Here’s where the threats stand as of early Thursday morning: CVE-2020-16898: “Bad Neighbor” or “Ping of Death” has a proof of concept available, but i
[See the full post at: October patched security holes are getting hit hard]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
October patched security holes are getting hit hard
Home » Forums » Newsletter and Homepage topics » October patched security holes are getting hit hard
- This topic has 17 replies, 10 voices, and was last updated 4 years, 7 months ago.
AuthorTopicViewing 4 reply threadsAuthorReplies-
anonymous
Guest -
Susan Bradley
ManagerOctober 15, 2020 at 8:29 am #2304476https://www.zerodayinitiative.com/blog/2020/10/13/the-october-2020-security-update-review
“- CVE-2020-16947 – Microsoft Outlook Remote Code Execution Vulnerability
This vulnerability was reported through the ZDI program, and it could allow code execution on affected versions of Outlook just by viewing a specially crafted e-mail. The Preview Pane is an attack vector here, so you don’t even need to open the mail to be impacted. The specific flaw exists within the parsing of HTML content in an email. The issue results from the lack of proper validation of the length of user-supplied data before copying it to a fixed-length heap-based buffer. Although Microsoft gives this an XI rating of 2, we have a working proof-of-concept. Patch this one quickly.”Susan Bradley Patch Lady/Prudent patcher
-
This reply was modified 4 years, 7 months ago by
Susan Bradley.
-
This reply was modified 4 years, 7 months ago by
-
Tex265
AskWoody Plus -
anonymous
GuestOctober 15, 2020 at 12:54 pm #2304514 -
Tex265
AskWoody PlusOctober 15, 2020 at 2:00 pm #2304544OK thanks. This shows the Security fix for Outlook 2016 Retail C2R is in the Current Channel, version 2009, Build 13231.20390, dated October 13, 2020.
Susan – have you cleared this Build as OK for installation? (I keep Office auto upgrades set to off until ready to upgrade).
Windows 11 Pro v24H2 and Windows 10 Pro x64 v22H2 -
Susan Bradley
Manager
-
-
-
anonymous
Guest -
dph853
AskWoody PlusOctober 16, 2020 at 7:33 am #2304706This is why it is so important for Susan to be very clear when she gives advice to apply a specific patch to correct a bug in MS office. Many do not have the ability to select which patches get installed and which do not. Statements such as the one above above “Patch this one quickly” cause all sorts of confusion unless the advice to patch is accompanied by instructions on how to accomplish the goal on the various flavors of MS Office especially Click-to-run versions. In this case it appears to be better for C2R users to disable the email preview screen rather than installing all available waiting updates all at once at this point in time which is the only available option for C2R Office users.
-
This reply was modified 4 years, 7 months ago by
dph853.
-
This reply was modified 4 years, 7 months ago by
-
-
-
-
Fred
AskWoody Lounger -
Microfix
AskWoody MVPOctober 17, 2020 at 1:52 am #2304911Venkat over on Techdows is reporting that there are issues with Octobers kb4579311 alongside the known MSFT published issues with this update.
Windows Update fails to install KB4579311 with an error for some users
Manual download and install from Microsoft Catalog update, also triggering an error
The update is causing sign-in and freezing issues. Desktop turns to black after startup. USB network printer problems also reported.
Explorer crashes in a loop after login and becomes unresponsive, sometimes.Windows - commercial by definition and now function...1 user thanked author for this post.
-
woody
Manager
-
-
CAS
AskWoody PlusOctober 17, 2020 at 4:14 pm #2304993I installed all updates today using MS Update Catalog. KB 4577671 took forever to download and install. I had to turn off my antivirus because the install got stuck about a quarter of the way into the install.
Windows update only offered me KB 4020357 which I hid using wsushowhide. A special “thank you” to Woody for the warning not to install it
I ran Belarc Advisor and it indicated that all necessary patches are now installed. Winver shows Version 1909 (OS Build 18363.1139). Just finished running Macrium Reflect. I’m tired but pleased to be done with this month’s ordeal.
CAS
1 user thanked author for this post.
Viewing 4 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Migrating from win10 to win11, instructions coming?
by
astro46
2 hours, 41 minutes ago -
Device Eligibility for Apple 2026 Operating Systems due this Fall
by
PKCano
4 hours, 11 minutes ago -
Recommended watching : Mountainhead movie
by
Alex5723
8 hours, 36 minutes ago -
End of support for Windows 10
by
Old enough to know better
5 hours, 54 minutes ago -
What goes on inside an LLM
by
Michael Covington
35 minutes ago -
The risk of remote access
by
Susan Bradley
1 hour, 3 minutes ago -
The cruelest month for many Office users
by
Peter Deegan
5 hours, 14 minutes ago -
Tracking protection and trade-offs in Edge
by
Mary Branscombe
10 hours, 50 minutes ago -
Supreme Court grants DOGE access to confidential Social Security records
by
Alex5723
17 hours, 26 minutes ago -
EaseUS Partition Master free 19.6
by
Alex5723
4 hours, 37 minutes ago -
Microsoft : Edge is better than Chrome
by
Alex5723
1 day, 6 hours ago -
The EU launched DNS4EU
by
Alex5723
1 day, 19 hours ago -
Cell Phone vs. Traditional Touchtone Phone over POTS
by
280park
1 day, 9 hours ago -
Lost access to all my networked drives (shares) listed in My Computer
by
lwerman
2 days ago -
Set default size for pasted photo to word
by
Cyn
2 days, 6 hours ago -
Dedoimedo tries 24H2…
by
Cybertooth
1 day, 18 hours ago -
Windows 11 Insider Preview build 27871 released to Canary
by
joep517
3 days, 5 hours ago -
Windows 11 ad from Campaign Manager in Windows 10
by
Jim McKenna
22 hours, 38 minutes ago -
Small desktops
by
Susan Bradley
21 hours, 44 minutes ago -
Totally disable Bitlocker
by
CWBillow
1 day, 23 hours ago -
Phishers extract Millions from HMRC accounts..
by
Microfix
3 days, 3 hours ago -
Windows 10 22H2 Update today (5 June) says up-to-date but last was 2025-04
by
Alan_uk
4 days, 9 hours ago -
Thoughts on Malwarebytes Scam Guard for Mobile?
by
opti1
2 days, 4 hours ago -
Mystical Desktop
by
CWBillow
4 days, 13 hours ago -
Meta and Yandex secretly tracked billions of Android users
by
Alex5723
3 days, 18 hours ago -
MS-DEFCON 2: Do you need that update?
by
Susan Bradley
1 day, 5 hours ago -
CD/DVD drive is no longer recognized
by
WSCape Sand
5 days, 4 hours ago -
Windows 11 24H2 Default Apps stuck on Edge and Adobe Photoshop
by
MikeBravo
5 days, 7 hours ago -
North Face and Cartier customer data stolen in cyber attacks
by
Alex5723
5 days, 5 hours ago -
What is wrong with simple approach?
by
WSSpoke36
3 days, 3 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.