Microsoft have released a security advisory on the 08th of December 2020 in line with their regular monthly patch schedule which includes a number of updates to address critical vulnerabilities. System / Technology components affected include Microsoft Office, Windows, Extended Security Updates (ESU), Exchange Server, Developer Tools, Microsoft Dynamics, Azure and Browser. These updates address vulnerabilities which may impact Elevation of Privilege, Remote Code Execution, Security Restriction Bypass, Information Disclosure and Spoofing.
https://msrc.microsoft.com/update-guide/releaseNote/2020-Dec
The following operating systems/applications are affected:
- Microsoft Windows
- Microsoft Edge (EdgeHTML-based)
- Microsoft Edge for Android
- ChakraCore
- Microsoft Office and Microsoft Office Services and Web Apps
- Microsoft Exchange Server
- Azure DevOps
- Microsoft Dynamics
- Visual Studio
- Azure SDK
- Azure Sphere
Matsco recommends any affected systems are updated as soon as convenient