With this Microsoft Patch Tuesday update, we see a large set of updates in comparison to the recent small list of updates release by Microsoft for the month of January. In total there are 12 Microsoft Security Updates with the following rating; 3 Critical and 9 as rated Important. Though this is a large update from Microsoft, the impact for the updates is relatively small and only affecting a small number of packages across the AOK sample application portfolio.
Given the nature of the changes and updates included in each of these patches, most systems will require a reboot to successfully implement any and all of the patches and updates released in this February Patch Tuesday release cycle.
The top image is a sample of the results for one application and a summary of the Patch Tuesday results for one of our AOK Sample databases.
MS11-009: Vulnerabilities in Jscript and VBScript Scripting Engine could allow information disclosure.
Below that is a sample screen shot of the AOK Summary Information HTML report from a small sample database.
Testing Summary - MS11-003 : Cumulative Security Update for Internet Explorer (2482017)
- MS11-004 : Vulnerability in Internet Information Services (IIS) FTP Service Could Allow Remote Code Execution (2489256)
- MS11-005 : Vulnerability in Active Directory Could Allow Denial of Service (2478953)
- MS11-006 : Vulnerability in Windows Shell Graphics Processing Could Allow Remote Code Execution (2483185)
- MS11-007 : Vulnerability in the OpenType Compact Font Format (CFF) Driver Could Allow Remote Code Execution (2485376)
- MS11-008 : Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (2451879)
- MS11-009 : Vulnerability in JScript and VBScript Scripting Engines Could Allow Information Disclosure (2475792)
- MS11-010 : Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2476687)
- MS11-011 : Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2393802)
- MS11-012 : Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2479628)
- MS11-013 : Vulnerabilities in Kerberos Could Allow Elevation of Privilege (2496930)
- MS11-014 : Vulnerability in Local Security Authority Subsystem Service Could Allow Local Elevation of Privilege (2478960)
Patch Name | Total
Issues | Matches
Affected | Reboot | Rating | RAG |
Microsoft Security Bulletin MS11-003 | <1% | <1% | YES | | |
Microsoft Security Bulletin MS11-004 | <1% | <1% | YES | | |
Microsoft Security Bulletin MS11-005 | <1% | <1% | YES | | |
Microsoft Security Bulletin MS11-006 | <1% | <1% | YES | | |
Microsoft Security Bulletin MS11-007 | <1% | <1% | YES | | |
Microsoft Security Bulletin MS11-008 | <1% | <1% | YES | | |
Microsoft Security Bulletin MS11-009 | <1% | <1% | YES | | |
Microsoft Security Bulletin MS11-010 | <1% | <1% | YES | | |
Microsoft Security Bulletin MS11-011 | <1% | <1% | YES | | |
Microsoft Security Bulletin MS11-012 | <1% | <1% | YES | | |
Microsoft Security Bulletin MS11-013 | <1% | <1% | YES | | |
Microsoft Security Bulletin MS11-014 | <1% | <1% | YES | | |
Legend:
| No Issues Detected |
| Potentially fixable application Impact |
| Serious Compatibility Issue |
Security Update Detailed Summary
MS11-003 | Cumulative Security Update for Internet Explorer (2482017) |
Description | This security update resolves two privately reported vulnerabilities and two publicly disclosed vulnerabilities in Internet Explorer. The vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer or if a user opens a legitimate HTML file that loads a specially crafted library file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. |
Payload | Browseui.dll, Html.iec, Ieencode.dll, Iepeers.dll, Mshtml.dll, Mshtmled.dll, Mstime.dll, Shdocvw.dll, Tdc.ocx, Urlmon.dll, Wininet.dll |
Impact | Critical - Remote Code Execution |
MS11-004 | Vulnerability in Internet Information Services (IIS) FTP Service Could Allow Remote Code Execution (2489256) |
Description | This security update resolves a publicly disclosed vulnerability in Microsoft Internet Information Services (IIS) FTP Service. The vulnerability could allow remote code execution if an FTP server receives a specially crafted FTP command. FTP Service is not installed by default on IIS. |
Payload | Ftpconfigext.dll, Ftpctrlps.dll, Ftpmib.dll, Ftpres.dll, Ftpsvc.dll, Ftpsvc.mof |
Impact | Important - Remote Code Execution |
MS11-005 | Vulnerability in Active Directory Could Allow Denial of Service (2478953) |
Description | This security update resolves a publicly disclosed vulnerability in Active Directory. The vulnerability could allow denial of service if an attacker sent a specially crafted packet to an affected Active Directory server. The attacker must have valid local administrator privileges on the domain-joined computer in order to exploit this vulnerability. |
