1 min read
Microsoft December Patch Commentary by Tenable

Copyright 2023, IT Voice Media Pvt. Ltd.
All Rights Reserved

Microsoft sent administrators around the world an early holiday gift with a lighter-than-usual Patch Tuesday. The December 2019 Patch Tuesday contains updates for 36 CVEs, seven of which are rated as critical. This month’s updates include patches for Microsoft Windows, Microsoft Office, Internet Explorer, SQL Server, Visual Studio, and Skype for Business. The following is a breakdown of the most important CVEs from this month’s release.CVE-2019-1471, a remote code execution vulnerability in Windows Hyper-V, exists due to improper validation of inputs from an authenticated user on the guest operating system by the host server. To exploit the vulnerability, an attacker would need to run a specially-crafted application on the guest operating system, resulting in the execution of arbitrary code on the host operating system.” said Satnam Narang, Senior Research Engineer, Tenable.