Skip to main content

Microsoft Monthly Security Update (Dec 2019)

Last Update Date: 11 Dec 2019 11:26 Release Date: 11 Dec 2019 5159 Views

RISK: High Risk

TYPE: Operating Systems - Windows OS

TYPE: Windows OS

Microsoft has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotes
BrowserMedium Risk Medium RiskRemote Code Execution 
Developer ToolsMedium Risk Medium RiskRemote Code Execution
Spoofing
Tampering
 
SQL ServerLow Risk Low RiskSpoofing 
Microsoft OfficeMedium Risk Medium RiskRemote Code Execution
Information Disclosure
Spoofing
Denial of Service
 
WindowsHigh Risk High RiskRemote Code Execution
Information Disclosure
Security Restriction Bypass
Denial of Service
Elevation of Privilege

 

Exploited in the wild (Local Exploit):

CVE-2019-1458

Skype for BusinessLow Risk Low RiskSpoofing 

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 1

Number of 'Medium Risk' product(s): 3

Number of 'Low Risk' product(s): 2

Evaluation of overall 'Risk Level': High Risk


Impact

  • Denial of Service
  • Elevation of Privilege
  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure
  • Spoofing
  • Data Manipulation

System / Technologies affected

  • Browser
  • Developer Tools
  • SQL Server
  • Microsoft Office
  • Windows
  • Skype for Business

 


Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Apply fixes issued by the vendor.

Vulnerability Identifier


Source


Related Link