CVE Announcements This Week
Microsoft fixes over 110 CVEs again.Microsoft has released patches for 129 CVEs, 23 of which are “critical”, 105 “important”, and one “medium”-risk (a security feature bypass flaw in SQL Server Reporting Services). None of them are publicly known or being actively exploited. Zeljka Zorz, Help Net Security / September 8, 2020
Android's September 2020 Patches Fix Critical System Vulnerabilities.More than 50 flaws are described in the Android Security Bulletin for September 2020: twenty-two as part of the 2020-09-01 security patch level and twenty-nine with the 2020-09-05 security patch level. By Ionut Arghire on September 09, 2020
Google Squashes Critical Android Media Framework Bug.Google patched a critical vulnerability in the Media Framework of its Android operating system, which if exploited could lead to remote code execution attacks on vulnerable devices. By Lindsey O'Donnell on September 9, 2020
Cisco patches critical, wormable RCE flaw in Cisco Jabber.Cisco has patched four vulnerabilities in its Jabber client for Windows, the most critical of which (CVE-2020-3495) could allow attackers to achieve remote code execution by sending specially crafted chat messages. By Zeljka Zorz, Managing Editor, Help Net Security on September 3, 2020