(LiveHacking.Com) – As part of December’s Patch Tuesday, Microsoft has released seven security updates, three of which Microsoft has rated Critical, while the other four are rated Important in severity. These seven patches to address 24 security vulnerabilities in Microsoft Windows, Internet Explorer (IE), Office and Exchange.
The first of the Critical patches is a cumulative update for IE. The patch resolves fourteen privately reported vulnerabilities in Internet Explorer. The most severe of these vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. The update applies to IE 6 to IE 11, on Windows Server 2003 to Windows 81, depending on the version of IE.
The second Critical patch applies to Microsoft Word and Microsoft Office Web Apps, to fix two privately reported vulnerabilities. The vulnerabilities could allow remote code execution if a user opens or previews a specially crafted Microsoft Word file in an affected version of Microsoft Office software.
The Critical patch resolves a privately reported vulnerability in the VBScript scripting engine in Microsoft Windows. The vulnerability could allow remote code execution if a user visits a specially crafted website.
Microsoft has also re-released and updated two security bulletins related to Internet Explorer. The first, MS14-065, is a cumulative security update for Microsoft’s default browser, while the second relates to the browser’s built-in version of Flash. Adobe also released a security update for Adobe Flash Player for Windows.