Risk: High
Microsoft patches one critical and one important issue in January's Patch Tuesday.
The critical security update resides in Transmission Control Protocol/Internet Protocol (TCP/IP) processing. Successful exploitation may lead to an attacker gaining complete control of an affected system.
The important issue has been patched in Microsoft Windows Local Security Authority Subsystem Service (LSASS). The vulnerability may allow an attacker to run arbitrary code with elevated privileges.