7 Security Bulletins were released – 1 Critical and 6 Important
We have not uncovered any widespread problems with any of these patches and are releasing all of them.
MS12-064 is the top priority this month. After your next patch cycle completes you should follow up and make sure this is installed. MS12-066 and MS12-067 are publicly disclosed and MS12-066 is already being exploited.
ONE out-of-band updates were released during the last month on 9/21/12. We previously blogged about this, but make sure that MS12-063 – Cumulative Security Update for Internet Explorer is applied to your machines
Noteworthy Patch News
nothing
This Month In Brief
Exploitability
- Publicly disclosed: MS12-066, MS12-067
- Being exploited: MS12-066
- Rated CRITICAL: MS12-064
- (The Severity Rating System: http://technet.microsoft.com/en-us/security/bulletin/rating )
Requires Restart
- Servers: Yes
- Workstations: Yes
Known Issues per Microsoft
- MS12-064 – check notes
- MS12-066 – check notes
- MS12-070 – check notes
New Security Bulletins
(MS#/Affected Software/Type)
CRITICAL
MS12-064: (Office Word) | This security update resolves two privately reported vulnerabilities in Microsoft Office. The more severe vulnerability could allow remote code execution if a user opens or previews a specially crafted RTF file. | |
IMPORTANT
MS12-065: (Works Converters) | The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Word file using Microsoft Works. | |
MS12-066: (Microsoft Office, Communications Platforms, Server software, and Office Web Apps) | The vulnerability could allow elevation of privilege if an attacker sends specially crafted content to a user. | |
MS12-067: (Fast Search Server) | The vulnerability could allow remote code execution if a user opens a specially crafted file or embeds a specially crafted Computer Graphics Metafile (CGM) graphics file into an Office file. | |
MS12-068: (Windows) | The vulnerability could allow elevation of privilege if an attacker logs on to the system and runs a specially crafted application. | |
MS12-069: (Kerberos) | The vulnerability could allow denial of service if a remote attacker sends a specially crafted session request to the Kerberos server. | |
MS12-070: (SQL Server Report Manager) | The vulnerability is a cross-site-scripting (XSS) vulnerability that could allow elevation of privilege, enabling an attacker to execute arbitrary commands on the SSRS site in the context of the targeted user. |