This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

MS Security Bulletin Summary - June 2013

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- https://technet.microsoft.com/en-us/securit…lletin/ms13-jun
June 11, 2013 - "This bulletin summary lists security bulletins released for June 2013…
(Total of -5-)

Microsoft Security Bulletin MS13-047 - Critical
Cumulative Security Update for Internet Explorer (2838727)
- https://technet.microsoft.com/en-us/securit…lletin/ms13-047
Critical - Remote Code Execution - Requires restart - Microsoft Windows, Internet Explorer

Microsoft Security Bulletin MS13-048 - Important
Vulnerability in Windows Kernel Could Allow Information Disclosure (2839229)
- https://technet.microsoft.com/en-us/securit…lletin/ms13-048
Important - Information Disclosure - Requires restart - Microsoft Windows
- https://support.microsoft.com/kb/2839229
Last Review: June 15, 2013 - Revision: 4.1 - "… MS13-048… Known issues with this security update:
Customers who use non-updated versions of certain Kingsoft software products may experience issues installing this security update. In some cases, systems may not successfully restart after security update 2839229 is applied, and customers may encounter a blue or blank screen. We are aware that Kingsoft antivirus and browser product components (kisknl.sys, knbdrv.sys, and dgsafe.sys) may be affected. We recommend that customers update their Kingsoft software to the latest versions -before- security update 2839229 is applied…"

Microsoft Security Bulletin MS13-049 - Important
Vulnerability in Kernel-Mode Driver Could Allow Denial of Service (2845690)
- https://technet.microsoft.com/en-us/securit…lletin/ms13-049
Important - Denial of Service - Requires restart - Microsoft Windows

Microsoft Security Bulletin MS13-050 - Important
Vulnerability in Windows Print Spooler Components Could Allow Elevation of Privilege
- https://technet.microsoft.com/en-us/securit…lletin/ms13-050
Important - Elevation of privilege - Requires restart - Microsoft Windows

Microsoft Security Bulletin MS13-051 - Important
Vulnerability in Microsoft Office Could Allow Remote Code Execution (2839571)
- https://technet.microsoft.com/en-us/securit…lletin/ms13-051
Important - Remote Code Execution - May require restart - Microsoft Office
___

- http://blogs.technet.com/b/srd/archive/201…Redirected=true
11 Jun 2013 - "MS13-051… We have seen this vulnerability exploited in targeted 0day attacks in the wild…"

- https://krebsonsecurity.com/2013/06/adobe-m…-flash-windows/
11 Jun 2013 - "… five updates address 23 vulnerabilities in Windows, Internet Explorer, and Office…"

- http://blogs.technet.com/b/msrc/archive/20…Redirected=true

Bulletin Deployment Priority
- https://blogs.technet.com/cfs-filesystemfil…13-DP-Slide.PNG

Severity and Exploitability Index
- https://blogs.technet.com/cfs-filesystemfil…nd-Severity.PNG
___

- https://secunia.com/advisories/53728/ - MS13-047
- https://secunia.com/advisories/53739/ - MS13-048
- https://secunia.com/advisories/53741/ - MS13-049
- https://secunia.com/advisories/53742/ - MS13-050
- https://secunia.com/advisories/53747/ - MS13-051
___

ISC Analysis
- https://isc.sans.edu/diary.html?storyid=15977
Last Updated: 2013-06-11 17:10:35 UTC
___

MSRT
- https://support.microsoft.com/?kbid=890830
June 11, 2013 - Revision: 123.0

- http://www.microsoft.com/security/pc-secur…e-families.aspx
"… added in this release…
• Tupym…"

Download:
- https://www.microsoft.com/en-us/download/ma…ol-details.aspx
Windows-KB890830-V5.1.exe - 19.1 MB
… Change systems:
Windows Malicious Software Removal Tool x64:
Windows-KB890830-x64-V5.1.exe - 19.9 MB

.
FYI…

MS13-029 re-released for XPSP3 …
Microsoft Security Bulletin MS13-029 - Critical
- https://technet.microsoft.com/en-us/securit…lletin/ms13-029
… Update FAQ: Why was this bulletin revised on June 25, 2013?
Microsoft revised this bulletin to rerelease the 2813347 update for Remote Desktop Connection 7.0 Client on Windows XP Service Pack 3. The rereleased update addresses an issue with the original update that caused the update to be incorrectly reoffered to systems running in specific configurations. Microsoft recommends that customers running the affected software apply the rereleased security update immediately…

V2.0 (June 25, 2013): Revised bulletin to rerelease the 2813347 update for Remote Desktop Connection 7.0 Client on Windows XP Service Pack 3. Microsoft recommends that customers running the affected software apply the rereleased security update immediately…

- https://support.microsoft.com/kb/2828223
Last Review: June 25, 2013 - Revision: 2.0

:ph34r: :ph34r: