Security News > 2020 > December > Microsoft Patches Critical SharePoint, Exchange Security Holes
Microsoft's final batch of security patches for 2020 shipped today with fixes for at least 58 documented vulnerabilities affecting a wide range of OS and software products.
The December security updates include fixes for code execution vulnerabilities in the company's flagship Windows operating system and serious problems in Microsoft Sharepoint, Microsoft Exchange, HyperV, and a Kerberos security feature bypass.
Microsoft slapped a "Critical" severity rating on nine of the 58 bulletins, while 46 are rated "Important." None of the documented bugs are under active attack and Microsoft said it was unaware of the availability of public exploit code.
CVE-2020-17132 - Microsoft Exchange Remote Code Execution Vulnerability - This is one of several Exchange code execution bugs, and it is credited to three different researchers.
CVE-2020-17121 - Microsoft SharePoint Remote Code Execution Vulnerability - Originally reported through the ZDI program, this patch corrects a bug that could allow an authenticated user to execute arbitrary.
News URL
Related news
- Microsoft pulls Exchange security updates over mail delivery issues (source)
- Microsoft overhauls security for publishing Edge extensions (source)
- Two simple give-me-control security bugs found in Optigo network switches used in critical manufacturing (source)
- Microsoft Issues Security Update Fixing 118 Flaws, Two Actively Exploited in the Wild (source)
- CISA Warns of Critical Fortinet Flaw as Palo Alto and Cisco Issue Urgent Security Patches (source)
- Week in review: Microsoft fixes two exploited zero-days, SOC teams are losing trust in security tools (source)
- Microsoft warns it lost some customer's security logs for a month (source)
- Microsoft lost some customers’ cloud security logs (source)
- CISA Warns of Active Exploitation of Microsoft SharePoint Vulnerability (CVE-2024-38094) (source)
- Microsoft SharePoint RCE flaw exploits in the wild – you've had 3 months to patch (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-12-10 | CVE-2020-17121 | Unspecified vulnerability in Microsoft Sharepoint Foundation and Sharepoint Server Microsoft SharePoint Remote Code Execution Vulnerability | 8.8 |
2020-12-10 | CVE-2020-17132 | Unspecified vulnerability in Microsoft Exchange Server 2013/2016/2019 Microsoft Exchange Remote Code Execution Vulnerability | 9.1 |