Showing posts with label release. Show all posts
Showing posts with label release. Show all posts
Tuesday, March 7, 2017
Microsoft Security Bulletin Release for November 2015
Microsoft Security Bulletin Release for November 2015

Microsoft released twelve (12) bulletins. Four (4) bulletins are identified as Critical and the remaining eight (8) are rated Important in severity.
The updates address vulnerabilities in Microsoft Windows, Microsoft Office, Microsoft Office Services and Web Apps, Microsoft, Skype for Business, Microsoft .NET Framework, Microsoft Edge and Internet Explorer.
Details about the CVEs can be found in the below-referenced TechNet Security Bulletin. Watch for the November 2015 "monthly patch review" by Dustin Childs picking up where MSRC has left us hanging. The review can be found on the HP Security Research blog.
Critical:
- MS15-112 -- Cumulative Security Update for Internet Explorer (3104517)
- MS15-113 -- Cumulative Security Update for Microsoft Edge (3104519)
- MS15-114 -- Security Update for Windows Journal to Address Remote Code Execution (3100213)
- MS15-115 -- Security Update for Microsoft Windows to Address Remote Code Execution (3105864)
- MS15-116 -- Security Update for Microsoft Office to Address Remote Code Execution (3104540)
- MS15-117 -- Security Update for NDIS to Address Elevation of Privilege (3101722)
- MS15-118 -- Security Update for .NET Framework to Address Elevation of Privilege (3104507)
- MS15-119 -- Security Update for Winsock to Address Elevation of Privilege (3104521)
- MS15-120 -- Security Update for IPSec to Address Denial of Service (3102939)
- MS15-121 -- Security Update for Schannel to Address Spoofing (3081320)
- MS15-122 -- Security Update for Kerberos to Address Security Feature Bypass (3105256)
- MS15-123 -- Security Update for Skype for Business and Microsoft Lync to Address Information Disclosure (3105872)
Additional Update Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center. The updated version includes detection for the the following ransomware families: Crowti, Critroni, Teerac and Tescrypt . Details are available in the MMPC Blog Post.
- Windows 8.x and Windows 10 -- Non-security new features and improvements for Windows 8.1 and Windows 10 are included with the updates.
References
- MSRC
- TechNet: Microsoft Security Bulletin for November 2015

Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Friday, February 17, 2017
Microsoft Security Bulletin Release for December 2015
Microsoft Security Bulletin Release for December 2015

Microsoft released twelve (12) bulletins. Eight (8) bulletins are identified as Critical and the remaining four (4) are rated Important in severity.
The updates address vulnerabilities in Microsoft Windows, Microsoft Edge, Internet Explorer, Microsoft .NET Framework, Microsoft Office, Skype for Business, Microsoft Lync Silverlight and Microsoft Silverlight.
Details about the CVEs can be found in the below-referenced TechNet Security Bulletin. If you are prioritizing updates, the most critical is MS15-0131.
Also released today is Microsoft Security Advisory 3123040 which revokes a certificate for *.xboxlive.com where private keys were disclosed.
Critical:
- MS15-124 Cumulative Security Update for Internet Explorer (3116180
- MS15-125 Cumulative Security Update for Microsoft Edge (3116184)
- MS15-126 Cumulative Security Update for JScript and VBScript to Address Remote Code Execution (3116178)
- MS15-127 Security Update for Microsoft Windows DNS to Address Remote Code Execution (3100465)
- MS15-128 Security Update for Microsoft Graphics Component to Address Remote Code Execution (3104503)
- MS15-129 Security Update for Silverlight to Address Remote Code Execution (3106614)
- MS15-130 Security Update for Microsoft Uniscribe to Address Remote Code Execution (3108670)
- MS15-131 Security Update for Microsoft Office to Address Remote Code Execution (3116111)
Important:
- MS15-132 Security Update for Microsoft Windows to Address Remote Code Execution (3116162)
- MS15-133 Security Update for Windows PGM to Address Elevation of Privilege (3116130
- MS15-134 Security Update for Windows Media Center to Address Remote Code Execution (3108669)
- MS15-135 Security Update for Windows Kernel-Mode Drivers to Address Elevation of Privilege (3119075)
Additional Update Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center. The updated version includes detection for the Blakamba, Brambul, Diplugem, Drixed, Escad, Joanap and Tescrypt.
- Windows 8.x and Windows 10 -- Non-security new features and improvements for Windows 8.1 and Windows 10 are included with the updates.
References
- MSRC
- TechNet: Microsoft Security Bulletin for December 2015

Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Wednesday, February 15, 2017
Microsoft Security Bulletin Release for March 2015
Microsoft Security Bulletin Release for March 2015

Microsoft released fourteen (14) bulletins. Five (5) bulletins are identified as Critical and the remaining nine (9) are rated Important in severity.
The updates address vulnerabilities in Microsoft Windows, Microsoft Office, Microsoft Exchange and Internet Explorer. Details about the CVEs can be found in the below-referenced TechNet Security Bulletin.
Security Bulletin MS15-031 addresses the vulnerability in Security Advisory 3046015 which relates to the SSL/TLS issue referred being referred to as FREAK (Factoring attack on RSA-EXPORT Keys).
In addition to providing information about the additional families added to the MSRT, information regarding Superfish and steps by Microsoft, Lenovo and others is available in the MMPC blog post, MSRT March: Superfish cleanup.
Updates:
Critical:
- MS15-022 -- Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3038999)
- MS15-021 -- Vulnerabilities in Adobe Font Driver Could Allow Remote Code Execution (3032323)
- MS15-020 -- Vulnerability in Microsoft Windows Could Allow Remote Code Execution (3041836)
- MS15-019 -- Vulnerability in VBScript Scripting Engine Could Allow Remote Code Execution (3040297)
- MS15-018 -- Cumulative Security Update for Internet Explorer (3032359)
Important:
- MS15-031 -- Vulnerability in Schannel Could Allow Security Feature Bypass (3046049)
- MS15-030 -- Vulnerability in Remote Desktop Protocol Could Allow Denial of Service (3039976)
- MS15-029 -- Vulnerability in Windows Photo Decoder Component Could Allow Information Disclosure (3035126)
- MS15-028 -- Vulnerability in Windows Task Scheduler Could Allow Security Feature Bypass (3030377)
- MS15-027 -- Vulnerability in NETLOGON Could Allow Spoofing (3002657)
- MS15-026 -- Vulnerabilities in Microsoft Exchange Server Could Allow Elevation of Privilege (3040856)
- MS15-025 -- Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (3038680)
- MS15-024 -- Vulnerability in PNG Processing Could Allow Information Disclosure (3035132)
- MS15-023 -- Vulnerabilities in Kernel-Mode Driver Could Allow Elevation of Privilege (3034344)
Additional Update Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.
The updated version includes the Win32/CompromisedCert and Win32/Alinaos malware families. Additional details ave available in the MMPC blog post. - Internet Explorer -- For additional information about the blocking of out-of-date ActiveX controls see the TechNet article, Out-of-date ActiveX control blocking. Additional changes introduced this month include the blocking of outdated Silverlight. Additional information is available in the IE Blog.
- Windows 8.x -- Non-security new features and improvements for Windows 8.1 are now included with the second Tuesday of the month updates. Additional information about this change is available here.
- Windows XP -- Although Microsoft has stopped providing Microsoft Security Essentials for Windows XP, definitions will be available until July 15, 2015. See Microsoft antimalware support for Windows XP. The MSRT still works on Windows XP.
References
- MSRC: March 2015 Updates
- TechNet: Microsoft Security Bulletin for March 2015

Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Saturday, January 28, 2017
Microsoft Security Bulletin Release for February 2016
Microsoft Security Bulletin Release for February 2016

Microsoft released thirteen (13) bulletins. Six (6) bulletins are identified as Critical and the remaining seven (7) are rated Important in severity.
The updates address vulnerabilities in Microsoft Windows, Microsoft Edge, Internet Explorer, Microsoft .NET Framework, Microsoft Office Services and Web Apps,
Microsoft Server Software and Microsoft .NET Framework.
For Windows Server 2012, Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10, and Windows 10 Version 1511, Adobe Flash Player is now a security bulletin rather than a security advisory and was included with the updates.
As a very welcome change in response to feedback, Microsoft is now providing more details about the Windows 10 updates delivered through Windows Update. A summary of important product developments included in each update, with links to more details is available at Windows 10 Update History. The page will be regularly refreshed, as new updates are released.
Critical:
- MS16-009 Cumulative Security Update for Internet Explorer (3134220)
- MS16-011 Cumulative Security Update for Microsoft Edge (3134225)
- MS16-012 Security Update for Microsoft Windows PDF Library to Address Remote Code Execution (3138938)
- MS16-013 Security Update for Windows Journal to Address Remote Code Execution (3134811)
- MS16-015 Security Update for Microsoft Office to Address Remote Code Execution (3134226)
- MS16-022 Security Update for Adobe Flash Player (3135782)
- MS16-014 Security Update for Microsoft Windows to Address Remote Code Execution (3134228)
- MS16-016 Security Update for WebDAV to Address Elevation of Privilege (3136041)
- MS16-017 Security Update for Remote Desktop Display Driver to Address Elevation of Privilege (3134700)
- MS16-018 Security Update for Windows Kernel-Mode Drivers to Address Elevation of Privilege (3136082)
- MS16-019 Security Update for .NET Framework to Address Denial of Service (3137893)
- MS16-020 Security Update for Active Directory Federation Services to Address Denial of Service (3134222)
- MS16-021 Security Update for NPS RADIUS Server to Address Denial of Service (3133043)
Additional Update Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center. The update includes updated detections for the following malware families: Bladabindi, Gamarue, Sality, Kelihos and Diplugem??.
Windows 8.x and Windows 10 -- Non-security new features and improvements for Windows 8.1 and Windows 10 are included with the updates.References
- MSRC
- TechNet: Microsoft Security Bulletin for February 2016
- Windows 10 Update History

Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Tuesday, January 10, 2017
Microsoft Security Bulletin Release for March 2016
Microsoft Security Bulletin Release for March 2016

Microsoft released thirteen (13) bulletins. Five (5) bulletins are identified as Critical and the remaining eight (8) are rated Important in severity.
The updates address vulnerabilities in Microsoft Windows, Microsoft Edge, Internet Explorer, Microsoft Office, Microsoft Office Services and Web Apps, Microsoft Server Software and Microsoft .NET Framework.
Critical:
- MS16-023 Cumulative Security Update for Internet Explorer (3142015)
- MS16-024 Cumulative Security Update for Microsoft Edge (3142019)
- MS16-026 Security Update for Graphic Fonts to Address Remote Code Execution (3143148)
- MS16-027 Security Update for Windows Media to Address Remote Code Execution (3143146)
- MS16-028 Security Update for Microsoft Windows PDF Library to Address Remote Code Execution (3143081)
- MS16-025 Security Update for Windows Library Loading to Address Remote Code Execution (3140709)
- MS16-029 Security Update for Microsoft Office to Address Remote Code Execution (3141806)
- MS16-030 Security Update for Windows OLE to Address Remote Code Execution (3143136)
- MS16-031 Security Update for Microsoft Windows to Address Elevation of Privilege (3140410)
- MS16-032 Security Update for Secondary Logon to Address Elevation of Privilege (3143141)
- MS16-033 Security Update for Windows USB Mass Storage Class Driver to Address Elevation of Privilege (3143142)
- MS16-034 Security Update for Windows Kernel-Mode Drivers to Address Elevation of Privilege (3143145)
- MS16-035 Security Update for .NET Framework to Address Security Feature Bypass (3141780)
Additional Update Notes
- Adobe Flash Player -- For Windows Server 2012, Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10, and Windows 10 Version 1511, Adobe Flash Player is now a security bulletin rather than a security advisory and is included with the updates.
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.
- Windows 8.x and Windows 10 -- Non-security new features and improvements for Windows 8.1 and Windows 10 are included with the updates.
- Windows 10 -- A summary of important product developments included in each update, with links to more details is available at Windows 10 Update History. The page will be regularly refreshed, as new updates are released.
References
- MSRC
- TechNet: Microsoft Security Bulletin for March 2016
- Windows 10 Update History

Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Saturday, January 7, 2017
Microsoft Security Bulletin Release for April 2016
Microsoft Security Bulletin Release for April 2016

Microsoft released thirteen (13) bulletins. Six (6) bulletins are identified as Critical and the remaining eight (7) are rated Important in severity. Of particular note is MS16-039 which is under active attack.
The updates address vulnerabilities in Microsoft Windows, Microsoft Edge, Internet Explorer, Microsoft Office, Microsoft Office, Microsoft Office Services and Web Apps, Skype for Business, Microsoft Lync and Microsoft .NET Framework.
Information about the updates in KB 3147458 for Windows 10 is available at Windows 10 update history.
Critical:
- MS16-037 Cumulative Security Update for Internet Explorer (3148531)
- MS16-038 Cumulative Security Update for Microsoft Edge (3148532)
- MS16-039 Security Update for Microsoft Graphics Component (3148522)
- MS16-040 Security Update for Microsoft XML Core Services (3148541)
- MS16-042 Security Update for Microsoft Office (3148775)
- MS16-050 Security Update for Adobe Flash Player in IE/Edge on Win8.1/10 (3154132)
- MS16-041 Security Update for .NET Framework (3148789)
- MS16-044 Security Update for Windows OLE (3146706)
- MS16-045 Security Update for Windows Hyper-V (3143118)
- MS16-046 Security Update for Secondary Logon (3148538)
- MS16-047 Security Update for SAM and LSAD Remote Protocols (3148527)
- MS16-048 Security Update for CSRSS (3148528)
- MS16-049 Security Update for HTTP.sys (3148795)
Additional Update Notes
- Adobe Flash Player -- For Windows Server 2012, Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10, and Windows 10 Version 1511, Adobe Flash Player is now a security bulletin rather than a security advisory and is included with the updates.
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.
- Windows 8.x and Windows 10 -- Non-security new features and improvements for Windows 8.1 and Windows 10 are included with the updates.
- Windows 10 -- A summary of important product developments included in each update, with links to more details is available at Windows 10 Update History. The page will be regularly refreshed, as new updates are released.
References
- MSRC
- TechNet: Microsoft Security Bulletin for April 2016
- Windows 10 Update History

Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Microsoft Security Bulletin Release for April 2015
Microsoft Security Bulletin Release for April 2015

Microsoft released fourteen (11) bulletins. Four (4) bulletins are identified as Critical and the remaining seven (7) are rated Important in severity.
The updates address vulnerabilities in Microsoft Windows, Microsoft Office, Internet Explorer, Microsoft Server Software, Productivity Software and .NET Framework. Details about the CVEs can be found in the below-referenced TechNet Security Bulletin.
For those who have had issues with .NET Framework updates, it is suggested that MS-041 be installed separately with a shut/down restart between other updates.
As part of the Internet Explorer update released today, SSL 3.0 has been disabled by default in Internet Explorer 11.
Critical:
- MS15-032 Cumulative Security Update for Internet Explorer (3038314)
- MS15-033 Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3048019)
- MS15-034 Vulnerability in HTTP.sys Could Allow Remote Code Execution (3042553)
- MS15-035 Vulnerability in Microsoft Graphics Component Could Allow Remote Code Execution (3046306)
- MS15-036 Vulnerabilities in Microsoft SharePoint Server Could Allow Elevation of Privilege (3052044)
- MS15-037 Vulnerability in Windows Task Scheduler Could Allow Elevation of Privilege (3046269)
- MS15-038 Vulnerabilities in Microsoft Windows Could Allow Elevation of Privilege (3049576)
- MS15-039 Vulnerability in XML Core Services Could Allow Security Feature Bypass (3046482)
- MS15-040 Vulnerability in Active Directory Federation Services Could Allow Information Disclosure (3045711)
- MS15-041 Vulnerability in .NET Framework Could Allow Information Disclosure (3048010)
- MS15-042 Vulnerability in Windows Hyper-V Could Allow Denial of Service (3047234)
Additional Update Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.
The updated version includes the Win32/Saluchtra, Win32/Dexter, Win32/Unskal and Win32/IeEnablerCby malware families. Additional details ave available in the MMPC blog post. - Internet Explorer -- For additional information about the blocking of out-of-date ActiveX controls see the TechNet article, Out-of-date ActiveX control blocking. Additional changes introduced this month include the blocking of outdated Silverlight. Additional information is available in the IE Blog.
- Windows 8.x -- Non-security new features and improvements for Windows 8.1 are now included with the second Tuesday of the month updates. Additional information about this change is available here.
- Windows XP -- Although Microsoft has stopped providing Microsoft Security Essentials for Windows XP, definitions will be available until July 15, 2015. See Microsoft antimalware support for Windows XP. The MSRT still works on Windows XP.
References
- MSRC: April 2015 Updates
- TechNet: Microsoft Security Bulletin for April 2015

Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Tuesday, January 3, 2017
Microsoft Security Bulletin Release for May 2015
Microsoft Security Bulletin Release for May 2015

