Microsoft has released the October 2020 Office security updates with a total of 24 security updates and 5 cumulative updates for 7 different products, fixing 13 vulnerabilities that could enable remote attackers to execute arbitrary code on vulnerable systems. Microsoft rated the 11 RCE security flaws as Critical or Important severity issues seeing that they could enable attackers to run arbitrary code in the context of the current user after successful exploitation. The attackers could then install malicious programs, view, change, and delete data, as well as create their own rogue admin accounts on compromised Windows devices.
Source: https://www.bleepingcomputer.com/news/security/microsoft-fixes-critical-outlook-bug-exploitable-via-preview-pane/

