Microsoft IT Security Bulletins

Microsoft Security Content: Comprehensive Edition
Microsoft Security Content: Comprehensive Edition
Updated: 6 hours 5 min ago

Microsoft Security Bulletin Summary for August 2010

September 1, 2010 - 01:00
Revision Note: V2.1 (September 1, 2010): Added note for MS10-056 to inform customers using Word 2007 that in addition to security update package KB2251419, they also need to install the security update package KB2277947.Summary: This bulletin summary lists security bulletins released for August 2010.

MS10-056 - Critical: Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (2269638) - Version:1.3

September 1, 2010 - 01:00
Severity Rating: Critical - Revision Note: V1.3 (September 1, 2010): Added note to the affected software table to inform customers using Word 2007 that in addition to security update package KB2251419, they also need to install the security update package KB2277947 to be protected from the vulnerabilities described in this bulletin.Summary: This security update resolves four privately reported vulnerabilities in Microsoft Office. The most severe vulnerabilities could allow remote code execution if a user opens or previews a specially crafted RTF e-mail message. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

MS10-049 - Critical: Vulnerabilities in SChannel could allow Remote Code Execution (980436) - Version:1.1

September 1, 2010 - 01:00
Severity Rating: Critical - Revision Note: V1.1 (September 1, 2010): Corrected the bulletin replacement information for this update. This is an informational change only. There were no changes to the detection logic or the update files.Summary: This security update resolves one publicly disclosed vulnerability and one privately reported vulnerability in the Secure Channel (SChannel) security package in Windows. The more severe of these vulnerabilities could allow remote code execution if a user visits a specially crafted Web site that is designed to exploit these vulnerabilities through an Internet Web browser. In all cases, however, an attacker would have no way to force users to visit these Web sites. Instead, an attacker would have to convince users to visit the Web site, typically by getting them to click a link in an e-mail message or in an Instant Messenger message that takes users to the attacker's Web site.

Microsoft Security Advisory (2269637): Insecure Library Loading Could Allow Remote Code Execution

August 31, 2010 - 01:00
Revision Note: V1.1 (August 31, 2010) Added a link to Microsoft Knowledge Base Article 2264107 to provide an automated Microsoft Fix it solution for the workaround, Disable loading of libraries from WebDAV and remote network shares.Summary: Microsoft is aware that research has been published detailing a remote attack vector for a class of vulnerabilities that affects how applications load external libraries.

MS10-056 - Critical: Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (2269638) - Version:1.2

August 25, 2010 - 01:00
Severity Rating: Critical - Revision Note: V1.2 (August 25, 2010): Added a link to Microsoft Knowledge Base Article 2269638 under Known Issues in the Executive Summary.Summary: This security update resolves four privately reported vulnerabilities in Microsoft Office. The most severe vulnerabilities could allow remote code execution if a user opens or previews a specially crafted RTF e-mail message. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

MS10-054 - Critical: Vulnerabilities in SMB Server Could Allow Remote Code Execution (982214) - Version:1.2

August 25, 2010 - 01:00
Severity Rating: Critical - Revision Note: V1.2 (August 25, 2010): Removed erroneous reference to a Microsoft Fix it solution from the workarounds for SMB Stack Exhaustion Vulnerability - CVE-2010-2552.Summary: This security update resolves several privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow remote code execution if an attacker created a specially crafted SMB packet and sent the packet to an affected system. Firewall best practices and standard default firewall configurations can help protect networks from attacks originating outside the enterprise perimeter that would attempt to exploit these vulnerabilities.

MS10-046 - Critical: Vulnerability in Windows Shell Could Allow Remote Code Execution (2286198) - Version:1.2

August 24, 2010 - 01:00
Severity Rating: Critical - Revision Note: V1.2 (August 24, 2010): Added an update FAQ to announce a detection change. This is a detection change only. There were no changes to the security update files in this bulletin. Customers who have already installed the update successfully do not need to reinstall.Summary: This security update resolves a publicly disclosed vulnerability in Windows Shell. The vulnerability could allow remote code execution if the icon of a specially crafted shortcut is displayed. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Microsoft Security Advisory (2269637): Insecure Library Loading Could Allow Remote Code Execution

August 23, 2010 - 01:00
Revision Note: V1.0 (August 23, 2010) Advisory published.Summary: Microsoft is aware that research has been published detailing a remote attack vector for a class of vulnerabilities that affects how applications load external libraries.

Microsoft Security Advisory (2269637): Insecure Library Loading Could Allow Remote Code Execution

August 23, 2010 - 01:00
Revision Note: V1.0 (August 23, 2010) Advisory published.Summary: Microsoft is aware that research has been published detailing a remote attack vector for a class of vulnerabilities that affects how applications load external libraries.

MS10-058 - Important: Vulnerabilities in TCP/IP Could Allow Elevation of Privilege (978886) - Version:1.1

August 18, 2010 - 01:00
Severity Rating: Important - Revision Note: V1.1 (August 18, 2010): Added workaround for IPv6 Memory Corruption Vulnerability - CVE-2010-1892.Summary: This security update resolves two privately reported vulnerabilities in Microsoft Windows. The more severe of these vulnerabilities could allow elevation of privilege due to an error in the processing of a specific input buffer. An attacker who is able to log on to the target system could exploit this vulnerability and run arbitrary code with system-level privileges. The attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

MS10-055 - Critical: Vulnerability in Cinepak Codec Could Allow Remote Code Execution (982665) - Version:1.1

August 12, 2010 - 01:00
Severity Rating: Critical - Revision Note: V1.1 (August 12, 2010): Added Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2 to the Non-Affected Software table.Summary: This security update resolves a privately reported vulnerability in Cinepak Codec. The vulnerability could allow remote code execution if a user opens a specially crafted media file or receives specially crafted streaming content from a Web site or any application that delivers Web content. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Microsoft Security Bulletin Summary for March 2010

August 11, 2010 - 01:00
Revision Note: V3.1 (August 11, 2010): Removed Windows Movie Maker 2.6 as an affected component on Windows 7 for MS10-016.Summary: This bulletin summary lists security bulletins released for March 2010.

