{"id":7640,"date":"2020-12-09T01:55:00","date_gmt":"2020-12-09T01:55:00","guid":{"rendered":"https:\/\/www.syxsense.com\/december-patch-tuesday-2020\/"},"modified":"2020-12-09T01:55:00","modified_gmt":"2020-12-09T01:55:00","slug":"december-patch-tuesday-2020","status":"publish","type":"post","link":"https:\/\/www.syxsense.com\/december-patch-tuesday-2020","title":{"rendered":"December Patch Tuesday 2020 Fixes 58 Vulnerabilities"},"content":{"rendered":"<\/p>\n

December Patch Tuesday 2020 Fixes 58 Vulnerabilities<\/h1>\n<\/p>\n

December Patch Tuesday Arrives with 58 Fixes<\/h2>\n

To end the year, Microsoft has remediated 58 bugs including\u00a09\u00a0Critical,\u00a046 Important and\u00a03\u00a0Moderate. Microsoft has fixed over 1,200 vulnerabilities to date, more than any other year.<\/p>\n

Fixes this month included Microsoft Windows, Edge (Edge HTML-based), Chakra Core, Microsoft Office and Office Services and Web Apps, Exchange Server, Azure DevOps, Microsoft Dynamics, Visual Studio, Azure SDK, and Azure Sphere.<\/p>\n

However, there were surprisingly no fixes for Internet Explorer \u2014 could there be a last minute out-of-band for December? We will have to wait and see.<\/p>\n

There were just shy of half the fixes compared to November<\/a>, which was a record high of\u00a0112\u00a0vulnerabilities.<\/p>\n

There have also been Windows 7 and Windows Server 2008 (including R2) vulnerabilities for extended support subscribers. Windows 7 and Windows Server 2008 (including R2) both have\u00a09\u00a0vulnerabilities: all Important.<\/p>\n

Robert Brown, Director of Services for Syxsense said,\u00a0\u201cWe were told there would not be any preview updates this month to reduce the holiday burden on IT departments, but we are surprised not to see any Internet Explorer fixes in here and only 1 for Edge. Stay vigilant as there may be last minute OOB updates before New Year.\u201d<\/p>\n

Top December Patches and Vulnerabilities<\/h2>\n

1. CVE-2020-17132<\/strong><\/a> & CVE-2020-17142<\/strong><\/a>: Microsoft Exchange Remote Code Execution Vulnerability<\/p>\n