Microsoft released thirteen (13) bulletins. Three (3) bulletins are identified as Critical and the remaining ten (10) are rated Important in severity.
The updates address vulnerabilities in Microsoft Windows, Microsoft Office, Internet Explorer, Microsoft Lync, Microsoft Silverlight, Microsoft Server Software and .NET Framework. Details about the CVEs can be found in the below-referenced TechNet Security Bulletin.
For those who have had issues with .NET Framework updates, it is suggested that MS-041 be installed separately with a shut/down restart between other updates.
Also released was one new Security Advisory:
- Update to Default Cipher Suite Priority Order (3042058)
- Update for Adobe Flash Player in Internet Explorer (2755801)
Critical:
- MS15-043 -- Cumulative Security Update for Internet Explorer (3049563)
- MS15-044 -- Vulnerabilities in Microsoft Font Drivers Could Allow Remote Code Execution (3057110)
- MS15-045-- Vulnerability in Windows Journal Could Allow Remote Code Execution (3046002)
- MS15-046 -- Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3057181)
- MS15-047 -- Vulnerabilities in Microsoft SharePoint Server Could Allow Remote Code Execution (3058083)
- MS15-048 -- Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (3057134)
- MS15-049 -- Vulnerability in Silverlight Could Allow Elevation of Privilege (3058985)
- MS15-050 -- Vulnerability in Service Control Manager Could Allow Elevation of Privilege (3055642)
- MS15-051 -- Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (3057191)
- MS15-052 -- Vulnerability in Windows Kernel Could Allow Security Feature Bypass (3050514)
- MS15-053 -- Vulnerabilities in JScript and VBScript Scripting Engines Could Allow Security Feature Bypass (3057263)
- MS15-054 -- Vulnerability in Microsoft Management Console File Format Could Allow Denial of Service (3051768)
- MS15-055 -- Vulnerability in Schannel Could Allow Information Disclosure (3061518)
Additional Update Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.
- Internet Explorer -- For additional information about the blocking of out-of-date ActiveX controls see the TechNet article, Out-of-date ActiveX control blocking. Additional changes introduced this month include the blocking of outdated Silverlight. Additional information is available in the IE Blog.
- Windows 8.x -- Non-security new features and improvements for Windows 8.1 are now included with the second Tuesday of the month updates. Additional information about this change is available here.
- Windows XP -- Although Microsoft has stopped providing Microsoft Security Essentials for Windows XP, definitions will be available until July 15, 2015. See Microsoft antimalware support for Windows XP. The MSRT still works on Windows XP.
References
- MSRC: May 2015 Updates
- TechNet: Microsoft Security Bulletin for May 2015

Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Friday, December 30, 2016
Microsoft Security Bulletin Release for September 2015
Microsoft Security Bulletin Release for September 2015

Microsoft released twelve (12) bulletins. Five (5) bulletins are identified as Critical and the remaining seven (7) are rated Important in severity.
The updates address vulnerabilities in Microsoft Windows, Microsoft,.NET Framework, Microsoft Office, Microsoft Lync, Microsoft Silverlight, Skype for Business Server, Microsoft Lync Server, Microsoft Edge and Internet Explorer.
Details about the CVEs can be found in the below-referenced TechNet Security Bulletin.
Update: You wont want to miss the new Monthly Patch Review by Dustin Childs.
Critical:
- MS15-094 -- Cumulative Security Update for Internet Explorer (3089548)
- MS15-095 -- Cumulative Security Update for Microsoft Edge (3089665)
- MS15-097 --Vulnerabilities in Microsoft Graphics Component Could Allow Remote Code Execution (3089656)
- MS15-098 -- Vulnerabilities in Windows Journal Could Allow Remote Code Execution (3089669)
- MS15-099 -- Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3089664)
- MS15-096 -- Vulnerability in Active Directory Service Could Allow Denial of Service (3072595)
- MS15-100 -- Vulnerability in Windows Media Center Could Allow Remote Code Execution (3087918)
- MS15-101 -- Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (3089662)
- MS15-102 -- Vulnerabilities in Windows Task Management Could Allow Elevation of Privilege (3089657)
- MS15-103 -- Vulnerabilities in Microsoft Exchange Server Could Allow Information Disclosure (3089250)
- MS15-104 -- Vulnerabilities in Skype for Business Server and Lync Server Could Allow Elevation of Privilege (3089952)
- MS15-105 -- Vulnerability in Windows Hyper-V Could Allow Security Feature Bypass (3091287)
Additional Update Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center. The updated version includes detection for the prevalent ransomware family Win32/Teerac. Details are available in the MMPC Blog Post.
- Windows 8.x and Windows 10 -- Non-security new features and improvements for Windows 8.1 and Windows 10 are included with the updates.
References
- MSRC
- TechNet: Microsoft Security Bulletin for September 2015

Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Saturday, December 24, 2016
Microsoft Security Bulletin Release for November 2014
Microsoft Security Bulletin Release for November 2014

Microsoft released fourteen (14) bulletins*. Four (4) bulletins are identified as Critical, eight (8) as Important, and two (2) are rated Moderate in severity.
The updates address 33 Common Vulnerabilities and Exposures (CVEs) in Microsoft Windows, Internet Explorer (IE), Office, .NET Framework, Internet Information Services (IIS), Remote Desktop Protocol (RDP), Active Directory Federation Services (ADFS), Input Method Editor (IME) (Japanese), and Kernel Mode Driver (KMD).
Anyone who frequently experiences issues with .NET Framework updates should install those updates separately with a shutdown/restart between other updates.
Critical:
- MS14-064 -- Vulnerabilities in Windows OLE Could Allow Remote Code Execution (3011443)
- MS14-065 -- Cumulative Security Update for Internet Explorer (3003057)
- MS14-066 -- Vulnerability in Schannel Could Allow Remote Code Execution (2992611)
- MS14-067 --Vulnerability in XML Core Services Could Allow Remote Code Execution (2993958)
Important:
- MS14-069 -- Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3009710)
- MS14-070 -- Vulnerability in TCP/IP Could Allow Elevation of Privilege (2989935)
- MS14-071 -- Vulnerability in Windows Audio Service Could Allow Elevation of Privilege (3005607)
- MS14-072 -- Vulnerability in .NET Framework Could Allow Elevation of Privilege (3005210)
- MS14-073 -- Vulnerability in Microsoft SharePoint Foundation Could Allow Elevation of Privilege (3000431)
- MS14-074 -- Vulnerability in Remote Desktop Protocol Could Allow Security Feature Bypass (3003743)
- MS14-076 -- Vulnerability in Internet Information Services (IIS) Could Allow Security Feature Bypass (2982998)
- MS14-077 -- Vulnerability in Active Directory Federation Services Could Allow Information Disclosure (3003381)
Moderate:
- MS14-078 -- Vulnerability in IME (Japanese) Could Allow Elevation of Privilege (3005210)
- MS14-079 -- Vulnerability in Kernel Mode Driver Could Allow Denial of Service (3002885)
*Note: MS14-068 and MS14-075 are shown as "Release date to be determined".
Information on non-security update information can be found in KB 894199.
Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center. The updated version includes the Win32/Tofsee and Win32/Zoxpng malware families. Additional details ave available in the MMPC blog post.
- Internet Explorer -- For additional information about the blocking of out-of-date ActiveX controls see the TechNet article, Out-of-date ActiveX control blocking. Additional changes introduced this month include the blocking of outdated Silverlight. Additional information is available in the IE Blog.
- Windows 8.1 -- Non-security new features and improvements for Windows 8.1. are now included with the second Tuesday of the month updates. Additional information is available at August updates for Windows 8.1 and Windows Server 2012 R2.
- Windows XP -- Although Microsoft has stopped providing Microsoft Security Essentials for Windows XP, definitions will be available until July 15, 2015. See Microsoft antimalware support for Windows XP. The MSRT still works on Windows XP.
The following additional information is provided in the Security Bulletin:
- The affected software listed have been tested to determine which versions are affected. Other versions are past their support life cycle. To determine the support life cycle for your software version, visit Microsoft Support Lifecycle.
- Security solutions for IT professionals: TechNet Security Troubleshooting and Support
- Help protect your computer that is running Windows from viruses and malware: Virus Solution and Security Center
- Local support according to your country: International Support
References
- MSRC: November 2014 Security Updates
- TechNet: Microsoft Security Bulletin for November 2014

Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Friday, December 23, 2016
Microsoft Security Bulletin Release for February 2015
Microsoft Security Bulletin Release for February 2015

Microsoft released nine (9) bulletins. Three (3) bulletins are identified as Critical and the remaining six (6) are rated Important in severity.
The updates address 56 unique Common Vulnerabilities and Exposures (CVEs) in Microsoft Windows, Microsoft Office, Internet Explorer, and Microsoft Server software. Details about the CVEs can be found in the below-referenced TechNet Security Bulletin.
Also of note:
Edit Note: Fast response! The update has been pulled. [There are numerous reports of KB3001652, Update rollup for Visual Studio 2010 Tools for Office Runtime, taking a very long time to install. This has been reported on both Windows 7 and Windows 8x, 32- and 64-bit.]
Security Advisory 3009008 has been updated. Internet Explorer 11 will prevent insecure fallback to SSL 3.0 for Protected Mode sites. Additional information about this update is available in the IE Blog.
MS14-083 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution was re-released.
Security Advisory 3004375, Update for Windows Command Line Auditing, was released.
Updates:
Critical:
- MS15-009 -- Security Update for Internet Explorer (3034682)
- MS15-010 -- Vulnerabilities in Windows Kernel-Mode Driver Could Allow Remote Code Execution (3036220)
- MS15-011 -- Vulnerability in Group Policy Could Allow Remote Code Execution (3000483)
Important:
- MS15-012 -- Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3032328)
- MS15-013 -- Vulnerability in Microsoft Office Could Allow Security Feature Bypass (3033857)
- MS15-014 -- Vulnerability in Group Policy Could Allow Security Feature Bypass (3004361)
- MS15-015 -- Vulnerability in Microsoft Windows Could Allow Elevation of Privilege (3031432)
- MS15-016 -- Vulnerability in Microsoft Graphics Component Could Allow Information Disclosure (3029944)
- MS15-016 -- Vulnerability in Microsoft Graphics Component Could Allow Information Disclosure (3029944)
Additional Update Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.
The updated version includes the Win32/Escad, Win32/Jinupd and Win32/NukeSped malware families. Additional details ave available in the MMPC blog post. - Internet Explorer -- For additional information about the blocking of out-of-date ActiveX controls see the TechNet article, Out-of-date ActiveX control blocking. Additional changes introduced this month include the blocking of outdated Silverlight. Additional information is available in the IE Blog.
- Windows 8.x -- Non-security new features and improvements for Windows 8.1 are now included with the second Tuesday of the month updates. Additional information about this change is available here.
- Windows XP -- Although Microsoft has stopped providing Microsoft Security Essentials for Windows XP, definitions will be available until July 15, 2015. See Microsoft antimalware support for Windows XP. The MSRT still works on Windows XP.
References
- MSRC: February 2015 Updates
- TechNet: Microsoft Security Bulletin for February 2015

Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Tuesday, December 20, 2016
Microsoft Security Bulletin Release for October 2015
Microsoft Security Bulletin Release for October 2015

Microsoft released six (6) bulletins. Three (3) bulletins are identified as Critical and the remaining three (3) are rated Important in severity.
The updates address vulnerabilities in Microsoft Windows, Microsoft Office, Microsoft Office Services and Web Apps, Microsoft Server Software, Microsoft Edge and Internet Explorer.
Details about the CVEs can be found in the below-referenced TechNet Security Bulletin. Also see the The monthly patch review October, 2015 by Dustin Childs -- picking up where MSRC has left us hanging.
Critical:
- MS15-106 Cumulative Security Update for Internet Explorer (3096441)
- MS15-108 Security Update for JScript and VBScript to Address Remote Code Execution (3089659)
- MS15-109 Security Update for Windows Shell to Address Remote Code Execution (3096443)
- MS15-107 Cumulative Security Update for Microsoft Edge (3096448)
- MS15-110 Security Updates for Microsoft Office to Address Remote Code Execution (3096440)
- MS15-111 Security Update for Windows Kernel to Address Elevation of Privilege (3096447)
Additional Update Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center. The updated version includes detection for the following families: Tescrypt, Blakamba, Diplugem, Escad, Joanap, Brambul and Drixed. Details are available in the MMPC Blog Post.
- Windows 8.x and Windows 10 -- Non-security new features and improvements for Windows 8.1 and Windows 10 are included with the updates.
References
- MSRC
- TechNet: Microsoft Security Bulletin for October 2015

Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Monday, December 19, 2016
Microsoft Security Bulletin Release for July 2015
Microsoft Security Bulletin Release for July 2015

