Microsoft Security Bulletin MS15-094 - Critical
Cumulative Security Update for Internet Explorer (3089548)
- https://technet.microsoft.com/library/security/ms15-094
Critical - Remote Code Execution - Requires restart - Microsoft Windows, Internet Explorer
Microsoft Security Bulletin MS15-095 - Critical
Cumulative Security Update for Microsoft Edge (3089665)
- https://technet.microsoft.com/library/security/ms15-095
Critical - Remote Code Execution - Requires restart - Microsoft Windows, Microsoft Edge
Microsoft Security Bulletin MS15-096 - Important
Vulnerability in Active Directory Service Could Allow Denial of Service (3072595)
- https://technet.microsoft.com/library/security/ms15-096
Important - Denial of Service - Requires restart - Microsoft Windows
Microsoft Security Bulletin MS15-097 - Critical
Vulnerabilities in Microsoft Graphics Component Could Allow Remote Code Execution (3089656)
- https://technet.microsoft.com/library/security/ms15-097
Critical - Remote Code Execution - May require restart - Microsoft Windows, Microsoft Office, Microsoft Lync
Microsoft Security Bulletin MS15-098 - Critical
Vulnerabilities in Windows Journal Could Allow Remote Code Execution (3089669)
- https://technet.microsoft.com/library/security/ms15-098
Critical - Remote Code Execution - May require restart - Microsoft Windows
Microsoft Security Bulletin MS15-099 - Critical
Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3089664)
- https://technet.microsoft.com/library/security/ms15-099
Critical - Remote Code Execution - May require restart - Microsoft Office, Microsoft SharePoint Foundation
Microsoft Security Bulletin MS15-100 - Important
Vulnerability in Windows Media Center Could Allow Remote Code Execution (3087918)
- https://technet.microsoft.com/library/security/ms15-100
Important - Remote Code Execution - May require restart - Microsoft Windows
Microsoft Security Bulletin MS15-101 - Important
Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (3089662)
- https://technet.microsoft.com/library/security/ms15-101
Important - Elevation of Privilege - Does not require restart - Microsoft Windows, Microsoft .NET Framework
Microsoft Security Bulletin MS15-102 - Important
Vulnerabilities in Windows Task Management Could Allow Elevation of Privilege (3089657)
- https://technet.microsoft.com/library/security/ms15-102
Important - Elevation of Privilege - Requires restart - Microsoft Windows
Microsoft Security Bulletin MS15-103 - Important
Vulnerabilities in Microsoft Exchange Server Could Allow Information Disclosure (3089250)
- https://technet.microsoft.com/library/security/ms15-103
Important - Information Disclosure - May require restart - Microsoft Exchange Server
Microsoft Security Bulletin MS15-104 - Important
Vulnerabilities in Skype for Business Server and Lync Server Could Allow Elevation of Privilege (3089952)
- https://technet.microsoft.com/library/security/ms15-104
Important - Elevation of Privilege - Does not require restart - Skype for Business Server, Microsoft Lync Server
Microsoft Security Bulletin MS15-105 - Important
Vulnerability in Windows Hyper-V Could Allow Security Feature Bypass (3091287)
- https://technet.microsoft.com/library/security/ms15-105
Important - Security Feature Bypass - Requires restart - Microsoft Windows
___
Microsoft Security Advisory 3083992
Update to Improve AppLocker Publisher Rule Enforcement
- https://technet.microsoft.com/library/security/3083992.aspx
Sep 8, 2015 - "… a defense-in-depth update that improves the enforcement of publisher rules by Windows AppLocker in Windows 7, Windows Server 2008 R2, Windows 8, Windows Server 2012, Windows 8.1, and Windows Server 2012 R2. The improvement is part of ongoing efforts to bolster the effectiveness of AppLocker controls in Windows…"
___
MS15-097: Description of the security update for the graphics component in Windows
- https://support.microsoft.com/en-us/kb/3086255
Last Review: 09/08/2015 17:38:00 - Rev: 2.0
"… Known issues in this security update:
After you install this security update, some programs may not run. (For example, some video games may not run.) To work around this issue, you can temporarily turn on the service for the secdrv.sys driver by running certain commands, or by editing the registry.
