Microsoft released Patch Tuesday updates for December 2017 that address more than 30 vulnerabilities, including 19 critical browser issues. Microsoft acknowledged researchers from Google, Palo Alto Networks, McAfee and Qihoo 360 for finding the issues. Most of the vulnerabilities reside in the browsers scripting engine, an attack can trigger them by tricking the victim into visiting a specially crafted website or a site that serves malicious ads. The list of flaws addressed by Microsoft also includes a collection of information disclosure issues in Office, a privilege escalation vulnerability affecting SharePoint and a spoofing issue in Exchange.”]
Source: https://securityaffairs.co/wordpress/66676/security/december-microsoft-patch-tuesday.html