Security News > 2020 > December > Microsoft Patches Critical SharePoint, Exchange Security Holes

Microsoft's final batch of security patches for 2020 shipped today with fixes for at least 58 documented vulnerabilities affecting a wide range of OS and software products.
The December security updates include fixes for code execution vulnerabilities in the company's flagship Windows operating system and serious problems in Microsoft Sharepoint, Microsoft Exchange, HyperV, and a Kerberos security feature bypass.
Microsoft slapped a "Critical" severity rating on nine of the 58 bulletins, while 46 are rated "Important." None of the documented bugs are under active attack and Microsoft said it was unaware of the availability of public exploit code.
CVE-2020-17132 - Microsoft Exchange Remote Code Execution Vulnerability - This is one of several Exchange code execution bugs, and it is credited to three different researchers.
CVE-2020-17121 - Microsoft SharePoint Remote Code Execution Vulnerability - Originally reported through the ZDI program, this patch corrects a bug that could allow an authenticated user to execute arbitrary.
News URL
Related news
- Microsoft: Outdated Exchange servers fail to auto-mitigate security bugs (source)
- Severe Security Flaws Patched in Microsoft Dynamics 365 and Power Apps Web API (source)
- The ongoing evolution of the CIS Critical Security Controls (source)
- 3 Actively Exploited Zero-Day Flaws Patched in Microsoft's Latest Security Update (source)
- Microsoft: Exchange 2016 and 2019 reach end of support in October (source)
- ‘Sneaky Log’ Microsoft Spoofing Scheme Sidesteps Two-Factor Security (source)
- Microsoft: January Windows security updates break audio playback (source)
- Critical Cacti Security Flaw (CVE-2025-22604) Enables Remote Code Execution (source)
- Microsoft SharePoint Connector Flaw Could've Enabled Credential Theft Across Power Platform (source)
- Microsoft Patches Critical Azure AI Face Service Vulnerability with CVSS 9.9 Score (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-12-10 | CVE-2020-17121 | Unspecified vulnerability in Microsoft Sharepoint Foundation and Sharepoint Server Microsoft SharePoint Remote Code Execution Vulnerability | 0.0 |
2020-12-10 | CVE-2020-17132 | Unspecified vulnerability in Microsoft Exchange Server 2013/2016/2019 Microsoft Exchange Remote Code Execution Vulnerability | 0.0 |