Microsoft Patch Tuesday - January 2012
Thursday, 05 January 2012

Microsoft has issued a Security Bulletin Advance Notification indicating that its January release will contain seven bulletins. These bulletins will have the severity rating of critical and important and will be for Microsoft Windows and Microsoft Developer Tools and Software. Release of these bulletins is scheduled for Tuesday, January 10, 2012.

 

 

Bulletin IDBulletin Title and Executive SummaryMaximum Severity Rating and Vulnerability ImpactRestart RequirementAffected Software
MS12-004Vulnerabilities in Windows Media Could Allow Remote Code Execution (2636391) 

This security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow remote code execution if a user opens a specially crafted media file. An attacker who successfully exploited the vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Critical 
Remote Code Execution
Requires restartMicrosoft Windows
MS12-001Vulnerability in Windows Kernel Could Allow Security Feature Bypass (2644615) 

This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow an attacker to bypass the SafeSEH security feature in a software application. An attacker could then use other vulnerabilities to leverage the structured exception handler to run arbitrary code. Only software applications that were compiled using Microsoft Visual C++ .NET 2003 can be used to exploit this vulnerability.
Important 
Security Feature Bypass
Requires restartMicrosoft Windows
MS12-002Vulnerability in Windows Object Packager Could Allow Remote Code Execution (2603381) 

This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate file with an embedded packaged object that is located in the same network directory as a specially crafted executable file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Important 
Remote Code Execution
May require restartMicrosoft Windows
MS12-003Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2646524) 

This security update resolves one privately reported vulnerability in Microsoft Windows. This security update is rated Important for all supported editions of Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008. All supported editions of Windows 7 and Windows Server 2008 R2 are not affected by this vulnerability.

The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application. The attacker could then take complete control of the affected system and install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability can only be exploited on systems configured with a Chinese, Japanese, or Korean system locale.
Important 
Elevation of Privilege
Requires restartMicrosoft Windows
MS12-005Vulnerability in Microsoft Windows Could Allow Remote Code Execution (2584146) 

This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Office file containing a malicious embedded ClickOnce application. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Important 
Remote Code Execution
May require restartMicrosoft Windows
MS12-006Vulnerability in SSL/TLS Could Allow Information Disclosure (2643584) 

This security update resolves a publicly disclosed vulnerability in SSL 3.0 and TLS 1.0. This vulnerability affects the protocol itself and is not specific to the Windows operating system. The vulnerability could allow information disclosure if an attacker intercepts encrypted web traffic served from an affected system. TLS 1.1, TLS 1.2, and all cipher suites that do not use CBC mode are not affected.
Important 
Information Disclosure
Requires restartMicrosoft Windows
MS12-007Vulnerability in AntiXSS Library Could Allow Information Disclosure (2607664) 

This security update resolves one privately reported vulnerability in the Microsoft Anti-Cross Site Scripting (AntiXSS) Library. The vulnerability could allow information disclosure if a an attacker passes a malicious script to a website using the sanitization function of the AntiXSS Library. The consequences of the disclosure of that information depend on the nature of the information itself. Note that this vulnerability would not allow an attacker to execute code or to elevate the attacker's user rights directly, but it could be used to produce information that could be used to try to further compromise the affected system. Only sites that use the sanitization module of the AntiXSS Library are affected by this vulnerability.
Important 
Information Disclosure
May require restartMicrosoft Developer Tools and Software

 

 

Windows Operating System and Components

 

Windows XP
Bulletin IdentifierMS12-004MS12-001MS12-002MS12-003MS12-005MS12-006
Aggregate Severity RatingCriticalImportantImportantImportantImportantImportant
Windows XP Service Pack 3Windows Multimedia Library
(KB2598479)
(Critical)

Windows Multimedia Library
(KB2628259)
(Windows XP Media Center Edition 2005 Service Pack 3 only)
(Critical)

DirectShow
(KB2631813)
(Important)
Not applicableWindows XP Service Pack 3
(Important)
Windows XP Service Pack 3
(Important)
Windows XP Service Pack 3
(Important)
Windows XP Service Pack 3
(KB2585542)
(Important)
Windows XP Professional x64 Edition Service Pack 2Windows Multimedia Library
(KB2598479)
(Critical)

