Microsoft Security Bulletins

Syndicate content
Microsoft Security Content: Comprehensive Edition
Updated: 3 hours 5 min ago

MS11-100 - Critical : Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (2638420) - Version: 1.3

Wed, 01/02/2012 - 09:00
Severity Rating: Critical
Revision Note: V1.3 (February 1, 2012): Corrected registry keys and installation switches in the deployment tables for Windows Server 2003 and Windows Server 2008, and installation switches in the deployment table for Windows Vista. This is an informational change only. There were no changes to the security update files or detection logic.
Summary: This security update resolves one publicly disclosed vulnerability and three privately reported vulnerabilities in Microsoft .NET Framework. The most severe of these vulnerabilities could allow elevation of privilege if an unauthenticated attacker sends a specially crafted web request to the target site. An attacker who successfully exploited this vulnerability could take any action in the context of an existing account on the ASP.NET site, including executing arbitrary commands. In order to exploit this vulnerability, an attacker must be able to register an account on the ASP.NET site, and must know an existing user name.
Categories: Microsoft, Security

MS11-098 - Important : Vulnerability in Windows Kernel Could Allow Elevation of Privilege (2633171) - Version: 1.1

Wed, 01/02/2012 - 09:00
Severity Rating: Important
Revision Note: V1.1 (February 1, 2012): Added a link to Microsoft Knowledge Base Article 2633171 under Known Issues in the Executive Summary.
Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application designed to exploit the vulnerability. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.
Categories: Microsoft, Security

MS12-004 - Critical : Vulnerabilities in Windows Media Could Allow Remote Code Execution (2636391) - Version: 1.2

Fri, 27/01/2012 - 09:00
Severity Rating: Critical
Revision Note: V1.2 (January 27, 2012): Corrected the aggregate severity rating for the KB2631813 update package in the Affected Software table for all supported editions of Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008. This is a bulletin change only. There were no changes to the security update files or detection logic. Customers should apply all update packages offered for the software installed on their systems. See the update FAQ for details.
Summary: This security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow remote code execution if a user opens a specially crafted media file. An attacker who successfully exploited the vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Categories: Microsoft, Security

Summary for January 2012 - Version: 2.1

Fri, 27/01/2012 - 09:00
Revision Note: V2.1 (January 27, 2012): For MS12-004, corrected the aggregate severity rating for the KB2631813 update package for all supported editions of Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008. See the MS12-004 bulletin for details.
Summary: This bulletin summary lists security bulletins released for January 2012.
Categories: Microsoft, Security

MS11-049 - Important : Vulnerability in the Microsoft XML Editor Could Allow Information Disclosure (2543893) - Version: 2.3

Tue, 24/01/2012 - 09:00
Severity Rating: Important
Revision Note: V2.3 (January 24, 2012): Added an entry to the update FAQ to announce a detection change for KB2251481, KB2251487, and KB2251489 to correct an installation issue. This is a detection change only. There were no changes to the security update files. Customers who have already successfully updated their systems do not need to take any action.
Summary: This security update resolves a privately reported vulnerability in Microsoft XML Editor. The vulnerability could allow information disclosure if a user opened a specially crafted Web Service Discovery (.disco) file with one of the affected software listed in this bulletin. Note that this vulnerability would not allow an attacker to execute code or to elevate their user rights directly, but it could be used to produce information that could be used to try to further compromise the affected system.
Categories: Microsoft, Security

MS11-025 - Important : Vulnerability in Microsoft Foundation Class (MFC) Library Could Allow Remote Code Execution (2500212) - Version: 4.2

Tue, 24/01/2012 - 09:00
Severity Rating: Important
Revision Note: V4.2 (January 24, 2012): Added an entry to the update FAQ to announce a detection change for KB2538242, KB2538243, KB2467173, KB2538218, KB2538241, and KB2542054 to correct an installation issue. This is a detection change only. There were no changes to the security update files. Customers who have already successfully updated their systems do not need to take any action.
Summary: This security update resolves a publicly disclosed vulnerability in certain applications built using the Microsoft Foundation Class (MFC) Library. The vulnerability could allow remote code execution if a user opens a legitimate file associated with such an affected application, and the file is located in the same network folder as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by the affected application.
Categories: Microsoft, Security

