Print

In this month, December of 2018, Microsoft has published more than thirty vulnerabilities in which more than five vulnerabilities are rated as critical and more than twenty vulnerabilities are rated as important.

  

Another important classification is based on their nature of exploitability, we find that the network exploited vulnerabilities are more than the locally exploitable ones.

 

While classifying the vulnerabilities based on authentication, the vulnerabilities that require high level of authentication are much higher than the vulnerabilities that require low level of authentication. 

 

The below graph shows the count of MS Vulnerabilities based on the type of the vulnerability.

 

The below graph shows the count of MS Vulnerabilities based on the impacted component.

 

 

 

Sl No

CVE Number

Vulnerability Type

Affected Products

1

CVE-2018-8583

Memory Corruption Vulnerability

Microsoft Edge

Microsoft ChakraCore

Microsoft Windows 10 Version 1703 for 32-bit Systems

Microsoft Windows 10 Version 1703 for x64-based Systems

Microsoft Windows 10 Version 1803 for 32-bit Systems

Microsoft Windows 10 Version 1803 for x64-based Systems

Microsoft Windows 10 Version 1803 for ARM64-based Systems

Microsoft Windows 10 Version 1809 for 32-bit Systems

Microsoft Windows 10 Version 1809 for x64-based Systems

Microsoft Windows 10 Version 1809 for ARM64-based Systems

Microsoft Windows Server 2019

Microsoft Windows 10 Version 1709 for 32-bit Systems

Microsoft Windows 10 Version 1709 for 64-based Systems

Microsoft Windows 10 Version 1709 for ARM64-based Systems

2

CVE-2018-8617

Memory Corruption Vulnerability

Microsoft Edge

Microsoft ChakraCore

Microsoft Windows 10 Version 1703 for 32-bit Systems

Microsoft Windows 10 Version 1703 for x64-based Systems

Microsoft Windows 10 Version 1803 for 32-bit Systems

Microsoft Windows 10 Version 1803 for x64-based Systems

Microsoft Windows 10 Version 1803 for ARM64-based Systems

Microsoft Windows 10 Version 1809 for 32-bit Systems

Microsoft Windows 10 Version 1809 for x64-based Systems

Microsoft Windows 10 Version 1809 for ARM64-based Systems

Microsoft Windows Server 2019

Microsoft Windows 10 Version 1709 for 32-bit Systems

Microsoft Windows 10 Version 1709 for 64-based Systems

Microsoft Windows 10 Version 1709 for ARM64-based Systems

Microsoft Windows 10 for 32-bit Systems

Microsoft Windows 10 for x64-based Systems

Microsoft Windows 10 Version 1607 for 32-bit Systems

Microsoft Windows 10 Version 1607 for x64-based Systems

Microsoft Windows Server 2016

3

CVE-2018-8618

Memory Corruption Vulnerability

Microsoft Edge

Microsoft ChakraCore

Microsoft Windows 10 Version 1703 for 32-bit Systems

Microsoft Windows 10 Version 1703 for x64-based Systems

Microsoft Windows 10 Version 1803 for 32-bit Systems

Microsoft Windows 10 Version 1803 for x64-based Systems

Microsoft Windows 10 Version 1803 for ARM64-based Systems

Microsoft Windows 10 Version 1809 for 32-bit Systems

Microsoft Windows 10 Version 1809 for x64-based Systems

Microsoft Windows 10 Version 1809 for ARM64-based Systems

Microsoft Windows Server 2019

Microsoft Windows 10 Version 1709 for 32-bit Systems

Microsoft Windows 10 Version 1709 for 64-based Systems

Microsoft Windows 10 Version 1709 for ARM64-based Systems

Microsoft Windows 10 Version 1607 for 32-bit Systems

Microsoft Windows 10 Version 1607 for x64-based Systems

Microsoft Windows Server 2016

4

CVE-2018-8629

Memory Corruption Vulnerability

Microsoft Edge

Microsoft ChakraCore

Microsoft Windows 10 Version 1703 for 32-bit Systems

Microsoft Windows 10 Version 1703 for x64-based Systems

Microsoft Windows 10 Version 1803 for 32-bit Systems

Microsoft Windows 10 Version 1803 for x64-based Systems

Microsoft Windows 10 Version 1803 for ARM64-based Systems

Microsoft Windows 10 Version 1809 for 32-bit Systems

Microsoft Windows 10 Version 1809 for x64-based Systems

Microsoft Windows 10 Version 1809 for ARM64-based Systems

Microsoft Windows Server 2019

Microsoft Windows 10 Version 1709 for 32-bit Systems

Microsoft Windows 10 Version 1709 for 64-based Systems

Microsoft Windows 10 Version 1709 for ARM64-based Systems

Microsoft Windows 10 for 32-bit Systems

Microsoft Windows 10 for x64-based Systems

Microsoft Windows 10 Version 1607 for 32-bit Systems

Microsoft Windows 10 Version 1607 for x64-based Systems

Microsoft Windows Server 2016

5

CVE-2018-8631

Memory Corruption Vulnerability

Microsoft Internet Explorer 11

Microsoft Internet Explorer 10

Microsoft Internet Explorer 9

Microsoft Windows Server 2012

Microsoft Windows 10 Version 1703 for 32-bit Systems

Microsoft Windows 10 Version 1703 for x64-based Systems

Microsoft Windows 10 Version 1803 for 32-bit Systems

Microsoft Windows 10 Version 1803 for x64-based Systems

Microsoft Windows 10 Version 1803 for ARM64-based Systems

Microsoft Windows 10 Version 1809 for 32-bit Systems

Microsoft Windows 10 Version 1809 for x64-based Systems

Microsoft Windows 10 Version 1809 for ARM64-based Systems

Microsoft Windows Server 2019