Payload | Netlogon.dll, Ntdsa.dll, Wnetlogon.dll, Wntdsa.dll |
Impact | Important - Denial of Service |
MS11-006 | Vulnerability in Windows Shell Graphics Processing Could Allow Remote Code Execution (2483185) |
Description | This security update resolves a publicly disclosed vulnerability in the Windows Shell graphics processor. The vulnerability could allow remote code execution if a user views a specially crafted thumbnail image. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. |
Payload | Shell32.dll, Shimgvw.dll |
Impact | Critical - Remote Code Execution |
MS11-007 | Vulnerability in the OpenType Compact Font Format (CFF) Driver Could Allow Remote Code Execution (2485376) |
Description | This security update resolves a privately reported vulnerability in the Windows OpenType Compact Font Format (CFF) driver. The vulnerability could allow remote code execution if a user views content rendered in a specially crafted CFF font. In all cases, an attacker would have no way to force users to view the specially crafted content. Instead, an attacker would have to convince users to visit a Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker's Web site. |
Payload | Atmfd.dll |
Impact | Critical - Remote Code Execution |
MS11-008 | Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (2451879) |
Description | This security update resolves two privately reported vulnerabilities in Microsoft Visio. The vulnerabilities could allow remote code execution if a user opens a specially crafted Visio file. An attacker who successfully exploited either of these vulnerabilities could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. |
Payload | Dfdc.dll, Dwgcnvt.dll, F218_gdiplus.dll.4540efcf_5448_414f_be31_0b2aaf52e7b9, Mso.dll.d0df3458_a845_11d3_8d0a_0050046416b9, Ormelems.dll, Umlc.dll, Umlsystem.dll, Visio.exe, Visiodwg.dll, Vislib.dll |
Impact | Important - Remote Code Execution |
MS11-009 | Vulnerability in JScript and VBScript Scripting Engines Could Allow Information Disclosure (2475792) |
Description | This security update resolves a privately reported vulnerability in the JScript and VBScript scripting engines. The vulnerability could allow information disclosure if a user visited a specially crafted Web site. An attacker would have no way to force users to visit these Web sites. Instead, an attacker would have to convince users to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker's Web site. |
Payload | Jscript.dll, Vbscript.dll |
Impact | Important - Information Disclosure |
MS11-010 | Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2476687) |
Description | This security update resolves a privately reported vulnerability in the Microsoft Windows Client/Server Run-time Subsystem (CSRSS) in Windows XP and Windows Server 2003. |
Payload | Csrsrv.dll |
Impact | Important - Elevation of Privilege |
MS11-011 | Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2393802) |
Description | This security update resolves one publicly disclosed vulnerability and one privately reported vulnerability in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logged on locally and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities. The vulnerabilities could not be exploited remotely or by anonymous users. |
Payload | Ntdll.dll, Ntkrnlmp.exe, Ntkrnlpa.exe, Ntkrpamp.exe, Ntoskrnl.exe, Mpsyschk.dll |
Impact | Important - Elevation of Privilege |
MS11-012 | Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2479628) |
Description | This security update resolves five privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logged on locally and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities. The vulnerabilities could not be exploited remotely or by anonymous users. |
Payload | Win32k.sys, W32ksign.dll |
Impact | Important - Elevation of Privilege |
MS11-013 | Vulnerabilities in Kerberos Could Allow Elevation of Privilege (2496930) |
Description | This security update resolves one privately reported vulnerability and one publicly disclosed vulnerability in Microsoft Windows. The more severe of these vulnerabilities could allow elevation of privilege if a local, authenticated attacker installs a malicious service on a domain-joined computer. |
Payload | Kerberos.dll |
Impact | Important - Elevation of Privilege |
MS11-014 | Vulnerability in Local Security Authority Subsystem Service Could Allow Local Elevation of Privilege (2478960) |
Description | This security update resolves a privately reported vulnerability in the Local Security Authority Subsystem Service (LSASS) in Windows XP and Windows Server 2003. |
Payload | Lsasrv.dll |
Impact | Important - Elevation of Privilege |
*All results are based on an AOK Application Compatibility Lab’s test portfolio of over 1,000 applications. |
No comments:
Post a Comment