Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93098 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

MS Security Bulletin Summary - September 2015


  • Please log in to reply
9 replies to this topic

#1 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 08 September 2015 - 12:39 PM

FYI...

- https://technet.micr...curity/ms15-sep
Sep 8, 2015 - "This bulletin summary lists security bulletins released for September 2015...
(Total of -12-)

Microsoft Security Bulletin MS15-094 - Critical
Cumulative Security Update for Internet Explorer (3089548)
- https://technet.micr...curity/ms15-094
Critical - Remote Code Execution - Requires restart - Microsoft Windows, Internet Explorer

Microsoft Security Bulletin MS15-095 - Critical
Cumulative Security Update for Microsoft Edge (3089665)
- https://technet.micr...curity/ms15-095
Critical - Remote Code Execution - Requires restart - Microsoft Windows, Microsoft Edge

Microsoft Security Bulletin MS15-096 - Important
Vulnerability in Active Directory Service Could Allow Denial of Service (3072595)
- https://technet.micr...curity/ms15-096
Important - Denial of Service - Requires restart - Microsoft Windows

Microsoft Security Bulletin MS15-097 - Critical
Vulnerabilities in Microsoft Graphics Component Could Allow Remote Code Execution (3089656)
- https://technet.micr...curity/ms15-097
Critical - Remote Code Execution - May require restart - Microsoft Windows, Microsoft Office, Microsoft Lync

Microsoft Security Bulletin MS15-098 - Critical
Vulnerabilities in Windows Journal Could Allow Remote Code Execution (3089669)
- https://technet.micr...curity/ms15-098
Critical - Remote Code Execution - May require restart - Microsoft Windows

Microsoft Security Bulletin MS15-099 - Critical
Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3089664)
- https://technet.micr...curity/ms15-099
Critical - Remote Code Execution - May require restart - Microsoft Office, Microsoft SharePoint Foundation

Microsoft Security Bulletin MS15-100 - Important
Vulnerability in Windows Media Center Could Allow Remote Code Execution (3087918)
- https://technet.micr...curity/ms15-100
Important - Remote Code Execution - May require restart - Microsoft Windows

Microsoft Security Bulletin MS15-101 - Important
Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (3089662)
- https://technet.micr...curity/ms15-101
Important - Elevation of Privilege - Does not require restart - Microsoft Windows, Microsoft .NET Framework

Microsoft Security Bulletin MS15-102 - Important
Vulnerabilities in Windows Task Management Could Allow Elevation of Privilege (3089657)
- https://technet.micr...curity/ms15-102
Important - Elevation of Privilege - Requires restart - Microsoft Windows

Microsoft Security Bulletin MS15-103 - Important
Vulnerabilities in Microsoft Exchange Server Could Allow Information Disclosure (3089250)
- https://technet.micr...curity/ms15-103
Important - Information Disclosure - May require restart - Microsoft Exchange Server

Microsoft Security Bulletin MS15-104 - Important
Vulnerabilities in Skype for Business Server and Lync Server Could Allow Elevation of Privilege (3089952)
- https://technet.micr...curity/ms15-104
Important - Elevation of Privilege - Does not require restart - Skype for Business Server, Microsoft Lync Server

Microsoft Security Bulletin MS15-105 - Important
Vulnerability in Windows Hyper-V Could Allow Security Feature Bypass (3091287)
- https://technet.micr...curity/ms15-105
Important - Security Feature Bypass - Requires restart - Microsoft Windows
___

- http://blogs.technet...se-summary.aspx
8 Sep 2015

Microsoft Security Advisory 3083992
Update to Improve AppLocker Publisher Rule Enforcement
- https://technet.micr...ty/3083992.aspx
Sep 8, 2015 - "... a defense-in-depth update that improves the enforcement of publisher rules by Windows AppLocker in Windows 7, Windows Server 2008 R2, Windows 8, Windows Server 2012, Windows 8.1, and Windows Server 2012 R2. The improvement is part of ongoing efforts to bolster the effectiveness of AppLocker controls in Windows..."
___

September 2015 Office Update Release
- http://blogs.technet...te-release.aspx
8 Sep 2015 - "... There are 15 security updates (2 bulletins) and 41 non-security updates..."