Microsoft Windows 10 Version 1709 for 32-bit Systems

Microsoft Windows 10 Version 1709 for 64-based Systems

Microsoft Windows 10 Version 1709 for ARM64-based Systems

Microsoft Windows 10 for 32-bit Systems

Microsoft Windows 10 for x64-based Systems

Microsoft Windows 10 Version 1607 for 32-bit Systems

Microsoft Windows 10 Version 1607 for x64-based Systems

Microsoft Windows Server 2016

Microsoft Windows 7 for 32-bit Systems Service Pack 1

Microsoft Windows 7 for x64-based Systems Service Pack 1

Microsoft Windows 8.1 for 32-bit systems

Microsoft Windows 8.1 for x64-based systems

Microsoft Windows RT 8.1

Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1

Microsoft Windows Server 2012 R2

Microsoft Windows Server 2008 for 32-bit Systems Service Pack 2

Microsoft Windows Server 2008 for x64-based Systems Service Pack 2

6

CVE-2018-8624

Memory Corruption Vulnerability

Microsoft Edge

Microsoft ChakraCore

Microsoft Windows 10 Version 1703 for 32-bit Systems

Microsoft Windows 10 Version 1703 for x64-based Systems

Microsoft Windows 10 Version 1803 for 32-bit Systems

Microsoft Windows 10 Version 1803 for x64-based Systems

Microsoft Windows 10 Version 1803 for ARM64-based Systems

Microsoft Windows 10 Version 1809 for 32-bit Systems

Microsoft Windows 10 Version 1809 for x64-based Systems

Microsoft Windows 10 Version 1809 for ARM64-based Systems

Microsoft Windows Server 2019

Microsoft Windows 10 Version 1709 for 32-bit Systems

Microsoft Windows 10 Version 1709 for 64-based Systems

Microsoft Windows 10 Version 1709 for ARM64-based Systems

Microsoft Windows 10 Version 1607 for 32-bit Systems

Microsoft Windows 10 Version 1607 for x64-based Systems

Microsoft Windows Server 2016

7

CVE-2018-8626

Heap Overflow Vulnerability

Microsoft Windows 10 Version 1607 for 32-bit Systems

Microsoft Windows 10 Version 1607 for x64-based Systems

Microsoft Windows 10 Version 1709 for 32-bit Systems

Microsoft Windows 10 Version 1709 for 64-based Systems

Microsoft Windows 10 Version 1709 for ARM64-based Systems

Microsoft Windows 10 Version 1803 for 32-bit Systems

Microsoft Windows 10 Version 1803 for ARM64-based Systems

Microsoft Windows 10 Version 1803 for x64-based Systems

Microsoft Windows 10 Version 1809 for 32-bit Systems

Microsoft Windows 10 Version 1809 for ARM64-based Systems

Microsoft Windows 10 Version 1809 for x64-based Systems

Microsoft Windows Server 2012 R2

Microsoft Windows Server 2012 R2 (Server Core installation)

Microsoft Windows Server 2016

Microsoft Windows Server 2016 (Server Core installation)

Microsoft Windows Server 2019

Microsoft Windows Server 2019 (Server Core installation)

Microsoft Windows Server, version 1709 (Server Core Installation)

Microsoft Windows Server, version 1803 (Server Core Installation)

8

CVE-2018-8634

Remote Code Execution Vulnerability

Microsoft Windows 10 for 32-bit Systems

Microsoft Windows 10 for x64-based Systems

Microsoft Windows 10 Version 1607 for 32-bit Systems

Microsoft Windows 10 Version 1607 for x64-based Systems

Microsoft Windows 10 Version 1703 for 32-bit Systems

Microsoft Windows 10 Version 1703 for x64-based Systems

Microsoft Windows 10 Version 1709 for 32-bit Systems

Microsoft Windows 10 Version 1709 for 64-based Systems

Microsoft Windows 10 Version 1709 for ARM64-based Systems

Microsoft Windows 10 Version 1803 for 32-bit Systems

Microsoft Windows 10 Version 1803 for ARM64-based Systems

Microsoft Windows 10 Version 1803 for x64-based Systems

Microsoft Windows 10 Version 1809 for 32-bit Systems

Microsoft Windows 10 Version 1809 for ARM64-based Systems

Microsoft Windows 10 Version 1809 for x64-based Systems

Microsoft Windows Server 2016

Microsoft Windows Server 2016 (Server Core installation)

Microsoft Windows Server 2019

Microsoft Windows Server 2019 (Server Core installation)

Microsoft Windows Server, version 1709 (Server Core Installation)

Microsoft Windows Server, version 1803 (Server Core Installation)

9

CVE-2018-8540

Remote Code Injection Vulnerability

Microsoft .NET Framework 3.5

Microsoft .NET Framework 3.5.1

Microsoft .NET Framework 4.5.2

Microsoft .NET Framework 4.6

Microsoft .NET Framework 4.6.1

Microsoft .NET Framework 4.6.2

Microsoft .NET Framework 4.7

Microsoft .NET Framework 4.7.1

Microsoft .NET Framework 4.7.2

Windows 10 Version 1703 for 32-bit Systems

Windows 10 Version 1703 for x64-based Systems

Windows 10 Version 1803 for 32-bit Systems

Windows 10 Version 1803 for x64-based Systems

Windows Server, version 1803 (Server Core Installation)

Windows 10 Version 1809 for 32-bit Systems

Windows 10 Version 1809 for x64-based Systems

Windows Server 2019

Windows Server 2019 (Server Core installation)

Windows 10 Version 1709 for 32-bit Systems

Windows 10 Version 1709 for 64-based Systems

Windows Server, version 1709 (Server Core Installation)

Windows 10 for 32-bit Systems

Windows 10 for x64-based Systems

Windows 10 Version 1607 for 32-bit Systems

Windows 10 Version 1607 for x64-based Systems

Windows Server 2016

Windows Server 2016 (Server Core installation)