Microsoft released fourteen (14) bulletins. Four (4) bulletins are identified as Critical and the remaining ten (10) are rated Important in severity.
The updates address vulnerabilities in Microsoft Windows, Microsoft Office, Microsoft SQL Server, and Internet Explorer. Details about the CVEs can be found in the below-referenced TechNet Security Bulletin.
Two Security Advisories were also released:
KB3057154 -- Update to Harden Use of DES Encryption
KB3074162 -- Vulnerability in Microsoft Malicious Software Removal Tool Could Allow Elevation of Privilege
Critical:
- MS15-065 -- Security Update for Internet Explorer (3076321)
- MS15-066 -- Vulnerability in VBScript Scripting Engine Could Allow Remote Code Execution (3072604)
- MS15-067 -- Vulnerability in RDP Could Allow Remote Code Execution (3073094)
- MS15-068 -- Vulnerabilities in Windows Hyper-V Could Allow Remote Code Execution (3072000)
- MS15-058 -- Vulnerabilities in SQL Server Could Allow Remote Code Execution (3065718)
- MS15-069 -- Vulnerabilities in Windows Could Allow Remote Code Execution (3072631)
- MS15-070 -- Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3072620)
- MS15-071 -- Vulnerability in Netlogon Could Allow Elevation of Privilege (3068457)
- MS15-072 -- Vulnerability in Windows Graphics Component Could Allow Elevation of Privilege (3069392)
- MS15-073 -- Vulnerability in Windows Kernel-Mode Driver Could Allow Elevation of Privilege (3070102)
- MS15-074 -- Vulnerability in Windows Installer Service Could Allow Elevation of Privilege (3072630)
- MS15-075 -- Vulnerabilities in OLE Could Allow Elevation of Privilege (3072633)
- MS15-076 -- Vulnerability in Windows Remote Procedure Call Could Allow Elevation of Privilege (3067505)
- MS15-077 -- Vulnerability in ATM Font Driver Could Allow Elevation of Privilege (3077657)
Additional Update Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center. The updated version includes Win32/Crowti and Win32/Reveton. Details are available in the MMPC Blog Post.
- Internet Explorer -- For additional information about the blocking of out-of-date ActiveX controls see the TechNet article, Out-of-date ActiveX control blocking. Additional changes introduced this month include the blocking of outdated Silverlight. Additional information is available in the IE Blog.
- Windows 8.x -- Non-security new features and improvements for Windows 8.1 are now included with the second Tuesday of the month updates. Additional information about this change is available here.
- Windows XP -- Effective today, Microsoft definition updates for Microsoft Security Essentials for Windows XP are finished! See Microsoft antimalware support for Windows XP.
References
- MSRC: July 2015 Updates
- TechNet: Microsoft Security Bulletin for July 2015

Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Sunday, December 4, 2016
Microsoft Security Bulletin Release for August 2015
Microsoft Security Bulletin Release for August 2015

Microsoft released fourteen (14) bulletins. Four (4) bulletins are identified as Critical and the remaining ten (10) are rated Important in severity.
The updates address vulnerabilities in Microsoft Windows, Microsoft .NET Framework, Microsoft Office, Microsoft Lync, Microsoft Silverlight Microsoft Server Software, Microsoft Edge and Internet Explorer. Details about the CVEs can be found in the below-referenced TechNet Security Bulletin.
Critical:
- MS15-079 -- Cumulative Security Update for Internet Explorer (3082442)
- MS15-080 -- Vulnerabilities in Microsoft Graphics Component Could Allow Remote Code Execution (3078662)
- MS15-081 -- Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3080790)
- MS15-091 -- Cumulative Security Update for Microsoft Edge (3084525)
- MS15-082 -- Vulnerabilities in RDP Could Allow Remote Code Execution (3080348)
- MS15-083 -- Vulnerability in Server Message Block Could Allow Remote Code Execution (3073921)
- MS15-084 -- Vulnerabilities in XML Core Services Could Allow Information Disclosure (3080129)
- MS15-085 -- Vulnerability in Mount Manager Could Allow Elevation of Privilege (3082487)
- MS15-086 -- Vulnerability in System Center Operations Manager Could Allow Elevation of Privilege (3075158)
- MS15-087 -- Vulnerability in UDDI Services Could Allow Elevation of Privilege (3082459)
- MS15-088 -- Unsafe Command Line Parameter Passing Could Allow Information Disclosure (3082458)
- MS15-089 -- Vulnerability in WebDAV Could Allow Information Disclosure (3076949)
- MS15-090 -- Vulnerabilities in Microsoft Windows Could Allow Elevation of Privilege (3060716)
- MS15-092 -- Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (3086251)
Additional Update Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center. The updated version includes Win32/Vawtrak, Win32/Critroni and Win32/Kasidet. Details are available in the MMPC Blog Post.
- Internet Explorer -- For additional information about the blocking of out-of-date ActiveX controls see the TechNet article, Out-of-date ActiveX control blocking. Additional changes introduced this month include the blocking of outdated Silverlight. Additional information is available in the IE Blog.
- Windows 8.x and Windows 10 -- Non-security new features and improvements for Windows 8.1 and Windows 10 are included with the updates.
References
- MSRC: August 2015 Security Update Release Summary
- TechNet: Microsoft Security Bulletin for August 2015

Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Sunday, November 27, 2016
Microsoft Security Bulletin Release for June 2015
Microsoft Security Bulletin Release for June 2015

Microsoft released eight (8) bulletins. Two (2) bulletins are identified as Critical and the remaining six (6) are rated Important in severity.
The updates address vulnerabilities in Microsoft Windows, Microsoft Office, Internet Explorer and Microsoft Exchange Server. Details about the CVEs can be found in the below-referenced TechNet Security Bulletin.
Also released was one new Security Advisory:
- Update for Juniper Network Windows In-Box Junos Pulse Client (2962393)
- Update for Adobe Flash Player in Internet Explorer (2755801)
Critical:
- MS15-056 -- Cumulative Security Update for Internet Explorer (3049563)
- MS15-057 -- Vulnerability in Windows Media Player Could Allow Remote Code Execution (3033890)
- MS15-059 -- Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3064949)
- MS15-060 -- Vulnerability in Microsoft Common Controls Could Allow Remote Code Execution (3059317)
- MS15-061 -- Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (3057839)
- MS15-062 -- Vulnerability in Active Directory Federation Services Could Allow Elevation of Privilege (3062577)
- MS15-063 -- Vulnerability in Windows Kernel Could Allow Elevation of Privilege (3063858)
- MS15-064 -- Vulnerabilities in Microsoft Exchange Server Could Allow Elevation of Privilege (3062157)
Additional Update Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.
- Internet Explorer -- For additional information about the blocking of out-of-date ActiveX controls see the TechNet article, Out-of-date ActiveX control blocking. Additional changes introduced this month include the blocking of outdated Silverlight. Additional information is available in the IE Blog.
- Windows 8.x -- Non-security new features and improvements for Windows 8.1 are now included with the second Tuesday of the month updates. Additional information about this change is available here.
- Windows XP -- Although Microsoft has stopped providing Microsoft Security Essentials for Windows XP, definitions will be available until July 15, 2015. See Microsoft antimalware support for Windows XP. The MSRT still works on Windows XP.
References
- MSRC: June 2015 Updates
- TechNet: Microsoft Security Bulletin for June 2015

Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Tuesday, November 22, 2016
Microsoft Security Bulletin Release for October 2014
Microsoft Security Bulletin Release for October 2014

Microsoft released eight (8) bulletins. Three (3) bulletins are identified as Critical and five (5) as Important.
The updates address 24 Common Vulnerabilities & Exposures (CVEs) in Windows, Office, .NET Framework, .ASP.NET, and Internet Explorer (IE). Reminder to those who have problems with .NET updates to install separately with a restart between other updates.
Critical:
- MS14-056 -- Cumulative Security Update for Internet Explorer (2987107)
- MS14-057 -- Vulnerabilities in .NET Framework Could Allow Remote Code Execution (3000414)
- MS14-058 -- Vulnerability in Kernel-Mode Driver Could Allow Remote Code Execution (3000061)
Important:
- MS14-059 -- Vulnerability in ASP.NET MVC Could Allow Security Feature Bypass (2990942)
- MS14-060 -- Vulnerability in Windows OLE Could Allow Remote Code Execution (3000869)
- MS14-061 -- Vulnerability in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (3000434)
- MS14-062 -- Vulnerability in Message Queuing Service Could Allow Elevation of Privilege (2993254)
- MS14-063 -- Vulnerability in FAT32 Disk Partition Driver Could Allow Elevation of Privilege (2998579)
Security Advisories
The following security advisories were released:
- Update to Improve Credentials Protection and Management (2871997)
- Availability of SHA-2 Hashing Algorithm for Windows 7 and Windows Server 2008R (2949927)
- Update for Microsoft EAP Implementation that Enables the Use of TLS (2977292)
- Security Bulletin MS14-042: Vulnerability in Microsoft Service Bus Could Allow Denial of Service (2972621)
- Security Advisory 2755801: Update for Vulnerabilities in Adobe Flash Player in Internet Explorer
Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center. The updated version includes Win32/Hikiti and related families. Additional details ave available in the MMPC blog post.
- Internet Explorer -- For additional information about the blocking of out-of-date ActiveX controls see the TechNet article, Out-of-date ActiveX control blocking. Upcoming changes are included in the IE Blog.
- Windows 8.1 -- Non-security new features and improvements for Windows 8.1. are now included with the second Tuesday of the month updates. Additional information is available at August updates for Windows 8.1 and Windows Server 2012 R2.
- Windows XP -- Although Microsoft has stopped providing Microsoft Security Essentials for Windows XP, definitions will be available until July 15, 2015. See Microsoft antimalware support for Windows XP. The MSRT still works on Windows XP.
The following additional information is provided in the Security Bulletin:
- The affected software listed have been tested to determine which versions are affected. Other versions are past their support life cycle. To determine the support life cycle for your software version, visit Microsoft Support Lifecycle.
- Security solutions for IT professionals: TechNet Security Troubleshooting and Support
- Help protect your computer that is running Windows from viruses and malware: Virus Solution and Security Center
- Local support according to your country: International Support
References
- MSRC: October 2014 Security Updates
- TechNet: Microsoft Security Bulletin for October 2014

Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Friday, November 4, 2016
Microsoft Security Bulletin Release for January 2015
Microsoft Security Bulletin Release for January 2015

Microsoft released eight (8) bulletins. One (1) bulletin is identified as Critical and the remaining seven (7) are rated Important in severity.
The updates address 8 unique Common Vulnerabilities and Exposures (CVEs) in Microsoft Windows MS15-001 and MS15-003 have been publicly disclosed. Details about the CVEs can be found in the below-referenced TechNet Security Bulletin.
Important Note:
Although it was officially released in May, 2014, non-Security updates include the release of .NET Framework 4.5.2 to Automatic Updates, WSUS, and Catalog.
Because many people have problems with .NET updates, it is strongly recommended that they be installed separately from other updates with a shutdown/restart.
Critical:
- MS15-002 -- Vulnerability in Windows Telnet Service Could Allow Remote Code Execution (3020393)
Important:
- MS15-001 -- Vulnerability in Windows Application Compatibility Cache Could Allow Elevation of Privilege (3023266)
- MS15-003 -- Vulnerability in Windows User Profile Service Could Allow Elevation of Privilege (3021674)
- MS15-004 -- Vulnerability in Windows Components Could Allow Elevation of Privilege (3025421)
- MS15-005 -- Vulnerability in Network Location Awareness Service Could Allow Security Feature Bypass (3022777)
- MS15-006 -- Vulnerability in Windows Error Reporting Could Allow Security Feature Bypass (3004365)
- MS15-007 -- Vulnerability in Network Policy Server RADIUS Implementation Could Cause Denial of Service (3014029)
- MS15-008 -- Vulnerability in Windows Kernel-Mode Driver Could Allow Elevation of Privilege (3019215)
Security Bulletin MS14-080 Cumulative Security Update for Internet Explorer was re-released. Also note the following additional information:
- Information on non-security update information can be found in KB 894199.
- Outdated ActiveX control blocking will be added to Windows Vista SP2 and Windows Server 2008 SP2. See the TechNet article, Out-of-date ActiveX control blocking and the IE Blog for information on what this entails.
- For those interested in determining specific updates applicable to their operating system, see myBulletin.
Additional Update Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.
The updated version includes the Win32/Emotet and Win32/Dyap malware families. Additional details ave available in the MMPC blog post. - Internet Explorer -- For additional information about the blocking of out-of-date ActiveX controls see the TechNet article, Out-of-date ActiveX control blocking. Additional changes introduced this month include the blocking of outdated Silverlight. Additional information is available in the IE Blog.
- Windows 8.x -- Non-security new features and improvements for Windows 8.1 are now included with the second Tuesday of the month updates. Additional information about this change is available here.
- Windows XP -- Although Microsoft has stopped providing Microsoft Security Essentials for Windows XP, definitions will be available until July 15, 2015. See Microsoft antimalware support for Windows XP. The MSRT still works on Windows XP.
References
- MSRC: January 2015 Security Updates
- TechNet: Microsoft Security Bulletin for January 2015

Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Monday, October 24, 2016
Microsoft Security Release ISO Image September 2010
Microsoft Security Release ISO Image September 2010
This DVD5 ISO image file contains the security updates for Windows released on Windows Update on September 14th, 2010. The image does not contain security updates for other Microsoft products.

