege | 37 | 1 |
| Remote Code Execution | 35 | 16 |
| Information Disclosure | 19 | - |
| Spoofing | 10 | - |
| Security Feature Bypass | 5 | - |
| Denial of Service | 4 | - |
| Tampering | 2 | - |
Affected Products 19
| Product | CVEs | Exploited |
|---|---|---|
| Microsoft Windows | 34 | - |
| Azure Sphere | 15 | - |
| Microsoft Windows Codecs Library | 14 | - |
| Microsoft Office | 8 | - |
| Windows Update Stack | 7 | - |
| Microsoft Office SharePoint | 6 | - |
| Microsoft Graphics Component | 5 | - |
| Microsoft Dynamics | 4 | - |
| Microsoft Scripting Engine | 4 | - |
| Microsoft Exchange Server | 3 | - |
| Visual Studio | 2 | - |
| Windows Kernel | 2 | 1 |
| Windows WalletService | 2 | - |
| Azure DevOps | 1 | - |
| Microsoft Browsers | 1 | - |
| Microsoft Teams | 1 | - |
| Windows Common Log File System Driver | 1 | - |
| Windows Defender | 1 | - |
| Windows NDIS | 1 | - |