Note: When you no longer require the service to be running, we recommend that you turn off the service again.
Warning: This workaround may make a computer or a network more vulnerable to attack by malicious users or by malicious software such as viruses. We do not recommend this workaround but are providing this information so that you can implement this workaround at your own discretion. Use this workaround at your own risk…"
Software Update Services and Windows Server Update Services changes in content for 2015
- https://support.microsoft.com/en-us/kb/894199
Last Review: 09/15/2015 22:18:00 - Revision: 195.0
___
Microsoft Security Advisory 2755801
Update for Vulnerabilities in Adobe Flash Player in Internet Explorer and Microsoft Edge
- https://technet.microsoft.com/en-us/library/security/2755801
Updated: Sep 21, 2015 - "… Microsoft released an update (3087040) for Internet Explorer 10 on Windows 8, Windows Server 2012, and Windows RT; Internet Explorer 11 on Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10; and Microsoft Edge on Windows 10. The update addresses the vulnerabilities described in Adobe Security bulletin APSB15-23. For more information about this update, including download links, see Microsoft Knowledge Base Article 3087040*."
* https://support.microsoft.com/en-us/kb/3087040
Last Review: 09/21/2015 17:08:00 - Rev: 1.0
September 2015 servicing stack update for Windows 8 and Windows Server 2012
- https://support.microsoft.com/en-us/kb/3096053
Last Review: 09/23/2015 04:37:00 - Rev: 3.0
"Issues that are fixed in this update:
- This update fixes an issue in which you may not be able to install Security update 3069114 because of corruption that occurs during the installation. After you install update 3096053, update 3069114 can be installed successfully.
- Note: When you install update 3096053, there is a brief delay before the installation is finished. You should wait several minutes to make sure that update 3096053 is fully installed before you try to install update 3069114."
MS15-098: Description of the security update for Windows Journal: September 8, 2015
- https://support.microsoft.com/en-us/kb/3069114
Last Review: 09/08/2015 17:32:00 - Rev: 1.0 (See "Applies to…")
Microsoft Security Advisory 3097966
Inadvertently Disclosed Digital Certificates Could Allow Spoofing
- https://technet.microsoft.com/library/security/3097966
Sep 24, 2015 - "Microsoft is aware of four digital certificates that were inadvertently disclosed by D-Link Corporation that could be used in attempts to spoof content. The disclosed end-entity certificates cannot be used to issue other certificates or impersonate other domains, but could be used to sign code. This issue affects all supported releases of Microsoft Windows. To help protect customers from potentially fraudulent use of the certificates, Microsoft has modified the Certificate Trust List (CTL) to remove trust for the four certificates. Furthermore, the respective issuing certificate authorities have revoked the certificates…
Recommendation: Please see the Suggested Actions section of this advisory for instructions on applying an update for specific releases of Microsoft Windows…
Suggested Actions: Apply the update for supported releases of Microsoft Windows.
An automatic updater of revoked certificates is included in supported editions of Windows 8, Windows Server 2012, Windows RT, Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, and Windows 10 and for devices running Windows Phone 8 and Windows Phone 8.1. For these operating systems or devices, customers do not need to take any action, because the CTL will be updated automatically. For systems running Windows Vista, Windows 7, Windows Server 2008, or Windows Server 2008 R2 that are using the automatic updater of revoked certificates (see Microsoft Knowledge Base Article 2677070* for details), customers do not need to take any action, because these systems will be automatically protected…"
* https://support.microsoft.com/en-us/kb/2677070
Last Review: 02/17/2014 Rev: 6.0
Update that adds telemetry points to consent.exe in Win8.1 and Win7
- https://support.microsoft.com/en-us/kb/3075249
3075249 - Last Review: 08/18/2015 - Rev: 1.0
See "Applies to: …"
___