DirectShow
(KB2631813)
(Important)
Windows XP Professional x64 Edition Service Pack 2
(Important)
Windows XP Professional x64 Edition Service Pack 2
(Important)
Windows XP Professional x64 Edition Service Pack 2
(Important)
Windows XP Professional x64 Edition Service Pack 2
(Important)
Windows XP Professional x64 Edition Service Pack 2
(KB2585542)
(Important)

Windows XP Professional x64 Edition Service Pack 2
(KB2638806)
(Important)
Windows Server 2003
BulletinIdentifierMS12-004MS12-001MS12-002MS12-003MS12-005MS12-006
AggregateSeverity RatingCriticalImportantImportantImportantImportantImportant
Windows Server 2003 Service Pack 2Windows Multimedia Library
(KB2598479)
(Critical)

DirectShow
(KB2631813)
(Important)
Windows Server 2003 Service Pack 2
(Important)
Windows Server 2003 Service Pack 2
(Important)
Windows Server 2003 Service Pack 2
(Important)
Windows Server 2003 Service Pack 2
(Important)
Windows Server 2003 Service Pack 2
(KB2585542)
(Important)

Windows Server 2003 Service Pack 2
(KB2638806)
(Important)
Windows Server 2003 x64 Edition Service Pack 2Windows Multimedia Library
(KB2598479)
(Critical)

DirectShow
(KB2631813)
(Important)
Windows Server 2003 x64 Edition Service Pack 2
(Important)
Windows Server 2003 x64 Edition Service Pack 2
(Important)
Windows Server 2003 x64 Edition Service Pack 2
(Important)
Windows Server 2003 x64 Edition Service Pack 2
(Important)
Windows Server 2003 x64 Edition Service Pack 2
(KB2585542)
(Important)

Windows Server 2003 x64 Edition Service Pack 2
(KB2638806)
(Important)
Windows Server 2003 with SP2 for Itanium-based SystemsWindows Multimedia Library
(KB2598479)
(Critical)

DirectShow
(KB2631813)
(Important)
Windows Server 2003 with SP2 for Itanium-based Systems
(Important)
Windows Server 2003 with SP2 for Itanium-based Systems
(Important)
Windows Server 2003 with SP2 for Itanium-based Systems
(Important)
Windows Server 2003 with SP2 for Itanium-based Systems
(Important)
Windows Server 2003 with SP2 for Itanium-based Systems
(KB2585542)
(Important)

Windows Server 2003 with SP2 for Itanium-based Systems
(KB2638806)
(Important)
Windows Vista
Bulletin IdentifierMS12-004MS12-001MS12-002MS12-003MS12-005MS12-006
Aggregate Severity RatingCriticalImportantNoneImportantImportantImportant
Windows Vista Service Pack 2Windows Multimedia Library
(KB2598479)
(Critical)

Windows Media Center TV Pack for Windows Vista (32-bit editions)[1]
(KB2628642)
(Important)

DirectShow
(KB2631813)
(Important)
Windows Vista Service Pack 2
(Important)
Not applicableWindows Vista Service Pack 2
(Important)
Windows Vista Service Pack 2
(Important)
Windows Vista Service Pack 2
(KB2585542)
(Important)
Windows Vista x64 Edition Service Pack 2Windows Multimedia Library
(KB2598479)
(Critical)

Windows Media Center TV Pack for Windows Vista (64-bit editions)[1]
(KB2628642)
(Important)

DirectShow
(KB2631813)
(Important)
Windows Vista x64 Edition Service Pack 2
(Important)
Not applicableWindows Vista x64 Edition Service Pack 2
(Important)
Windows Vista x64 Edition Service Pack 2
(Important)
Windows Vista x64 Edition Service Pack 2
(KB2585542)
(Important)
Windows Server 2008
Bulletin IdentifierMS12-004MS12-001MS12-002MS12-003MS12-005MS12-006
Aggregate Severity RatingCriticalImportantNoneImportantImportantImportant
Windows Server 2008 for 32-bit Systems Service Pack 2Windows Multimedia Library*
(KB2598479)
(Critical)

