Risk: High
Microsoft patches three critical and four important issues in December's Patch Tuesday.
The first critical vulnerability addressed resides in DirectX. Two flaws have been reported which may allow code execution if a user opens a specially crafted file used for streaming media in DirectX. The second and third critical vulnerabilities patched have been identified in Windows Media Format and Internet Explorer which may result in remote code execution if a user views a specially crafted web page or file.
Two important vulnerabilities that have been found in Server Message Block Version 2 (SMBv2) and Message Queuing Service (MSMQ) may lead to remote code execution. The other two flaws that may lead to an attacker gaining elevation of privilege reside in Windows kernel and the Macrovision driver.