Monday, March 23, 2015

It’s March Madness for Microsoft this month as they release 14 separate security-related updates.



MS15-018 This update is cumulative and addresses several vulnerabilities which affect all supported versions of Internet Explorer.

MS15-019 repairs a scripting vulnerability in some older Windows versions

MS15-020 fixes a flaw in the way Microsoft Text Services handles objects in memory and how Microsoft Windows handles the loading of DLL files. This fix is associated with the bugs originally associated with Stuxnet, in 2010.

MS15-021 addresses an issue with the Adobe Font Driver. These vulnerabilities may allow remote code execution.

MS15-022 applies to all supported Microsoft Office versions (2007, 2010, and 2013), as well as the server-based Office Web Apps and SharePoint Server products. It fixes three known vulnerabilities in Office document formats as well as multiple cross-site scripting issues for SharePoint Server. The worst outcome allows remote code execution.  

Eight of the remaining nine updates affect Microsoft Windows, and the ninth update is to fix a Microsoft Exchange issue.

One of these updates is to resolve a problem with Windows Task Scheduler.  This issue was that a user could bypass file access controls and run executables files. Another update is to fix a DOS (Denial of Service) that only affects systems where Remote Desktop Protocol (RDP) is enabled. (By default, RDP is off on all Windows versions.)

MS15-031, fixes what has been known as the Schannel vulnerability, more popularly known as the FREAK technique . This update means Microsoft and Apple platforms are secured for Internet Explorer in Windows 10.

Systems with Internet Explorer 11 are also receiving an update to the built-in Flash Player code.

Also this month there are a number of other recommended updates.


If you have a Server with Microsoft Windows Server 2003 please note that support for Server 2003 ends July 14, 2015.  It is time to contact us to replace your 2003 server.

Clients with our Proactive Solution to Patch Management Automatically get the Updates.  

Contact us to find out how you can become "Proactive" instead of "Reactive".

Michael Glasser, Glasser Tech LLC (516) 762-0155

No comments:

Post a Comment