Microsoft Security Advisory (2641690): Fraudulent Digital Certificates Could Allow Spoofing - Version: 3.0

Thu, 19/01/2012 - 09:00
Revision Note: V3.0 (January 19, 2012): Revised to announce the release of an update for Windows Mobile 6.x, Windows Phone 7, and Windows Phone 7.5 devices.
Summary: Microsoft is aware that DigiCert Sdn. Bhd, a Malaysian subordinate certification authority (CA) under Entrust and GTE CyberTrust, has issued 22 certificates with weak 512 bit keys. These weak encryption keys, when broken, could allow an attacker to use the certificates fraudulently to spoof content, perform phishing attacks, or perform man-in-the-middle attacks against all Web browser users including users of Internet Explorer. While this is not a vulnerability in a Microsoft product, this issue affects all supported releases of Microsoft Windows.
Categories: Microsoft, Security

MS12-006 - Important : Vulnerability in SSL/TLS Could Allow Information Disclosure (2643584) - Version: 1.1

Wed, 18/01/2012 - 09:00
Severity Rating: Important
Revision Note: V1.1 (January 18, 2012): Added MS10-085 as a bulletin replaced by the KB2585542 update for Windows 7 for 32-bit Systems, Windows 7 for x64-based Systems, Windows Server 2008 R2 for x64-based Systems, and Windows Server 2008 R2 for Itanium-based Systems. This is an informational change only. There were no changes to the detection logic or the update files.
Summary: This security update resolves a publicly disclosed vulnerability in SSL 3.0 and TLS 1.0. This vulnerability affects the protocol itself and is not specific to the Windows operating system. The vulnerability could allow information disclosure if an attacker intercepts encrypted web traffic served from an affected system. TLS 1.1, TLS 1.2, and all cipher suites that do not use CBC mode are not affected.
Categories: Microsoft, Security

Summary for June 2011 - Version: 3.1

Wed, 18/01/2012 - 09:00
Revision Note: V3.1 (January 18, 2012): For MS11-049, added a note to the Affected Software and Download Locations section to clarify that this update also applies to 32-bit and x64-based SQL Server 2008 and SQL Server 2008 R2 Express and Express Advanced Editions.
Summary: This bulletin summary lists security bulletins released for June 2011.
Categories: Microsoft, Security

MS12-007 - Important : Vulnerability in AntiXSS Library Could Allow Information Disclosure (2607664) - Version: 2.1

Mon, 16/01/2012 - 09:00
Severity Rating: Important
Revision Note: V2.1 (January 16, 2012): Added a link to Microsoft Knowledge Base Article 2607664 under Known Issues in the Executive Summary. Also, revised entry in the update FAQ to clarify why the upgrade to AntiXSS Library version 4.2.1 is only available from the Microsoft Download Center.
Summary: This security update resolves one privately reported vulnerability in the Microsoft Anti-Cross Site Scripting (AntiXSS) Library. The vulnerability could allow information disclosure if an attacker passes a malicious script to a website using the sanitization function of the AntiXSS Library. The consequences of the disclosure of that information depends on the nature of the information itself. Note that this vulnerability would not allow an attacker to execute code or to elevate the attacker's user rights directly, but it could be used to produce information that could be used to try to further compromise the affected system. Only sites that use the sanitization module of the AntiXSS Library are affected by this vulnerability.
Categories: Microsoft, Security

Summary for January 2012 - Version: 2.0

Wed, 11/01/2012 - 09:00
Revision Note: V2.0 (January 11, 2012): For MS12-003, corrected exploitability assessment for latest software release in the Exploitability Index for CVE-2012-0005. For MS12-007, revised to announce bulletin rereleased. See the MS12-007 bulletin for more information.
Summary: This bulletin summary lists security bulletins released for January 2012.
Categories: Microsoft, Security

MS12-006 - Important : Vulnerability in SSL/TLS Could Allow Information Disclosure (2643584) - Version: 1.0

Tue, 10/01/2012 - 09:00
Severity Rating: Important
Revision Note: V1.0 (January 10, 2012): Bulletin published.
Summary: This security update resolves a publicly disclosed vulnerability in SSL 3.0 and TLS 1.0. This vulnerability affects the protocol itself and is not specific to the Windows operating system. The vulnerability could allow information disclosure if an attacker intercepts encrypted web traffic served from an affected system. TLS 1.1, TLS 1.2, and all cipher suites that do not use CBC mode are not affected.
Categories: Microsoft, Security