Windows 8.1 for 32-bit systems

Windows 8.1 for x64-based systems

Windows Server 2012

Windows Server 2012 (Server Core installation)

Windows Server 2012 R2

Windows Server 2012 R2 (Server Core installation)

Windows Server 2008 for 32-bit Systems Service Pack 2

Windows Server 2008 for x64-based Systems Service Pack 2

Windows 7 for 32-bit Systems Service Pack 1

Windows 7 for x64-based Systems Service Pack 1

Windows Server 2008 R2 for x64-based Systems Service Pack 1

Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Windows RT 8.1

Windows 10 Version 1709 for ARM64-based Systems

10

CVE-2018-8619

Remote Code Execution Vulnerability

Microsoft Internet Explorer 9

Microsoft Internet Explorer 11

Microsoft Internet Explorer 10

Microsoft Windows Server 2012

Microsoft Windows 10 Version 1703 for 32-bit Systems

Microsoft Windows 10 Version 1703 for x64-based Systems

Microsoft Windows 10 Version 1803 for 32-bit Systems

Microsoft Windows 10 Version 1803 for x64-based Systems

Microsoft Windows 10 Version 1809 for 32-bit Systems

Microsoft Windows 10 Version 1809 for x64-based Systems

Microsoft Windows 10 Version 1809 for ARM64-based Systems

Microsoft Windows Server 2019

Microsoft Windows 10 Version 1709 for 32-bit Systems

Microsoft Windows 10 Version 1709 for 64-based Systems

Microsoft Windows 10 for 32-bit Systems

Microsoft Windows 10 for x64-based Systems

Microsoft Windows 10 Version 1607 for 32-bit Systems

Microsoft Windows 10 Version 1607 for x64-based Systems

Microsoft Windows Server 2016

Microsoft Windows 7 for 32-bit Systems Service Pack 1

Microsoft Windows 7 for x64-based Systems Service Pack 1

Microsoft Windows 8.1 for 32-bit systems

Microsoft Windows 8.1 for x64-based systems

Microsoft Windows RT 8.1

Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1

Microsoft Windows Server 2012 R2

Microsoft Windows Server 2008 for 32-bit Systems Service Pack 2

Microsoft Windows Server 2008 for x64-based Systems Service Pack 2

11

CVE-2018-8625

Remote Code Execution Vulnerability

Microsoft Internet Explorer 9

Microsoft Internet Explorer 11

Microsoft Internet Explorer 10

Microsoft Windows Server 2012

Microsoft Windows 10 Version 1703 for 32-bit Systems

Microsoft Windows 10 Version 1703 for x64-based Systems

Microsoft Windows 10 Version 1803 for 32-bit Systems

Microsoft Windows 10 Version 1803 for x64-based Systems

Microsoft Windows 10 Version 1809 for 32-bit Systems

Microsoft Windows 10 Version 1809 for x64-based Systems

Microsoft Windows 10 Version 1809 for ARM64-based Systems

Microsoft Windows Server 2019

Microsoft Windows 10 Version 1709 for 32-bit Systems

Microsoft Windows 10 Version 1709 for 64-based Systems

Microsoft Windows 10 for 32-bit Systems

Microsoft Windows 10 for x64-based Systems

Microsoft Windows 10 Version 1607 for 32-bit Systems

Microsoft Windows 10 Version 1607 for x64-based Systems

Microsoft Windows Server 2016

Microsoft Windows 7 for 32-bit Systems Service Pack 1

Microsoft Windows 7 for x64-based Systems Service Pack 1

Microsoft Windows 8.1 for 32-bit systems

Microsoft Windows 8.1 for x64-based systems

Microsoft Windows RT 8.1

Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1

Microsoft Windows Server 2012 R2

Microsoft Windows Server 2008 for 32-bit Systems Service Pack 2

Microsoft Windows Server 2008 for x64-based Systems Service Pack 2

12

CVE-2018-8643

Memory Corruption Vulnerability

Microsoft Internet Explorer 9

Microsoft Internet Explorer 11

Microsoft Internet Explorer 10

Microsoft Windows Server 2012

Microsoft Windows 10 Version 1703 for 32-bit Systems

Microsoft Windows 10 Version 1703 for x64-based Systems

Microsoft Windows 10 Version 1803 for 32-bit Systems

Microsoft Windows 10 Version 1803 for x64-based Systems

Microsoft Windows 10 Version 1809 for 32-bit Systems

Microsoft Windows 10 Version 1809 for x64-based Systems

Microsoft Windows 10 Version 1809 for ARM64-based Systems

Microsoft Windows Server 2019

Microsoft Windows 10 Version 1709 for 32-bit Systems

Microsoft Windows 10 Version 1709 for 64-based Systems

Microsoft Windows 10 for 32-bit Systems

Microsoft Windows 10 for x64-based Systems

Microsoft Windows 10 Version 1607 for 32-bit Systems

Microsoft Windows 10 Version 1607 for x64-based Systems

Microsoft Windows Server 2016

Microsoft Windows 7 for 32-bit Systems Service Pack 1

Microsoft Windows 7 for x64-based Systems Service Pack 1

Microsoft Windows 8.1 for 32-bit systems

Microsoft Windows 8.1 for x64-based systems

Microsoft Windows RT 8.1

Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1

Microsoft Windows Server 2012 R2

Microsoft Windows Server 2008 for 32-bit Systems Service Pack 2

Microsoft Windows Server 2008 for x64-based Systems Service Pack 2

13

CVE-2018-8580

Information Disclosure Vulnerability

Microsoft SharePoint Enterprise Server 2013 Service Pack 1

Microsoft SharePoint Enterprise Server 2016

Microsoft SharePoint Foundation 2010 Service Pack 2

14

CVE-2018-8587

Remote Code Execution Vulnerability

Microsoft Office 2019 for 32-bit editions

Microsoft Office 2019 for 64-bit editions

Microsoft Outlook 2010 Service Pack 2 (32-bit editions)

