Here’s where the threats stand as of early Thursday morning: CVE-2020-16898: “Bad Neighbor” or “Ping of Death” has a proof of concept available, but i
[See the full post at: October patched security holes are getting hit hard]
![]() |
There are isolated problems with current patches, but they are well-known and documented on this site. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
October patched security holes are getting hit hard
Home » Forums » Newsletter and Homepage topics » October patched security holes are getting hit hard
- This topic has 17 replies, 10 voices, and was last updated 2 years, 11 months ago.
AuthorTopicViewing 4 reply threadsAuthorRepliesSusan Bradley
Managerhttps://www.zerodayinitiative.com/blog/2020/10/13/the-october-2020-security-update-review
“- CVE-2020-16947 – Microsoft Outlook Remote Code Execution Vulnerability
This vulnerability was reported through the ZDI program, and it could allow code execution on affected versions of Outlook just by viewing a specially crafted e-mail. The Preview Pane is an attack vector here, so you don’t even need to open the mail to be impacted. The specific flaw exists within the parsing of HTML content in an email. The issue results from the lack of proper validation of the length of user-supplied data before copying it to a fixed-length heap-based buffer. Although Microsoft gives this an XI rating of 2, we have a working proof-of-concept. Patch this one quickly.”Susan Bradley Patch Lady/Prudent patcher
-
This reply was modified 2 years, 11 months ago by
Susan Bradley.
-
Tex265
AskWoody Plus -
anonymous
Guest -
Tex265
AskWoody PlusOK thanks. This shows the Security fix for Outlook 2016 Retail C2R is in the Current Channel, version 2009, Build 13231.20390, dated October 13, 2020.
Susan – have you cleared this Build as OK for installation? (I keep Office auto upgrades set to off until ready to upgrade).
Windows 10 Pro x64 v22H2 and Windows 7 Pro SP1 x64 (RIP) -
Susan Bradley
Manager
-
-
-
-
anonymous
Guest -
dph853
AskWoody PlusThis is why it is so important for Susan to be very clear when she gives advice to apply a specific patch to correct a bug in MS office. Many do not have the ability to select which patches get installed and which do not. Statements such as the one above above “Patch this one quickly” cause all sorts of confusion unless the advice to patch is accompanied by instructions on how to accomplish the goal on the various flavors of MS Office especially Click-to-run versions. In this case it appears to be better for C2R users to disable the email preview screen rather than installing all available waiting updates all at once at this point in time which is the only available option for C2R Office users.
-
This reply was modified 2 years, 11 months ago by
dph853.
-
This reply was modified 2 years, 11 months ago by
-
Fred
AskWoody LoungerMicrofix
AskWoody MVPVenkat over on Techdows is reporting that there are issues with Octobers kb4579311 alongside the known MSFT published issues with this update.
Windows Update fails to install KB4579311 with an error for some users
Manual download and install from Microsoft Catalog update, also triggering an error
The update is causing sign-in and freezing issues. Desktop turns to black after startup. USB network printer problems also reported.
Explorer crashes in a loop after login and becomes unresponsive, sometimes.No problem can be solved from the same level of consciousness that created IT- AE1 user thanked author for this post.
-
woody
Manager
CAS
AskWoody PlusI installed all updates today using MS Update Catalog. KB 4577671 took forever to download and install. I had to turn off my antivirus because the install got stuck about a quarter of the way into the install.
Windows update only offered me KB 4020357 which I hid using wsushowhide. A special “thank you” to Woody for the warning not to install it
I ran Belarc Advisor and it indicated that all necessary patches are now installed. Winver shows Version 1909 (OS Build 18363.1139). Just finished running Macrium Reflect. I’m tired but pleased to be done with this month’s ordeal.
CAS
1 user thanked author for this post.
Viewing 4 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Return Full Context Menus to File Explorer
by
RetiredGeek
19 seconds ago -
Unusual Activity on Startup
by
Kenneth Stephens
3 hours, 51 minutes ago -
Windows Backup – incremental possible?
by
colin_thames
2 hours, 3 minutes ago -
New HD addition??
by
weendoggy
7 hours, 46 minutes ago -
Defcon 4 and Windows 11
by
cmar6
8 hours, 50 minutes ago -
Add-ins keep disappearing
by
hession
6 hours, 15 minutes ago -
MS-DEFCON 4: Is Windows 11 really a disaster?
by
Susan Bradley
2 hours, 30 minutes ago -
The Takahē is not extinct afterall
by
lylejk
17 hours, 40 minutes ago -
How to unbloc W10pro from moving to W11
by
hession
1 day, 7 hours ago -
Windows 11, Surface, and Windows Copilot
by
Will Fastie
10 hours, 37 minutes ago -
Why File Explorer keeps me on Windows
by
Josh Hendrickson
2 hours, 54 minutes ago -
Uninstalr — “World’s best cup of coffee”
by
Deanna McElveen
1 hour, 12 minutes ago -
Locked out of your refurbished computer?
by
Susan Bradley
1 hour, 32 minutes ago -
Thunderbird 115: Changing font size in the Message Panel
by
WCHS
1 day, 6 hours ago -
Lenovo ThinkPad not updating to Windows 11 22H2
by
Gordski
5 hours, 36 minutes ago -
Android Security
by
Magic66
1 day, 8 hours ago -
What happened to the manual?
by
Susan Bradley
23 hours, 10 minutes ago -
OK to Restore Files From a Possibly Hacked Computer?
by
kc27
1 day, 21 hours ago -
Startup loop after adding new user and installing File Explore Patch
by
PFC
2 days, 23 hours ago -
RoboCops comes to NYPD. You have the right to remain cyborg
by
Alex5723
3 days, 4 hours ago -
iOS 17 : New Safari Privat Search Engines
by
Alex5723
3 days, 5 hours ago -
Photos App running in background
by
Tom
2 days, 2 hours ago -
IPV6 Issue Win10 22H2 August Update
by
Win7and10
3 days, 4 hours ago -
Windows 11 Insider Preview build 23550 released to DEV
by
joep517
4 days, 4 hours ago -
Windows 11 Build 22621.2361 (22H2) released to Release Preview
by
joep517
4 days, 4 hours ago -
Lately I’ve been getting qr code spam attacks
by
Susan Bradley
4 days, 7 hours ago -
ghacks Wants Edge – FF Browser Update to View – hack/redirect
by
CraigS26
3 days, 5 hours ago -
iOS 17 : If your new iPhone gets stuck on the Apple logo when you transfer…
by
Alex5723
4 days, 15 hours ago -
Apple zero days out – September 2023
by
Susan Bradley
3 hours, 19 minutes ago -
No shortcuts to files on Taskbar in Win11
by
KingGeorgeN
4 days, 7 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2023 by AskWoody Tech LLC. All Rights Reserved.