Microsoft Fixing 11 Vulnerabilities for December Patch Tuesday

Microsoft announced today that it plans on shipping seven bulletins, five critical, two important, for the December edition of its monthly patch Tuesday security bulletin release cycle.The year’s last scheduled batch of patches will address 11 vulnerabilities in all currently supported operating systems, including Microsoft Windows, Internet Explorer (IE 6-10), Office and the company’s Server Software.

Patch TuesdayMicrosoft announced today that it plans on shipping seven bulletins, five critical, two important, for the December edition of its monthly patch Tuesday security bulletin release cycle.

The year’s last scheduled batch of patches will address 11 vulnerabilities in all currently supported operating systems, including Microsoft Windows, Internet Explorer (IE 6-10), Office and the company’s Server Software.

If left unpatched, six of the seven bulletins could lead to remote code execution while the last could allow a hacker to bypass one of Windows’ security features.

Qualys’ Wolfgang Kandek notes on the company’s Laws of Vulnerabilities blog that the third bulletin, rated critical, affects Microsoft Word, suggesting the vulnerability may leverage Outlook to display documents without the users’ interaction.

The bulletin summaries will be released in their entirety next Tuesday, December 11 and per usual, the company is set to host a Technnet webcast discussing the vulnerabilities and patch management practices the following day, December 12 at 11 a.m.

Suggested articles

biggest headlines 2020

The 5 Most-Wanted Threatpost Stories of 2020

A look back at what was hot with readers — offering a snapshot of the security stories that were most top-of-mind for security professionals and consumers throughout the year.