Microsoft Outlook 2010 Service Pack 2 (64-bit editions)

Microsoft Outlook 2013 RT Service Pack 1

Microsoft Outlook 2013 Service Pack 1 (32-bit editions)

Microsoft Outlook 2013 Service Pack 1 (64-bit editions)

Microsoft Outlook 2016 (32-bit edition)

Microsoft Outlook 2016 (64-bit edition)

Microsoft Office 365 ProPlus for 32-bit Systems

Microsoft Office 365 ProPlus for 64-bit Systems

15

CVE-2018-8597

Remote Code Execution Vulnerability

Microsoft Excel 2010 Service Pack 2 (32-bit editions)

Microsoft Excel 2010 Service Pack 2 (64-bit editions)

Microsoft Excel 2013 RT Service Pack 1

Microsoft Excel 2013 Service Pack 1 (32-bit editions)

Microsoft Excel 2013 Service Pack 1 (64-bit editions)

Microsoft Excel 2016 (32-bit edition)

Microsoft Excel 2016 (64-bit edition)

Microsoft Office 2010 Service Pack 2 (32-bit editions)

Microsoft Office 2010 Service Pack 2 (64-bit editions)

Microsoft Office 2016 for Mac

Microsoft Office 2019 for 32-bit editions

Microsoft Office 2019 for 64-bit editions

Microsoft Office 2019 for Mac

Microsoft Office Compatibility Pack Service Pack 3

Microsoft Office 365 ProPlus for 32-bit Systems

Microsoft Office 365 ProPlus for 64-bit Systems

16

CVE-2018-8598

Information Disclosure Vulnerability

Microsoft Excel 2010 Service Pack 2 (32-bit editions)

Microsoft Excel 2010 Service Pack 2 (64-bit editions)

Microsoft Excel 2013 RT Service Pack 1

Microsoft Excel 2013 Service Pack 1 (32-bit editions)

Microsoft Excel 2013 Service Pack 1 (64-bit editions)

Microsoft Excel 2016 (32-bit edition)

Microsoft Excel 2016 (64-bit edition)

Microsoft Office 2010 Service Pack 2 (32-bit editions)

Microsoft Office 2010 Service Pack 2 (64-bit editions)

Microsoft Office 2016 for Mac

Microsoft Office 2019 for 32-bit editions

Microsoft Office 2019 for 64-bit editions

Microsoft Office 2019 for Mac

Microsoft Office Compatibility Pack Service Pack 3

Microsoft Office 365 ProPlus for 32-bit Systems

Microsoft Office 365 ProPlus for 64-bit Systems

17

CVE-2018-8627

Information Disclosure Vulnerability

Microsoft SharePoint Server 2010 Service Pack 2

Microsoft Excel Services

Microsoft Excel 2010 Service Pack 2 (32-bit editions)

Microsoft Excel 2010 Service Pack 2 (64-bit editions)

Microsoft Excel 2013 RT Service Pack 1

Microsoft Excel 2013 Service Pack 1 (32-bit editions)

Microsoft Excel 2013 Service Pack 1 (64-bit editions)

Microsoft Excel 2016 (32-bit edition)

Microsoft Excel 2016 (64-bit edition)

Microsoft Excel Viewer 2007 Service Pack 3

Microsoft Office 2010 Service Pack 2 (32-bit editions)

Microsoft Office 2010 Service Pack 2 (64-bit editions)

Microsoft Office 2016 for Mac

Microsoft Office 2019 for 32-bit editions

Microsoft Office 2019 for 64-bit editions

Microsoft Office 2019 for Mac

Microsoft Office Compatibility Pack Service Pack 3

Microsoft Office 365 ProPlus for 32-bit Systems

Microsoft Office 365 ProPlus for 64-bit Systems

18

CVE-2018-8628

Remote Code Execution Vulnerability

Microsoft Office 2016 for Mac

Microsoft Office 2019 for 32-bit editions

Microsoft Office 2019 for 64-bit editions

Microsoft Office 2019 for Mac

Microsoft Office Compatibility Pack Service Pack 3

Microsoft Office Web Apps 2010 Service Pack 2

Microsoft Office Web Apps 2013 Service Pack 1

Microsoft PowerPoint 2010 Service Pack 2 (32-bit editions)

Microsoft PowerPoint 2010 Service Pack 2 (64-bit editions)

Microsoft PowerPoint 2013 RT Service Pack 1

Microsoft PowerPoint 2013 Service Pack 1 (32-bit editions)

Microsoft PowerPoint 2013 Service Pack 1 (64-bit editions)

Microsoft PowerPoint 2016 (32-bit edition)

Microsoft PowerPoint 2016 (64-bit edition)

Microsoft PowerPoint Viewer

Microsoft SharePoint Enterprise Server 2016

Microsoft SharePoint Server 2013 Service Pack 1

Microsoft SharePoint Server 2019

Microsoft Office 365 ProPlus for 32-bit Systems

Microsoft Office 365 ProPlus for 64-bit Systems

Microsoft Office Online Server

19

CVE-2018-8635

Elevation of Privilege Vulnerability

Microsoft SharePoint Enterprise Server 2013 Service Pack 1

Microsoft SharePoint Enterprise Server 2016

Microsoft SharePoint Foundation 2010 Service Pack 2

20

CVE-2018-8636

Remote Code Execution Vulnerability

Microsoft Excel 2010 Service Pack 2 (32-bit editions)

Microsoft Excel 2010 Service Pack 2 (64-bit editions)

Microsoft Excel 2013 RT Service Pack 1

Microsoft Excel 2013 Service Pack 1 (32-bit editions)

Microsoft Excel 2013 Service Pack 1 (64-bit editions)

