Microsoft security patch released in October fixed a vulnerability in how the Windows TCP/IP stack improperly handles ICMPv6 router advertisement packets. A remote hacker can execute the attack without authentication, but not easily. A second security patch is just as serious to an enterprise if not more so, CVE-2020-16952 occurs when an attacker/user uploads a specially crafted SharePoint application package to an affected version of the software fails to check the source markup of an application package and remote code execution can occur.”]

