Patch Tuesday a staggering 17 security bulletins (nine of which have been given Microsoft’s highest severity rating of “critical”), addressing 64 security vulnerabilities. Software including bugs which are said to be fixed by the patches include Microsoft Windows, Microsoft Office, Internet Explorer, Visual Studio and .NET Framework.
One of the vulnerabilities reportedly fixed will be the MHTML redering flaw that was discovered earlier this year. Internet Explorer was one the products found to be at risk from the zero-day vulnerability that could allow maliciously crafted webpages to execute code in any “zone” regardless of which zone is specified.
Bulletin Summary
|
Bulletin ID
|
Maximum Severity Rating
|
Vulnerability Impact
|
Restart Requirement
|
Affected Software*
|
|
Bulletin 1
|
Critical
|
Remote Code Execution
|
Requires restart
|
Internet Explorer on Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2.
|
|
Bulletin 2
|
Critical
|
Remote Code Execution
|
Requires restart
|
Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2.
|
|
Bulletin 3
|
Critical
|
Remote Code Execution
|
Requires restart
|
Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2.
|
|
Bulletin 4
|
Critical
|
Remote Code Execution
|
May require restart
|
Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2.
|
|
Bulletin 5
|
Critical
|
Remote Code Execution
|
May require restart
|
Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2.
|
|
Bulletin 6
|
Critical
|
Remote Code Execution
|
May require restart
|
Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Office XP.
|
|
Bulletin 7
|
Critical
|
Remote Code Execution
|
Requires restart
|
Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2.
|
|
Bulletin 8
|
Critical
|
Remote Code Execution
|
May require restart
|
Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2.
|
|
Bulletin 9
|
Critical
|
Remote Code Execution
|
Requires restart
|
Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2.
|
|
Bulletin 10
|
Important
|
Remote Code Execution
|
May require restart
|
Microsoft Excel 2002, Excel 2003, Excel 2007, Excel 2010, Office 2004 for Mac, Office 2008 for Mac, Office for Mac 2011, Open XML File Format Converter for Mac, Excel Viewer, and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats.
|
|
Bulletin 11
|
Important
|
Remote Code Execution
|
May require restart
|
Microsoft PowerPoint 2002, PowerPoint 2003, PowerPoint 2007; PowerPoint 2010, Office 2004 for Mac, Office 2008 for Mac, Office for Mac 2011, Open XML File Format Converter for Mac, PowerPoint Viewer, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats, and PowerPoint Web App.
|
|
Bulletin 12
|
Important
|
Remote Code Execution
|
May require restart
|
Microsoft Office XP, Office 2003, Office 2007, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac.
|
|
Bulletin 13
|
Important
|
Remote Code Execution
|
May require restart
|
Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2.
|
|
Bulletin 14
|
Important
|
Remote Code Execution
|
May require restart
|
Microsoft Visual Studio .NET 2003, Visual Studio 2005, Visual Studio 2008, Visual Studio 2010, Visual C++ 2005 SP1 Redistributable Package, Visual C++ 2008 Sp1 Redistributable Package, and Visual C++ 2010 Redistributable Package.
|
|
Bulletin 15
|
Important
|
Information Disclosure
|
Requires restart
|
Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2.
|
|
Bulletin 16
|
Important
|
Remote Code Execution
|
May require restart
|
Microsoft Windows XP and Windows Server 2003.
|
|
Bulletin 17
|
Important
|
Elevation of Privilege
|
Requires restart
|
Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2.
|
|
* The list of affected software in the summary table is an abstract. To see the full list of affected components please click on the “Advance Notification Webpage” link below and review the “Affected Software” section.
|
Further information on the patches can be found in the advance notice that Microsoft has published on its website.