Microsoft Excel 2016 (32-bit edition)

Microsoft Excel 2016 (64-bit edition)

Microsoft Office 2019 for 32-bit editions

Microsoft Office 2019 for 64-bit editions

Microsoft Office 365 ProPlus for 32-bit Systems

Microsoft Office 365 ProPlus for 64-bit Systems

21

CVE-2018-8650

Cross Site Scripting Vulnerability

Microsoft SharePoint Enterprise Server 2016

22

CVE-2018-8477

Information Disclosure Vulnerability

Microsoft Windows 10 for 32-bit Systems

Microsoft Windows 10 for x64-based Systems

Microsoft Windows 10 Version 1607 for 32-bit Systems

Microsoft Windows 10 Version 1607 for x64-based Systems

Microsoft Windows 10 Version 1703 for 32-bit Systems

Microsoft Windows 10 Version 1703 for x64-based Systems

Microsoft Windows 10 Version 1709 for 32-bit Systems

Microsoft Windows 10 Version 1709 for 64-based Systems

Microsoft Windows 10 Version 1709 for ARM64-based Systems

Microsoft Windows 10 Version 1803 for 32-bit Systems

Microsoft Windows 10 Version 1803 for ARM64-based Systems

Microsoft Windows 10 Version 1803 for x64-based Systems

Microsoft Windows 10 Version 1809 for 32-bit Systems

Microsoft Windows 10 Version 1809 for ARM64-based Systems

Microsoft Windows 10 Version 1809 for x64-based Systems

Microsoft Windows 7 for 32-bit Systems Service Pack 1

Microsoft Windows 7 for x64-based Systems Service Pack 1

Microsoft Windows 8.1 for 32-bit systems

Microsoft Windows 8.1 for x64-based systems

Microsoft Windows RT 8.1

Microsoft Windows Server 2008 for 32-bit Systems Service Pack 2

Microsoft Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)

Microsoft Windows Server 2008 for Itanium-Based Systems Service Pack 2

Microsoft Windows Server 2008 for x64-based Systems Service Pack 2

Microsoft Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)

Microsoft Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1

Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1

Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Microsoft Windows Server 2012

Microsoft Windows Server 2012 (Server Core installation)

Microsoft Windows Server 2012 R2

Microsoft Windows Server 2012 R2 (Server Core installation)

Microsoft Windows Server 2016

Microsoft Windows Server 2016 (Server Core installation)

Microsoft Windows Server 2019

Microsoft Windows Server 2019 (Server Core installation)

Microsoft Windows Server, version 1709 (Server Core Installation)

Microsoft Windows Server, version 1803 (Server Core Installation)

23

CVE-2018-8611

Elevation of Privilege Vulnerability

Microsoft Windows 10 for 32-bit Systems

Microsoft Windows 10 for x64-based Systems

Microsoft Windows 10 Version 1607 for 32-bit Systems

Microsoft Windows 10 Version 1607 for x64-based Systems

Microsoft Windows 10 Version 1703 for 32-bit Systems

Microsoft Windows 10 Version 1703 for x64-based Systems

Microsoft Windows 10 Version 1709 for 32-bit Systems

Microsoft Windows 10 Version 1709 for 64-based Systems

Microsoft Windows 10 Version 1709 for ARM64-based Systems

Microsoft Windows 10 Version 1803 for 32-bit Systems

Microsoft Windows 10 Version 1803 for ARM64-based Systems

Microsoft Windows 10 Version 1803 for x64-based Systems

Microsoft Windows 10 Version 1809 for 32-bit Systems

Microsoft Windows 10 Version 1809 for ARM64-based Systems

Microsoft Windows 10 Version 1809 for x64-based Systems

Microsoft Windows 7 for 32-bit Systems Service Pack 1

Microsoft Windows 7 for x64-based Systems Service Pack 1

Microsoft Windows 8.1 for 32-bit systems

Microsoft Windows 8.1 for x64-based systems

Microsoft Windows RT 8.1

Microsoft Windows Server 2008 for 32-bit Systems Service Pack 2

Microsoft Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)

Microsoft Windows Server 2008 for Itanium-Based Systems Service Pack 2

Microsoft Windows Server 2008 for x64-based Systems Service Pack 2

Microsoft Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)

Microsoft Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1

Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1

Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Microsoft Windows Server 2012

Microsoft Windows Server 2012 (Server Core installation)

Microsoft Windows Server 2012 R2

Microsoft Windows Server 2012 R2 (Server Core installation)

Microsoft Windows Server 2016

Microsoft Windows Server 2016 (Server Core installation)

Microsoft Windows Server 2019

Microsoft Windows Server 2019 (Server Core installation)

Microsoft Windows Server, version 1709 (Server Core Installation)

Microsoft Windows Server, version 1803 (Server Core Installation)

24

CVE-2018-8621

Information Disclosure Vulnerability

Microsoft Windows 7 for 32-bit Systems Service Pack 1

Microsoft Windows 7 for x64-based Systems Service Pack 1

Microsoft Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1

Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1

Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Microsoft Windows Server 2012

Microsoft Windows Server 2012 (Server Core installation)

25

CVE-2018-8622

Information Disclosure Vulnerability

Microsoft Windows 7 for 32-bit Systems Service Pack 1

Microsoft Windows 7 for x64-based Systems Service Pack 1

Microsoft Windows 8.1 for 32-bit systems

Microsoft Windows 8.1 for x64-based systems

Microsoft Windows RT 8.1

Microsoft Windows Server 2008 for 32-bit Systems Service Pack 2

Microsoft Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)

Microsoft Windows Server 2008 for Itanium-Based Systems Service Pack 2

Microsoft Windows Server 2008 for x64-based Systems Service Pack 2

Microsoft Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)

Microsoft Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1

Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1

Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Microsoft Windows Server 2012

Microsoft Windows Server 2012 (Server Core installation)