DirectShow**
(KB2631813)
(Important)
Windows Server 2008 for 32-bit Systems Service Pack 2*
(Important)
Not applicableWindows Server 2008 for 32-bit Systems Service Pack 2*
(Important)
Windows Server 2008 for 32-bit Systems Service Pack 2**
(Important)
Windows Server 2008 for 32-bit Systems Service Pack 2*
(KB2585542)
(Important)
Windows Server 2008 for x64-based Systems Service Pack 2Windows Multimedia Library*
(KB2598479)
(Critical)

DirectShow**
(KB2631813)
(Important)
Windows Server 2008 for x64-based Systems Service Pack 2*
(Important)
Not applicableWindows Server 2008 for x64-based Systems Service Pack 2*
(Important)
Windows Server 2008 for x64-based Systems Service Pack 2**
(Important)
Windows Server 2008 for x64-based Systems Service Pack 2*
(KB2585542)
(Important)
Windows Server 2008 for Itanium-based Systems Service Pack 2Windows Multimedia Library
(KB2598479)
(Critical)

DirectShow
(KB2631813)
(Important)
Windows Server 2008 for Itanium-based Systems Service Pack 2
(Important)
Not applicableWindows Server 2008 for Itanium-based Systems Service Pack 2
(Important)
Windows Server 2008 for Itanium-based Systems Service Pack 2
(Important)
Windows Server 2008 for Itanium-based Systems Service Pack 2
(KB2585542)
(Important)
Windows 7
Bulletin IdentifierMS12-004MS12-001MS12-002MS12-003MS12-005MS12-006
Aggregate Severity RatingImportantImportantNoneNoneImportantImportant
Windows 7 for 32-bit Systems and Windows 7 for 32-bit Systems Service Pack 1DirectShow
(KB2631813)
(Important)
Windows 7 for 32-bit Systems and Windows 7 for 32-bit Systems Service Pack 1
(Important)
Not applicableNot applicableWindows 7 for 32-bit Systems and Windows 7 for 32-bit Systems Service Pack 1
(Important)
Windows 7 for 32-bit Systems and Windows 7 for 32-bit Systems Service Pack 1
(KB2585542)
(Important)
Windows 7 for x64-based Systems and Windows 7 for x64-based Systems Service Pack 1DirectShow
(KB2631813)
(Important)
Windows 7 for x64-based Systems and Windows 7 for x64-based Systems Service Pack 1
(Important)
Not applicableNot applicableWindows 7 for x64-based Systems and Windows 7 for x64-based Systems Service Pack 1
(Important)
Windows 7 for x64-based Systems and Windows 7 for x64-based Systems Service Pack 1
(KB2585542)
(Important)
Windows Server 2008 R2
Bulletin IdentifierMS12-004MS12-001MS12-002MS12-003MS12-005MS12-006
Aggregate Severity RatingImportantImportantNoneNoneImportantImportant
Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1DirectShow**
(KB2631813)
(Important)
Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1*
(Important)
Not applicableNot applicableWindows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1**
(Important)
Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1*
(KB2585542)
(Important)
Windows Server 2008 R2 for Itanium-based Systems and Windows Server 2008 R2 for Itanium-based Systems Service Pack 1DirectShow
(KB2631813)
(Important)
Windows Server 2008 R2 for Itanium-based Systems and Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
(Important)
Not applicableNot applicableWindows Server 2008 R2 for Itanium-based Systems and Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
(Important)
Windows Server 2008 R2 for Itanium-based Systems and Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
(KB2585542)
(Important)

Microsoft Developer Tools and Software 

Microsoft Anti-Cross Site Scripting Library
Bulletin IdentifierMS12-007
Aggregate Severity RatingImportant
Microsoft Anti-Cross Site Scripting Library V3.x and Microsoft Anti-Cross Site Scripting Library V4.0Microsoft Anti-Cross Site Scripting Library V3.x and Microsoft Anti-Cross Site Scripting Library V4.0[1][2]

 

 

 
< Prev   Next >
Advertisement
© d-PIT, 2007-2012.

Site Disclaimer