Security News > 2020 > December > Microsoft Patches Critical SharePoint, Exchange Security Holes

Microsoft Patches Critical SharePoint, Exchange Security Holes
2020-12-08 18:52

Microsoft's final batch of security patches for 2020 shipped today with fixes for at least 58 documented vulnerabilities affecting a wide range of OS and software products.

The December security updates include fixes for code execution vulnerabilities in the company's flagship Windows operating system and serious problems in Microsoft Sharepoint, Microsoft Exchange, HyperV, and a Kerberos security feature bypass.

Microsoft slapped a "Critical" severity rating on nine of the 58 bulletins, while 46 are rated "Important." None of the documented bugs are under active attack and Microsoft said it was unaware of the availability of public exploit code.

CVE-2020-17132 - Microsoft Exchange Remote Code Execution Vulnerability - This is one of several Exchange code execution bugs, and it is credited to three different researchers.

CVE-2020-17121 - Microsoft SharePoint Remote Code Execution Vulnerability - Originally reported through the ZDI program, this patch corrects a bug that could allow an authenticated user to execute arbitrary.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/02LdrUjVKeY/microsoft-patches-critical-sharepoint-exchange-security-holes

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2020-12-10 CVE-2020-17121 Unspecified vulnerability in Microsoft Sharepoint Foundation and Sharepoint Server
Microsoft SharePoint Remote Code Execution Vulnerability
network
low complexity
microsoft
8.8
2020-12-10 CVE-2020-17132 Unspecified vulnerability in Microsoft Exchange Server 2013/2016/2019
Microsoft Exchange Remote Code Execution Vulnerability
network
low complexity
microsoft
critical
9.1

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 713 868 4788 4392 3717 13765