Microsoft Security Bulletin Summary for November 2012 : Stakes and Opportunities for customers
November 13, 2012 Microsoft released six security bulletins to
help protect customers. This release addresses 19 vulnerabilities in Microsoft
Windows Shell, Windows Kernel, Internet Explorer, Internet Information Services
(IIS), .NET Framework, and Excel. For those who need to prioritize deployment, Microsoft
recommends focusing on these two Critical updates first:
MS12-071 (Internet Explorer): This bulletin addresses three privately disclosed issues, none of which are currently known to be under active attack. Successful exploitation of these issues could result in code execution with the current user’s privileges. As such, Microsoft recommends the best practice of running applications with the least privileges possible in order to help mitigate potential risks.
MS12-075 (Windows Kernel): This security update addresses three privately reported issues, none of which are currently known to be under active attack. This bulletin affects all supported versions of Microsoft Windows. The most severe issue could result in remote code execution if an attacker is able to lure a user to a website with a maliciously crafted TrueType font file embedded.
Microsoft provides one such update for MS12-046 (Visual Basic), which is listed as available in the advisory. Also released MS12-062 (System Center Configuration Manager 2007) to address an issue in the localization of resource files.Learn more!
MS12-071 (Internet Explorer): This bulletin addresses three privately disclosed issues, none of which are currently known to be under active attack. Successful exploitation of these issues could result in code execution with the current user’s privileges. As such, Microsoft recommends the best practice of running applications with the least privileges possible in order to help mitigate potential risks.
MS12-075 (Windows Kernel): This security update addresses three privately reported issues, none of which are currently known to be under active attack. This bulletin affects all supported versions of Microsoft Windows. The most severe issue could result in remote code execution if an attacker is able to lure a user to a website with a maliciously crafted TrueType font file embedded.
Microsoft provides one such update for MS12-046 (Visual Basic), which is listed as available in the advisory. Also released MS12-062 (System Center Configuration Manager 2007) to address an issue in the localization of resource files.Learn more!
Comments