MS10-060 - Critical: Vulnerabilities in the Microsoft .NET Common Language Runtime and in Microsoft Silverlight Could Allow Remote Code Execution (2265906) - Version:1.1

August 11, 2010 - 01:00
Severity Rating: Critical - Revision Note: V1.1 (August 11, 2010): Added a link to Microsoft Knowledge Base Article 2265906 under Known Issues in the Executive Summary. Also corrected the entries for Microsoft Silverlight in the Non-Affected Software table and the workarounds for Microsoft Silverlight Memory Corruption Vulnerability - CVE-2010-0019.Summary: This security update resolves two privately reported vulnerabilities in Microsoft .NET Framework and Microsoft Silverlight. The vulnerabilities could allow remote code execution on a client system if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs) or Silverlight applications, or if an attacker succeeds in convincing a user to run a specially crafted Microsoft .NET application. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The vulnerabilities could also allow remote code execution on a server system running IIS, if that server allows processing ASP.NET pages and an attacker succeeds in uploading a specially crafted ASP.NET page to that server and executing the page, as could be the case in a Web hosting scenario.

MS10-057 - Important: Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution (2269707) - Version:1.1

August 11, 2010 - 01:00
Severity Rating: Important - Revision Note: V1.1 (August 11, 2010): Added a link to Microsoft Knowledge Base Article 2269707 under Known Issues in the Executive Summary.Summary: This security update resolves a privately reported vulnerability in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

MS10-056 - Critical: Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (2269638) - Version:1.1

August 11, 2010 - 01:00
Severity Rating: Critical - Revision Note: V1.1 (August 11, 2010): Corrected the update package names for Microsoft Office Word Viewer and Microsoft Office Compatibility Pack in the deployment reference tables. This is an informational change only. There were no changes to the security update files or detection logic.Summary: This security update resolves four privately reported vulnerabilities in Microsoft Office. The most severe vulnerabilities could allow remote code execution if a user opens or previews a specially crafted RTF e-mail message. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

MS10-054 - Critical: Vulnerabilities in SMB Server Could Allow Remote Code Execution (982214) - Version:1.1

August 11, 2010 - 01:00
Severity Rating: Critical - Revision Note: V1.1 (August 11, 2010): Corrected the security impact for Windows Server 2003, Windows 7, and Windows Server 2008 R2 for SMB Pool Overflow Vulnerability - CVE-2010-2550. This is an informational change only.Summary: This security update resolves several privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow remote code execution if an attacker created a specially crafted SMB packet and sent the packet to an affected system. Firewall best practices and standard default firewall configurations can help protect networks from attacks originating outside the enterprise perimeter that would attempt to exploit these vulnerabilities.

MS10-050 - Important: Vulnerability in Windows Movie Maker Could Allow Remote Code Execution (981997) - Version:1.1

August 11, 2010 - 01:00
Severity Rating: Important - Revision Note: V1.1 (August 11, 2010): Added a link to Microsoft Knowledge Base Article 981997 under Known Issues in the Executive Summary.Summary: This security update resolves a privately reported vulnerability in Windows Movie Maker. The vulnerability could allow remote code execution if an attacker sent a specially crafted Movie Maker project file and convinced the user to open the specially crafted file. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

MS10-016 - Important: Vulnerability in Windows Movie Maker Could Allow Remote Code Execution (975561) - Version:2.3

August 11, 2010 - 01:00
Severity Rating: Important - Revision Note: V2.3 (August 11, 2010): Removed Windows Movie Maker 2.6 as an affected component on Windows 7.Summary: This security update addresses a privately reported vulnerability in Windows Movie Maker and Microsoft Producer 2003. Windows Live Movie Maker, which is available for Windows Vista and Windows 7, is not affected by this vulnerability. The vulnerability could allow remote code execution if an attacker sent a specially crafted Movie Maker or Microsoft Producer project file and convinced the user to open the specially crafted file. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Microsoft Security Advisory (977377): Vulnerability in TLS/SSL Could Allow Spoofing

August 10, 2010 - 01:00
Revision Note: V2.0 (August 10, 2010): Advisory updated to reflect publication of security bulletin.Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS10-049 to address this issue. For more information about this issue, including download links for an available security update, please review MS10-049. The vulnerability addressed is the TLS/SSL Renegotiation Vulnerability - CVE-2009-3555. For additional information on this advisory, see Microsoft Knowledge Base Article 977377.

Microsoft Security Advisory (977377): Vulnerability in TLS/SSL Could Allow Spoofing

August 10, 2010 - 01:00
Revision Note: V2.0 (August 10, 2010): Advisory updated to reflect publication of security bulletin.Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS10-049 to address this issue. For more information about this issue, including download links for an available security update, please review MS10-049. The vulnerability addressed is the TLS/SSL Renegotiation Vulnerability - CVE-2009-3555. For additional information on this advisory, see Microsoft Knowledge Base Article 977377.