Security News > 2021 > May > Microsoft emits more fixes for Exchange Server plus patches for remote-code exec holes in HTTP stack, Visual Studio

Microsoft emits more fixes for Exchange Server plus patches for remote-code exec holes in HTTP stack, Visual Studio
2021-05-11 19:08

The Redmond-based firm's Office and Windows flagships house many of the identified vulnerabilities, alongside Internet Explorer, Visual Studio, Visual Studio Code, Skype, and other software.

Those who recall the slew of Exchange Server fixes in March and April may experience a sense of deja vu: May brings still more Exchange Server fixes, for Exchange Server 2013 CU23, Exchange Server 2016 CU19 and CU20, and Exchange Server 2019 CU8 and CU9.

"More Exchange patches are expected as not everything disclosed at the contest has been addressed," he said.

The other two critical vulnerabilities - OLE Automation Remote Code Execution Vulnerability and Scripting Engine Memory Corruption Vulnerability - both involve luring a victim to a website to get remote code execution, said Childs.

SAP. SAP released 11 security notes, six addressing new issues and five related to previous patches.

The two Hot News runners-up managed only 9.9 severity - an update to an April 2021 patch addressing a remote code execution vulnerability in SAP Commerce and an update to a January 2021 patch addressing a code injection flaw in SAP Business Warehouse and SAP BW/4HANA. Among the newly disclosed entries, two of the three High Priority notes fix issues in SAP Business One.


News URL

https://go.theregister.com/feed/www.theregister.com/2021/05/11/microsoft_patch_tuesday_exchange_hyperv/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 480 75 2308 5127 264 7774