Microsoft Windows Server 2012 R2

Microsoft Windows Server 2012 R2 (Server Core installation)

26

CVE-2018-8637

Information Disclosure Vulnerability

Microsoft Windows 10 Version 1803 for 32-bit Systems

Microsoft Windows 10 Version 1803 for ARM64-based Systems

Microsoft Windows 10 Version 1803 for x64-based Systems

Microsoft Windows 10 Version 1809 for 32-bit Systems

Microsoft Windows 10 Version 1809 for ARM64-based Systems

Microsoft Windows 10 Version 1809 for x64-based Systems

Microsoft Windows Server 2019

Microsoft Windows Server 2019 (Server Core installation)

Microsoft Windows Server, version 1803 (Server Core Installation)

27

CVE-2018-8639

Elevation of Privilege Vulnerability

Microsoft Windows 10 for 32-bit Systems

Microsoft Windows 10 for x64-based Systems

Microsoft Windows 10 Version 1607 for 32-bit Systems

Microsoft Windows 10 Version 1607 for x64-based Systems

Microsoft Windows 10 Version 1703 for 32-bit Systems

Microsoft Windows 10 Version 1703 for x64-based Systems

Microsoft Windows 10 Version 1709 for 32-bit Systems

Microsoft Windows 10 Version 1709 for 64-based Systems

Microsoft Windows 10 Version 1709 for ARM64-based Systems

Microsoft Windows 10 Version 1803 for 32-bit Systems

Microsoft Windows 10 Version 1803 for ARM64-based Systems

Microsoft Windows 10 Version 1803 for x64-based Systems

Microsoft Windows 10 Version 1809 for 32-bit Systems

Microsoft Windows 10 Version 1809 for ARM64-based Systems

Microsoft Windows 10 Version 1809 for x64-based Systems

Microsoft Windows 7 for 32-bit Systems Service Pack 1

Microsoft Windows 7 for x64-based Systems Service Pack 1

Microsoft Windows 8.1 for 32-bit systems

Microsoft Windows 8.1 for x64-based systems

Microsoft Windows RT 8.1

Microsoft Windows Server 2008 for 32-bit Systems Service Pack 2

Microsoft Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)

Microsoft Windows Server 2008 for Itanium-Based Systems Service Pack 2

Microsoft Windows Server 2008 for x64-based Systems Service Pack 2

Microsoft Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)

Microsoft Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1

Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1

Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Microsoft Windows Server 2012

Microsoft Windows Server 2012 (Server Core installation)

Microsoft Windows Server 2012 R2

Microsoft Windows Server 2012 R2 (Server Core installation)

Microsoft Windows Server 2016

Microsoft Windows Server 2016 (Server Core installation)

Microsoft Windows Server 2019

Microsoft Windows Server 2019 (Server Core installation)

Microsoft Windows Server, version 1709 (Server Core Installation)

Microsoft Windows Server, version 1803 (Server Core Installation)

28

CVE-2018-8641

Elevation of Privilege Vulnerability

Microsoft Windows 10 for 32-bit Systems

Microsoft Windows 10 for x64-based Systems

Microsoft Windows 10 Version 1607 for 32-bit Systems

Microsoft Windows 10 Version 1607 for x64-based Systems

Microsoft Windows 10 Version 1703 for 32-bit Systems

Microsoft Windows 10 Version 1703 for x64-based Systems

Microsoft Windows 10 Version 1709 for 32-bit Systems

Microsoft Windows 10 Version 1709 for 64-based Systems

Microsoft Windows 10 Version 1709 for ARM64-based Systems

Microsoft Windows 10 Version 1803 for 32-bit Systems

Microsoft Windows 10 Version 1803 for ARM64-based Systems

Microsoft Windows 10 Version 1803 for x64-based Systems

Microsoft Windows 10 Version 1809 for 32-bit Systems

Microsoft Windows 10 Version 1809 for ARM64-based Systems

Microsoft Windows 10 Version 1809 for x64-based Systems

Microsoft Windows 7 for 32-bit Systems Service Pack 1

Microsoft Windows 7 for x64-based Systems Service Pack 1

Microsoft Windows 8.1 for 32-bit systems

Microsoft Windows 8.1 for x64-based systems

Microsoft Windows RT 8.1

Microsoft Windows Server 2008 for 32-bit Systems Service Pack 2

Microsoft Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)

Microsoft Windows Server 2008 for Itanium-Based Systems Service Pack 2

Microsoft Windows Server 2008 for x64-based Systems Service Pack 2

Microsoft Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)

Microsoft Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1

Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1

Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Microsoft Windows Server 2012

Microsoft Windows Server 2012 (Server Core installation)

Microsoft Windows Server 2012 R2

Microsoft Windows Server 2012 R2 (Server Core installation)

Microsoft Windows Server 2016

Microsoft Windows Server 2016 (Server Core installation)

Microsoft Windows Server 2019

Microsoft Windows Server 2019 (Server Core installation)

Microsoft Windows Server, version 1709 (Server Core Installation)

Microsoft Windows Server, version 1803 (Server Core Installation)

29

CVE-2018-8514

Information Disclosure Vulnerability

Microsoft Windows 10 for 32-bit Systems

Microsoft Windows 10 for x64-based Systems

Microsoft Windows 10 Version 1607 for 32-bit Systems

Microsoft Windows 10 Version 1607 for x64-based Systems

Microsoft Windows 10 Version 1703 for 32-bit Systems

Microsoft Windows 10 Version 1703 for x64-based Systems

Microsoft Windows 10 Version 1709 for 32-bit Systems

Microsoft Windows 10 Version 1709 for 64-based Systems

Microsoft Windows 10 Version 1709 for ARM64-based Systems

Microsoft Windows 10 Version 1803 for 32-bit Systems

Microsoft Windows 10 Version 1803 for ARM64-based Systems

Microsoft Windows 10 Version 1803 for x64-based Systems

Microsoft Windows 10 Version 1809 for 32-bit Systems

Microsoft Windows 10 Version 1809 for ARM64-based Systems

Microsoft Windows 10 Version 1809 for x64-based Systems

Microsoft Windows 7 for 32-bit Systems Service Pack 1

Microsoft Windows 7 for x64-based Systems Service Pack 1

Microsoft Windows 8.1 for 32-bit systems

Microsoft Windows 8.1 for x64-based systems

Microsoft Windows RT 8.1

Microsoft Windows Server 2008 for 32-bit Systems Service Pack 2

Microsoft Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)