> http://technet.micro...curity/ms15-097

> http://technet.micro...curity/ms15-099
___

MS15-094: http://www.securityt....com/id/1033487
MS15-095: http://www.securityt....com/id/1033491
MS15-096: http://www.securityt....com/id/1033492
MS15-097: http://www.securityt....com/id/1033485
- http://www.securityt....com/id/1033500
- http://www.securityt....com/id/1033501
MS15-098: http://www.securityt....com/id/1033484
MS15-099: http://www.securityt....com/id/1033488

- http://www.securityt....com/id/1033489
MS15-100: http://www.securityt....com/id/1033499
MS15-101: http://www.securityt....com/id/1033493
MS15-102: http://www.securityt....com/id/1033494
MS15-103: http://www.securityt....com/id/1033495
MS15-104: http://www.securityt....com/id/1033497
MS15-105: http://www.securityt....com/id/1033496
___

ISC Analysis
- https://isc.sans.edu...l?storyid=20129
Last Updated: 2015-09-08

.


Edited by AplusWebMaster, 14 September 2015 - 11:36 AM.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.

    Advertisements

Register to Remove


#2 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 09 September 2015 - 09:32 AM

FYI...

MS15-097: Description of the security update for the graphics component in Windows
- https://support.micr...n-us/kb/3086255
Last Review: 09/08/2015 17:38:00 - Rev: 2.0
"... Known issues in this security update:
    After you install this security update, some programs may not run. (For example, some video games may not run.) To work around this issue, you can temporarily turn on the service for the secdrv.sys driver by running certain commands, or by editing the registry.
    Note: When you no longer require the service to be running, we recommend that you turn off the service again.
    Warning: This workaround may make a computer or a network more vulnerable to attack by malicious users or by malicious software such as viruses. We do not recommend this workaround but are providing this information so that you can implement this workaround at your own discretion. Use this workaround at your own risk..."
 

:wall:


.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.


#3 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 16 September 2015 - 06:35 AM

FYI...

Software Update Services and Windows Server Update Services changes in content for 2015
- https://support.micr...en-us/kb/894199
Last Review: 09/15/2015 22:18:00 - Revision: 195.0
___

September 2015 Quarterly Exchange Updates
- http://blogs.technet...ge-updates.aspx
15 Sep 2015
___

Cumulative update for Windows 10
- https://support.micr...n-us/kb/3095020
Last Review: 09/15/2015 20:34:00 - Rev: 1.0
 

:ph34r: :ph34r:


Edited by AplusWebMaster, 16 September 2015 - 02:27 PM.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.


#4 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 20 September 2015 - 07:25 AM

FYI...

Updated: September 2015 Office Update Release
- http://blogs.technet...te-release.aspx
Update - Sept. 18, 2015
The cumulative updates for SharePoint and Project Server 2013, which were -not- included in the Sept. 8 release, are now available:
    September 17, 2015, cumulative update for SharePoint Foundation 2013 (KB2975894)
- https://support.micr...n-us/kb/2975894
    September 17, 2015, cumulative update for SharePoint Server 2013 (KB2986213)
- https://support.micr...n-us/kb/2986213
    September 17, 2015, cumulative update for Project Server 2013 (KB2986195)
- https://support.micr...n-us/kb/2986195
 

:unsure:


.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.


#5 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 22 September 2015 - 05:37 AM

FYI...

Microsoft Security Advisory 2755801
Update for Vulnerabilities in Adobe Flash Player in Internet Explorer and Microsoft Edge
- https://technet.micr...ecurity/2755801
Updated: Sep 21, 2015 - "... Microsoft released an update (3087040) for Internet Explorer 10 on Windows 8, Windows Server 2012, and Windows RT; Internet Explorer 11 on Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10; and Microsoft Edge on Windows 10. The update addresses the vulnerabilities described in Adobe Security bulletin APSB15-23. For more information about this update, including download links, see Microsoft Knowledge Base Article 3087040*."
* https://support.micr...n-us/kb/3087040
Last Review: 09/21/2015 17:08:00 - Rev: 1.0
 

:ph34r:


.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.


#6 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 23 September 2015 - 07:29 AM

FYI...

September 2015 servicing stack update for Windows 8 and Windows Server 2012
- https://support.micr...n-us/kb/3096053
Last Review: 09/23/2015 04:37:00 - Rev: 3.0
"Issues that are fixed in this update:
- This update fixes an issue in which you may not be able to install Security update 3069114 because of corruption that occurs during the installation. After you install update 3096053, update 3069114 can be installed successfully.
- Note: When you install update 3096053, there is a brief delay before the installation is finished. You should wait several minutes to make sure that update 3096053 is fully installed before you try to install update 3069114."

MS15-098: Description of the security update for Windows Journal: September 8, 2015
- https://support.micr...n-us/kb/3069114
Last Review: 09/08/2015 17:32:00 - Rev: 1.0
(See "Applies to...")
 

:ph34r: :ph34r:


.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.


#7 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 24 September 2015 - 08:26 PM

FYI...

