Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • December 2018 Patch Tuesday current page
Link copied

December 2018 Patch Tuesday

Dec 14, 2018
Author:
400x400 Linkedin X Profile
Phantom Labs™
BeyondTrust
Blog banner default
December 2018 Patch Tuesday
400x400 Linkedin X Profile
Phantom Labs™
BeyondTrust

Patch Tuesday

Microsoft has patched 32 vulnerabilities this month, which is relatively light compared to the 50+ that they normally patch. One “zero-day” vulnerability was also patched in this update that allowed for privilege escalation. With the exception of that “zero-day” in the kernel, the most notable vulnerabilities were in Microsoft’s web browsers.

Internet Explorer and Edge

Microsoft’s browsers received a number of fixes this month, with two notable ones allowing for remote code execution. Edge received a fix for CVE-2018-8624, and Explorer received a fix for CVE-2018-8631 to address the remote code execution bugs. Attackers exploiting these vulnerabilities would gain rights equal to that of the current user.

Kernel

This month’s previously mentioned zero-day vulnerability, CVE-2018-8611, was actively exploited in the wild prior to patching. Unprivileged users could gain control over vulnerable systems after logging in locally. This could be used in conjunction with a remote attack to grant the remote attacker greater privileges.

Office

Office products received six fixes for the holiday season. Attackers exploiting these vulnerabilities could gain access to sensitive information, execute code with privileges equal to that of the current user, and cause denial of service conditions. As usual, MS Office products typically do not require a high level of privilege in order to complete their tasks. Be sure to run them with the principle of least privilege (PoLP) in mind.

Windows DNS

Similar to a few months ago, Windows DNS was patched for a remote code execution vulnerability. An attacker would exploit this vulnerability by crafting and sending a malicious request to the DNS server. The server would then be compromised at the Local System Account level. Microsoft has rated the chances of exploiting this particular vulnerability as less likely.

Adobe Flash Player

Adobe brought their holiday patches as early gifts this month, releasing an out-of-band patch for two remote code execution vulnerabilities that were being actively exploited in the wild. Attackers exploiting these vulnerabilities would gain rights equal to that of the current user. Adobe Flash has two more years of life left in it, as Adobe has promised to stop updating and distributing Flash Player by the end of 2020. Until then, it is important to update Adobe Flash Player or uninstall it altogether.

Latest Posts
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
Related
  • Windows Server 2008 R2 Recycle Bin
    Nov 26, 2011 Windows Server 2008 R2 Recycle Bin
    Blog
    1m
  • Understanding Sudo Vulnerability CVE-2021-3156 and How Privilege Management for Unix & Linux Can Protect Your Enterprise
    Jan 28, 2021 Understanding Sudo Vulnerability CVE-2021-3156 and How Privilege Management for Unix & Linux Can Protect Your Enterprise
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.