Microsoft Windows Server 2008 for Itanium-Based Systems Service Pack 2

Microsoft Windows Server 2008 for x64-based Systems Service Pack 2

Microsoft Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)

Microsoft Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1

Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1

Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Microsoft Windows Server 2012

Microsoft Windows Server 2012 (Server Core installation)

Microsoft Windows Server 2012 R2

Microsoft Windows Server 2012 R2 (Server Core installation)

Microsoft Windows Server 2016

Microsoft Windows Server 2016 (Server Core installation)

Microsoft Windows Server 2019

Microsoft Windows Server 2019 (Server Core installation)

Microsoft Windows Server, version 1709 (Server Core Installation)

Microsoft Windows Server, version 1803 (Server Core Installation)

30

CVE-2018-8595

Information Disclosure Vulnerability

Microsoft Windows 10 for 32-bit Systems

Microsoft Windows 10 for x64-based Systems

Microsoft Windows 10 Version 1607 for 32-bit Systems

Microsoft Windows 10 Version 1607 for x64-based Systems

Microsoft Windows 10 Version 1703 for 32-bit Systems

Microsoft Windows 10 Version 1703 for x64-based Systems

Microsoft Windows 10 Version 1709 for 32-bit Systems

Microsoft Windows 10 Version 1709 for 64-based Systems

Microsoft Windows 10 Version 1709 for ARM64-based Systems

Microsoft Windows 10 Version 1803 for 32-bit Systems

Microsoft Windows 10 Version 1803 for ARM64-based Systems

Microsoft Windows 10 Version 1803 for x64-based Systems

Microsoft Windows 10 Version 1809 for 32-bit Systems

Microsoft Windows 10 Version 1809 for ARM64-based Systems

Microsoft Windows 10 Version 1809 for x64-based Systems

Microsoft Windows 7 for 32-bit Systems Service Pack 1

Microsoft Windows 7 for x64-based Systems Service Pack 1

Microsoft Windows 8.1 for 32-bit systems

Microsoft Windows 8.1 for x64-based systems

Microsoft Windows RT 8.1

Microsoft Windows Server 2008 for 32-bit Systems Service Pack 2

Microsoft Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)

Microsoft Windows Server 2008 for Itanium-Based Systems Service Pack 2

Microsoft Windows Server 2008 for x64-based Systems Service Pack 2

Microsoft Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)

Microsoft Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1

Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1

Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Microsoft Windows Server 2012

Microsoft Windows Server 2012 (Server Core installation)

Microsoft Windows Server 2012 R2

Microsoft Windows Server 2012 R2 (Server Core installation)

Microsoft Windows Server 2016

Microsoft Windows Server 2016 (Server Core installation)

Microsoft Windows Server 2019

Microsoft Windows Server 2019 (Server Core installation)

Microsoft Windows Server, version 1709 (Server Core Installation)

Microsoft Windows Server, version 1803 (Server Core Installation)

31

CVE-2018-8596

Information Disclosure Vulnerability

Microsoft Windows 10 for 32-bit Systems

Microsoft Windows 10 for x64-based Systems

Microsoft Windows 10 Version 1607 for 32-bit Systems

Microsoft Windows 10 Version 1607 for x64-based Systems

Microsoft Windows 10 Version 1703 for 32-bit Systems

Microsoft Windows 10 Version 1703 for x64-based Systems

Microsoft Windows 10 Version 1709 for 32-bit Systems

Microsoft Windows 10 Version 1709 for 64-based Systems

Microsoft Windows 10 Version 1709 for ARM64-based Systems

Microsoft Windows 10 Version 1803 for 32-bit Systems

Microsoft Windows 10 Version 1803 for ARM64-based Systems

Microsoft Windows 10 Version 1803 for x64-based Systems

Microsoft Windows 10 Version 1809 for 32-bit Systems

Microsoft Windows 10 Version 1809 for ARM64-based Systems

Microsoft Windows 10 Version 1809 for x64-based Systems

Microsoft Windows 7 for 32-bit Systems Service Pack 1

Microsoft Windows 7 for x64-based Systems Service Pack 1

Microsoft Windows 8.1 for 32-bit systems

Microsoft Windows 8.1 for x64-based systems

Microsoft Windows RT 8.1

Microsoft Windows Server 2008 for 32-bit Systems Service Pack 2

Microsoft Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)

Microsoft Windows Server 2008 for Itanium-Based Systems Service Pack 2

Microsoft Windows Server 2008 for x64-based Systems Service Pack 2

Microsoft Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)

Microsoft Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1

Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1

Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Microsoft Windows Server 2012

Microsoft Windows Server 2012 (Server Core installation)

Microsoft Windows Server 2012 R2

Microsoft Windows Server 2012 R2 (Server Core installation)

Microsoft Windows Server 2016

Microsoft Windows Server 2016 (Server Core installation)

Microsoft Windows Server 2019

Microsoft Windows Server 2019 (Server Core installation)

Microsoft Windows Server, version 1709 (Server Core Installation)

Microsoft Windows Server, version 1803 (Server Core Installation)