Microsoft Security Advisory 3097966
Inadvertently Disclosed Digital Certificates Could Allow Spoofing
- https://technet.micr...ecurity/3097966
Sep 24, 2015 - "Microsoft is aware of four digital certificates that were inadvertently disclosed by D-Link Corporation that could be used in attempts to spoof content. The disclosed end-entity certificates cannot be used to issue other certificates or impersonate other domains, but could be used to sign code. This issue affects all supported releases of Microsoft Windows. To help protect customers from potentially fraudulent use of the certificates, Microsoft has modified the Certificate Trust List (CTL) to remove trust for the four certificates. Furthermore, the respective issuing certificate authorities have revoked the certificates...
Recommendation: Please see the Suggested Actions section of this advisory for instructions on applying an update for specific releases of Microsoft Windows...
Suggested Actions: Apply the update for supported releases of Microsoft Windows.
An automatic updater of revoked certificates is included in supported editions of Windows 8, Windows Server 2012, Windows RT, Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, and Windows 10 and for devices running Windows Phone 8 and Windows Phone 8.1. For these operating systems or devices, customers do not need to take any action, because the CTL will be updated automatically. For systems running Windows Vista, Windows 7, Windows Server 2008, or Windows Server 2008 R2 that are using the automatic updater of revoked certificates (see Microsoft Knowledge Base Article 2677070* for details), customers do not need to take any action, because these systems will be automatically protected..."
* https://support.micr...n-us/kb/2677070
Last Review: 02/17/2014 Rev: 6.0
 

:ph34r:


.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.


#8 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 30 September 2015 - 05:02 PM

FYI...

Mistakenly-deployed test patch leads to suspicious Windows update
- https://isc.sans.edu...l?storyid=20201
2015-09-30 - "Earlier today, various sources reported a highly-suspicious Windows update.  According to Ars Technica, a Microsoft spokesperson stated the company had incorrectly published a test update and is in the process of removing it [1]. The update is no longer available, and ZDNet has confirmed this was a test update "gone errant" [2]:
> https://isc.sans.edu...ry-image-01.jpg
Shown above: A screenshot someone posted on a Microsoft community forum [3]
Thanks to everyone who notified us at the ISC. See the references below for further information."
1] http://arstechnica.c...ered-worldwide/

2] http://www.zdnet.com...s-update-patch/

3] https://answers.micr...ee62725e?auth=1
 

:ph34r: :ph34r:


.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.


#9 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 02 October 2015 - 09:09 AM

FYI...

Cumulative update for Windows 10: September 30, 2015
- https://support.micr...n-us/kb/3093266
Last Review: 09/30/2015 18:36:00 - Rev: 1.0

- http://www.infoworld...e-failures.html
Oct 1, 2015
 

:ph34r: :ph34r:


.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.


#10 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 04 October 2015 - 04:31 AM

FYI...

MS KB's that may involve Win8.1 and Win7 Privacy issues:

MS snooping?
- http://windowssecret...ms-is-snooping/
Oct 1, 2015 - See "Windows telemetry service" and "Diagnostic Tracking Service".

___

 

Update that adds telemetry points to consent.exe in Win8.1 and Win7
- https://support.micr...n-us/kb/3075249
3075249 - Last Review: 08/18/2015 - Rev: 1.0
See "Applies to: ..."
___

Update for customer experience and diagnostic telemetry
- https://support.micr...n-us/kb/3080149
Last Review: 09/11/2015 - Rev: 5.0
See "Applies to: ..."
___

Update for customer experience and diagnostic telemetry
- https://support.micr...n-us/kb/3068708
Last Review: 09/11/2015 - Rev: 6.0
See "Applies to: ..."
___

Update installs Get Windows 10 app in Windows 8.1 and Windows 7 SP1
- https://support.micr...n-us/kb/3035583
Last Review: 10/05/2015 16:45:00 - Rev: 6.0

Compatibility update for upgrading Windows 7
- https://support.micr...n-us/kb/2952664
Last Review: 10/06/2015 16:38:00 - Rev: 15.0
Applies to: Windows 7 SP1

- http://www.infoworld...kb-2952664.html
Oct 6, 2015
___

Other update examples could include ...
- https://technet.micr...ecurity/3083992
- https://technet.micr...ecurity/3042058
- https://technet.micr...ecurity/3033929
- https://technet.micr...ecurity/3004375
- https://support.micr....com/kb/3080079
- https://support.micr....com/kb/2574819
___

GWX Control Panel (formerly GWX Stopper) to Permanently Remove the 'Get Windows 10' Icon:
- http://blog.ultimate...tly-remove.html
 

:ph34r: :ph34r:


Edited by AplusWebMaster, 07 October 2015 - 02:54 PM.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users