Security News > 2020 > December > Microsoft Patches Critical SharePoint, Exchange Security Holes
Microsoft's final batch of security patches for 2020 shipped today with fixes for at least 58 documented vulnerabilities affecting a wide range of OS and software products.
The December security updates include fixes for code execution vulnerabilities in the company's flagship Windows operating system and serious problems in Microsoft Sharepoint, Microsoft Exchange, HyperV, and a Kerberos security feature bypass.
Microsoft slapped a "Critical" severity rating on nine of the 58 bulletins, while 46 are rated "Important." None of the documented bugs are under active attack and Microsoft said it was unaware of the availability of public exploit code.
CVE-2020-17132 - Microsoft Exchange Remote Code Execution Vulnerability - This is one of several Exchange code execution bugs, and it is credited to three different researchers.
CVE-2020-17121 - Microsoft SharePoint Remote Code Execution Vulnerability - Originally reported through the ZDI program, this patch corrects a bug that could allow an authenticated user to execute arbitrary.
News URL
Related news
- Microsoft slammed for lax security that led to China's cyber-raid on Exchange Online (source)
- Microsoft slammed for lax security that led to China's cyber-raid on Exchange Online (source)
- Microsoft releases Exchange hotfixes for security update issues (source)
- Critical Security Flaw Found in Popular LayerSlider WordPress Plugin (source)
- Microsoft still unsure how hackers stole MSA key in 2023 Exchange attack (source)
- Microsoft fixes Outlook security alerts bug caused by December updates (source)
- US Cyber Safety Review Board on the 2023 Microsoft Exchange Hack (source)
- Microsoft April 2024 Patch Tuesday fixes 150 security flaws, 67 RCEs (source)
- Microsoft squashes SmartScreen security bypass bug exploited in the wild (source)
- Fortinet Rolls Out Critical Security Patches for FortiClientLinux Vulnerability (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-12-10 | CVE-2020-17121 | Unspecified vulnerability in Microsoft Sharepoint Foundation and Sharepoint Server Microsoft SharePoint Remote Code Execution Vulnerability | 8.8 |
2020-12-10 | CVE-2020-17132 | Unspecified vulnerability in Microsoft Exchange Server 2013/2016/2019 Microsoft Exchange Remote Code Execution Vulnerability | 9.1 |