Read more »
More News www.softnetarchive.com
Available link for download
Saturday, October 8, 2016
Microsoft Security Bulletin Release for December 2014
Microsoft Security Bulletin Release for December 2014

Microsoft released seven (7) bulletins. Three (3) bulletins are identified as Critical and four (4) are rated Moderate in severity.
The updates address 24 unique Common Vulnerabilities and Exposures (CVEs) in Microsoft Windows, Internet Explorer (IE), Office and Exchange.
For those testing Windows 10 Technical Preview, please see the important information below.
Critical:
- MS14-080 -- Cumulative Security Update for Internet Explorer (3008923)
- MS14-081 -- Vulnerabilities in Microsoft Word and Microsoft Office Web Apps Could Allow Remote Code Execution (3017301)
- MS14-084 -- Vulnerability in VBScript Scripting Engine Could Allow Remote Code Execution (3016711)
- MS14-075 -- Vulnerabilities in Microsoft Exchange Server Could Allow Elevation of Privilege (3009712)
- MS14-082 -- Vulnerability in Microsoft Office Could Allow Remote Code Execution (3017349)
- MS14-083 -- Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (3017347)
- MS14-085 -- Vulnerability in Microsoft Graphics Component Could Allow Information Disclosure (3013126)
The following two Security Bulletins were re-released:
- MS14-065 Cumulative Security Update for Internet Explorer
- MS14-066 Vulnerability in Schannel Could Allow Remote Code Execution
Windows 10 Technical Preview
Updates to Windows 10 Technical Preview include three updates for 9879. Two of the updates address security vulnerabilities and one update is for a HDD failure affecting some people.Microsoft Office on Windows 10 Technical Preview:
Via https://twitter.com/GabeAul: For those running Microsoft Office on the Windows 10 Technical Preview, the installer fails on 9879 if Office is installed. The decision was made to publish as is rather than rolling a new fix which would result in the loss of several days in the process. Unfortunately, the workaround is painful: uninstall Office, install the hotfix, reinstall Office.
Before attempting the workaround to uninstall Office, try to install KB3022827 first. It will work for many, no harm if not.
Additional Update Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center. The updated version does not include new families but includes updates to several prevelant malware families. Additional details ave available in the MMPC blog post.
- Internet Explorer -- For additional information about the blocking of out-of-date ActiveX controls see the TechNet article, Out-of-date ActiveX control blocking. Additional changes introduced this month include the blocking of outdated Silverlight. Additional information is available in the IE Blog.
- Windows 8.x -- Non-security new features and improvements for Windows 8.1. are now included with the second Tuesday of the month updates. Additional information is available at August updates for Windows 8.1 and Windows Server 2012 R2.
- Windows XP -- Although Microsoft has stopped providing Microsoft Security Essentials for Windows XP, definitions will be available until July 15, 2015. See Microsoft antimalware support for Windows XP. The MSRT still works on Windows XP.
The following additional information is provided in the Security Bulletin:
- The affected software listed have been tested to determine which versions are affected. Other versions are past their support life cycle. To determine the support life cycle for your software version, visit Microsoft Support Lifecycle.
- Security solutions for IT professionals: TechNet Security Troubleshooting and Support
- Help protect your computer that is running Windows from viruses and malware: Virus Solution and Security Center
- Local support according to your country: International Support
References
- MSRC: December 2014 Security Updates
- TechNet: Microsoft Security Bulletin for December 2014

Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Saturday, October 1, 2016
Microsoft Security Bulletin Release for January 2016
Microsoft Security Bulletin Release for January 2016

Microsoft released nine (9) bulletins. Six (6) bulletins are identified as Critical and the remaining three (3) are rated Important in severity.
The updates address vulnerabilities in Microsoft Windows, Microsoft Edge, Internet Explorer, Microsoft .NET Framework, Microsoft Office, Visual Basic and Microsoft Silverlight.
Details about the 25 CVEs can be found in the below-referenced TechNet Security Bulletin. If you are prioritizing updates, the most critical appears to be MS16-05 which indicates "more severe of the vulnerabilities could allow remote code execution if a user visits a malicious website". Attention is also directed to MS16-001 which has the last updates for versions of Internet Explorer that have reached end of support.
Critical:
- MS16-001-- Cumulative Security Update for Internet Explorer (3124903)
- MS16-002-- Cumulative Security Update for Microsoft Edge (3124904)
- MS16-003-- Cumulative Security Update for JScript and VBScript to Address Remote Code Execution (3125540)
- MS16-004-- Security Update for Microsoft Office to Address Remote Code Execution (3124585)
- MS16-005-- Security Update for Windows Kernel-Mode Drivers to Address Remote Code Execution (3124584)
- MS16-006-- Security Update for Silverlight to Address Remote Code Execution (3126036)
Important:
- MS16-007-- Security Update for Microsoft Windows to Address Remote Code Execution (3124901)
- MS16-008-- Security Update for Windows Kernel to Address Elevation of Privilege (3124605)
- MS16-010-- Security Update in Microsoft Exchange Server to Address Spoofing (3124557)
Additional Update Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.
- Windows 8.x and Windows 10 -- Non-security new features and improvements for Windows 8.1 and Windows 10 are included with the updates.
References
- MSRC
- TechNet: Microsoft Security Bulletin for January 2016

Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Subscribe to:
Posts (Atom)