32

CVE-2018-8599

Elevation of Privilege Vulnerability

Microsoft Visual Studio 2015 Update 3

Microsoft Visual Studio 2017

Microsoft Visual Studio 2017 version 15.9

Microsoft Windows 10 for 32-bit Systems

Microsoft Windows 10 for x64-based Systems

Microsoft Windows 10 Version 1607 for 32-bit Systems

Microsoft Windows 10 Version 1607 for x64-based Systems

Microsoft Windows 10 Version 1703 for 32-bit Systems

Microsoft Windows 10 Version 1703 for x64-based Systems

Microsoft Windows 10 Version 1709 for 32-bit Systems

Microsoft Windows 10 Version 1709 for 64-based Systems

Microsoft Windows 10 Version 1709 for ARM64-based Systems

Microsoft Windows 10 Version 1803 for 32-bit Systems

Microsoft Windows 10 Version 1803 for ARM64-based Systems

Microsoft Windows 10 Version 1803 for x64-based Systems

Microsoft Windows 10 Version 1809 for 32-bit Systems

Microsoft Windows 10 Version 1809 for ARM64-based Systems

Microsoft Windows 10 Version 1809 for x64-based Systems

Microsoft Windows Server 2016

Microsoft Windows Server 2016 (Server Core installation)

Microsoft Windows Server 2019 (Server Core installation)

Microsoft Windows Server, version 1709 (Server Core Installation)

Microsoft Windows Server, version 1803 (Server Core Installation)

33

CVE-2018-8612

Denial Of Service Vulnerability

Microsoft Windows 10 Version 1607 for 32-bit Systems

Microsoft Windows 10 Version 1607 for x64-based Systems

Microsoft Windows 10 Version 1703 for 32-bit Systems

Microsoft Windows 10 Version 1703 for x64-based Systems

Microsoft Windows 10 Version 1709 for 32-bit Systems

Microsoft Windows 10 Version 1709 for 64-based Systems

Microsoft Windows 10 Version 1709 for ARM64-based Systems

Microsoft Windows 10 Version 1803 for 32-bit Systems

Microsoft Windows 10 Version 1803 for ARM64-based Systems

Microsoft Windows 10 Version 1803 for x64-based Systems

Microsoft Windows 10 Version 1809 for 32-bit Systems

Microsoft Windows 10 Version 1809 for ARM64-based Systems

Microsoft Windows 10 Version 1809 for x64-based Systems

Microsoft Windows Server 2016

Microsoft Windows Server 2016 (Server Core installation)

Microsoft Windows Server 2019

Microsoft Windows Server 2019 (Server Core installation)

Microsoft Windows Server, version 1709 (Server Core Installation)

Microsoft Windows Server, version 1803 (Server Core Installation)

34

CVE-2018-8638

Information Disclosure Vulnerability

Microsoft Windows 10 Version 1809 for 32-bit Systems

Microsoft Windows 10 Version 1809 for ARM64-based Systems

Microsoft Windows 10 Version 1809 for x64-based Systems

Microsoft Windows Server 2019

Microsoft Windows Server 2019 (Server Core installation)

35

CVE-2018-8649

Denial Of Service Vulnerability

Microsoft Windows 10 Version 1809 for 32-bit Systems

Microsoft Windows 10 Version 1809 for ARM64-based Systems

Microsoft Windows 10 Version 1809 for x64-based Systems

Microsoft Windows Server 2019

Microsoft Windows Server 2019 (Server Core installation)

36

CVE-2018-8517

Denial Of Service Vulnerability

Microsoft .NET Framework 3.5

Microsoft .NET Framework 3.5.1

Microsoft .NET Framework 4.5.2

Microsoft .NET Framework 4.6

Microsoft .NET Framework 4.6.1

Microsoft .NET Framework 4.6.2

Microsoft .NET Framework 4.7

Microsoft .NET Framework 4.7.1

Microsoft .NET Framework 4.7.2

Windows 10 Version 1703 for 32-bit Systems

Windows 10 Version 1703 for x64-based Systems

Windows 10 Version 1803 for 32-bit Systems

Windows 10 Version 1803 for x64-based Systems

Windows Server, version 1803 (Server Core Installation)

Windows 10 Version 1809 for 32-bit Systems

Windows 10 Version 1809 for x64-based Systems

Windows Server 2019

Windows Server 2019 (Server Core installation)

Windows 10 Version 1709 for 32-bit Systems

Windows 10 Version 1709 for 64-based Systems

Windows Server, version 1709 (Server Core Installation)

Windows 10 Version 1607 for 32-bit Systems

Windows 10 Version 1607 for x64-based Systems

Windows Server 2016

Windows Server 2016 (Server Core installation)

Windows 8.1 for 32-bit systems

Windows 8.1 for x64-based systems

Windows Server 2012

Windows Server 2012 (Server Core installation)

Windows Server 2012 R2

Windows Server 2012 R2 (Server Core installation)

Windows Server 2008 for 32-bit Systems Service Pack 2

Windows Server 2008 for Itanium-Based Systems Service Pack 2

Windows Server 2008 for x64-based Systems Service Pack 2

Windows 7 for 32-bit Systems Service Pack 1

Windows 7 for x64-based Systems Service Pack 1

Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1

Windows Server 2008 R2 for x64-based Systems Service Pack 1

Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Windows RT 8.1

Windows 10 Version 1709 for ARM64-based Systems

37

CVE-2018-8604

Tampering Vulnerability

Microsoft Exchange Server 2016 Cumulative Update 10

Microsoft Exchange Server 2016 Cumulative Update 11

38

CVE-2018-8652

Cross Site Scripting Vulnerability

Microsoft Windows Azure Pack Rollup 13.1

39

CVE-2018-8651

Cross Site Scripting Vulnerability

Microsoft Dynamics NAV 2017

Microsoft Dynamics NAV 2016

 

 Microsoft's summary of the December 2018 releases can be found here:

https://portal.msrc.microsoft.com/en-us/security-guidance