Jump to content
Nytro

Microsoft Security Bulletin Summary for May 2013

Recommended Posts

Posted

[h=1]Microsoft Security Bulletin Summary for May 2013[/h]

Published: Tuesday, May 14, 2013

Version: 1.0

This bulletin summary lists security bulletins released for May 2013.

With the release of the security bulletins for May 2013, this bulletin summary replaces the bulletin advance notification originally issued May 9, 2013. For more information about the bulletin advance notification service, see Microsoft Security Bulletin Advance Notification.

For information about how to receive automatic notifications whenever Microsoft security bulletins are issued, visit Microsoft Technical Security Notifications.

Microsoft is hosting a webcast to address customer questions on these bulletins on May 15, 2013, at 11:00 AM Pacific Time (US & Canada). Register now for the May Security Bulletin Webcast. After this date, this webcast is available on-demand.

Microsoft also provides information to help customers prioritize monthly security updates with any non-security updates that are being released on the same day as the monthly security updates. Please see the section, Other Information.

[h=3]Bulletin Information[/h][h=4]Executive Summaries[/h]The following table summarizes the security bulletins for this month in order of severity.

For details on affected software, see the next section, Affected Software.

[TABLE=class: dataTable, width: 88%]

[TR]

[TH]Bulletin ID[/TH]

[TH]Bulletin Title and Executive Summary[/TH]

[TH]Maximum Severity Rating and Vulnerability Impact[/TH]

[TH]Restart Requirement[/TH]

[TH]Affected Software[/TH]

[/TR]

[TR]

[TD]MS13-037[/TD]

[TD]Cumulative Security Update for Internet Explorer (2829530)This security update resolves eleven privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited the most severe of these vulnerabilities could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.[/TD]

[TD]Critical

Remote Code Execution[/TD]

[TD]Requires restart[/TD]

[TD]Microsoft Windows,

Internet Explorer [/TD]

[/TR]

[TR=class: alternateRow]

[TD]MS13-038[/TD]

[TD]Security Update for Internet Explorer (2847204)

This security update resolves one publicly disclosed vulnerability in Internet Explorer. The vulnerability could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.[/TD]

[TD]Critical

Remote Code Execution[/TD]

[TD]May require restart[/TD]

[TD]Microsoft Windows,

Internet Explorer [/TD]

[/TR]

[TR]

[TD]MS13-039[/TD]

[TD]Vulnerability in HTTP.sys Could Allow Denial of Service (2829254) This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if an attacker sends a specially crafted HTTP packet to an affected Windows server or client.[/TD]

[TD]Important

Denial of Service[/TD]

[TD]Requires restart[/TD]

[TD]Microsoft Windows [/TD]

[/TR]

[TR=class: alternateRow]

[TD]MS13-040 [/TD]

[TD]Vulnerabilities in .NET Framework Could Allow Spoofing (2836440)This security update resolves one privately reported vulnerability and one publicly disclosed vulnerabilityin the .NET Framework. The more severe of the vulnerabilities could allow spoofing if a .NET application receives a specially crafted XML file. An attacker who successfully exploited the vulnerabilities could modify the contents of an XML file without invalidating the file's signature and could gain access to endpoint functions as if they were an authenticated user.[/TD]

[TD]Important

Spoofing[/TD]

[TD]May require restart[/TD]

[TD]Microsoft Windows,

Microsoft .NET Framework [/TD]

[/TR]

[TR]

[TD]MS13-041[/TD]

[TD]Vulnerability in Lync Could Allow Remote Code Execution (2834695)

This security update resolves a privately reported vulnerability in Microsoft Lync. The vulnerability could allow remote code execution if an attacker shares specially crafted content, such as a file or program, as a presentation in Lync or Communicator and then convinces a user to accept an invitation to view or share the presentable content. In all cases, an attacker would have no way to force users to view or share the attacker-controlled file or program. Instead, an attacker would have to convince users to take action, typically by getting them to accept an invitation in Lync or Communicator to view or share the presentable content.[/TD]

[TD]Important

Remote Code Execution[/TD]

[TD]May require restart[/TD]

[TD]Microsoft Lync [/TD]

[/TR]

[TR=class: alternateRow]

[TD]MS13-042 [/TD]

[TD]Vulnerabilities in Microsoft Publisher Could Allow Remote Code Execution (2830397)This security update resolves eleven privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user open a specially crafted Publisher file with an affected version of Microsoft Publisher. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.[/TD]

[TD]Important

Remote Code Execution[/TD]

[TD]May require restart[/TD]

[TD]Microsoft Office [/TD]

[/TR]

[TR]

[TD]MS13-043[/TD]

[TD]Vulnerability in Microsoft Word Could Allow Remote Code Execution (2830399) This security update resolves one privately reported vulnerability in Microsoft Office. The vulnerability could allow code execution if a user opens a specially crafted file or previews a specially crafted email message in an affected version of Microsoft Office software. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.[/TD]

[TD]Important

Remote Code Execution[/TD]

[TD]May require restart[/TD]

[TD]Microsoft Office [/TD]

[/TR]

[TR=class: alternateRow]

[TD]MS13-044[/TD]

[TD]Vulnerability in Microsoft Visio Could Allow Information Disclosure (2834692)This security update resolves a privately reported vulnerability in Microsoft Office. The vulnerability could allow information disclosure if a user opens a specially crafted Visio file. Note that this vulnerability would not allow an attacker to execute code or to elevate their user rights directly, but it could be used to produce information that could be used to try to further compromise an affected system.[/TD]

[TD]Important

Information Disclosure[/TD]

[TD]May require restart[/TD]

[TD]Microsoft Office [/TD]

[/TR]

[TR]

[TD]MS13-045[/TD]

[TD]Vulnerability in Windows Essentials Could Allow Information Disclosure (2813707)This security update resolves a privately reported vulnerability in Windows Essentials. The vulnerability could allow information disclosure if a user opens Windows Writer using a specially crafted URL. An attacker who successfully exploited the vulnerability could override Windows Writer proxy settings and overwrite files accessible to the user on the target system. In a web-based attack scenario, a website could contain a specially crafted link that is used to exploit this vulnerability. An attacker would have to convince users to visit the website and open the specially crafted link.[/TD]

[TD]Important

Information Disclosure[/TD]

[TD]May require restart[/TD]

[TD]Microsoft Windows Essentials [/TD]

[/TR]

[TR=class: alternateRow]

[TD]MS13-046[/TD]

[TD]Vulnerabilities in Kernel-Mode Drivers Could Allow Elevation Of Privilege (2840221)

This security update resolves three privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logs on to the system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities.[/TD]

[TD]Important

Elevation of Privilege[/TD]

[TD]Requires restart[/TD]

[TD]Microsoft Windows [/TD]

[/TR]

[/TABLE]

Sursa: Microsoft Security Bulletin Summary for May 2013

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...