MS12-005 - Important : Vulnerability in Microsoft Windows Could Allow Remote Code Execution (2584146) - Version: 1.0

Tue, 10/01/2012 - 09:00
Severity Rating: Important
Revision Note: V1.0 (January 10, 2012): Bulletin published.
Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Office file containing a malicious embedded ClickOnce application. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Categories: Microsoft, Security

MS12-003 - Important : Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2646524) - Version: 1.0

Tue, 10/01/2012 - 09:00
Severity Rating: Important
Revision Note: V1.0 (January 10, 2012): Bulletin published.
Summary: This security update resolves one privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker successfully exploited this vulnerability. The attacker could then take complete control of the affected system and install programs; view, change, or delete data; or create new accounts with full user rights. Only systems configured with a Chinese, Japanese, or Korean system locale are affected.
Categories: Microsoft, Security

MS12-002 - Important : Vulnerability in Windows Object Packager Could Allow Remote Code Execution (2603381) - Version: 1.0

Tue, 10/01/2012 - 09:00
Severity Rating: Important
Revision Note: V1.0 (January 10, 2012): Bulletin published.
Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate file with an embedded packaged object that is located in the same network directory as a specially crafted executable file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Categories: Microsoft, Security

MS12-001 - Important : Vulnerability in Windows Kernel Could Allow Security Feature Bypass (2644615) - Version: 1.0

Tue, 10/01/2012 - 09:00
Severity Rating: Important
Revision Note: V1.0 (January 10, 2012): Bulletin published.
Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow an attacker to bypass the SafeSEH security feature in a software application. An attacker could then use other vulnerabilities to leverage the structured exception handler to run arbitrary code. Only software applications that were compiled using Microsoft Visual C++ .NET 2003 can be used to exploit this vulnerability.
Categories: Microsoft, Security

MS11-099 - Important : Cumulative Security Update for Internet Explorer (2618444) - Version: 1.2

Tue, 10/01/2012 - 09:00
Severity Rating: Important
Revision Note: V1.2 (January 10, 2012): Announced that this update, MS11-099, enables the protections provided in the Vulnerability in SSL/TLS Could Allow Information Disclosure update, MS12-006, for Internet Explorer. For more information, see the Update FAQ.
Summary: This security update resolves three privately reported vulnerabilities in Internet Explorer. The most severe vulnerability could allow remote code execution if a user opens a legitimate HyperText Markup Language (HTML) file that is located in the same directory as a specially crafted dynamic link library (DLL) file.
Categories: Microsoft, Security

Microsoft Security Advisory (2588513): Vulnerability in SSL/TLS Could Allow Information Disclosure - Version: 2.0

Tue, 10/01/2012 - 09:00
Revision Note: V2.0 (January 10, 2012): Advisory updated to reflect publication of security bulletin.
Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS12-006 to address this issue. For more information about this issue, including download links for an available security update, please review MS12-006. The vulnerability addressed is the SSL/TLS Information Disclosure Vulnerability - CVE-2011-3389.
Categories: Microsoft, Security

Microsoft Security Advisory (2659883): Vulnerability in ASP.NET Could Allow Denial of Service - Version: 2.0

Thu, 29/12/2011 - 09:00
Revision Note: V2.0 (December 29, 2011): Advisory updated to reflect publication of security bulletin.
Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS11-100 to address this issue. For more information about this issue, including download links for an available security update, please review MS11-100. The vulnerability addressed is the Collisions in HashTable May Cause DoS Vulnerability - CVE-2011-3414.
Categories: Microsoft, Security

Summary for December 2011 - Version: 2.0

Thu, 29/12/2011 - 09:00
Revision Note: V2.0 (December 29, 2011): Added Microsoft Security Bulletin MS11-100, Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (2638420). Also added the bulletin webcast link for this out-of-band security bulletin.
Summary: This bulletin summary lists security bulletins released for December 2011.
Categories: Microsoft, Security

Martijn's van Alles en (N)iets Website Feeds

Blocked Spam Attempts

Total Stopped Spam Attempts 12,999