Microsoft Security Bulletin MS16-023 - Critical
Cumulative Security Update for Internet Explorer (3142015)
- https://technet.microsoft.com/library/security/MS16-023
Critical - Remote Code Execution - Requires restart - Microsoft Windows, Internet Explorer
Microsoft Security Bulletin MS16-024 - Critical
Cumulative Security Update for Microsoft Edge (3142019)
- https://technet.microsoft.com/library/security/MS16-024
Critical - Remote Code Execution - Requires restart - Microsoft Windows, Microsoft Edge
Microsoft Security Bulletin MS16-025 - Important
Security Update for Windows Library Loading to Address Remote Code Execution (3140709)
- https://technet.microsoft.com/library/security/MS16-025
Important - Remote Code Execution - Requires restart - Microsoft Windows
Microsoft Security Bulletin MS16-026 - Critical
Security Update for Graphic Fonts to Address Remote Code Execution (3143148)
- https://technet.microsoft.com/en-us/library/security/MS16-026
Critical - Remote Code Execution - Requires restart - Microsoft Windows
Microsoft Security Bulletin MS16-027 - Critical
Security Update for Windows Media to Address Remote Code Execution (3143146)
- https://technet.microsoft.com/en-us/library/security/MS16-027
Critical - Remote Code Execution - May require restart - Microsoft Windows
Microsoft Security Bulletin MS16-028 - Critical
Security Update for Microsoft Windows PDF Library to Address Remote Code Execution (3143081)
- https://technet.microsoft.com/en-us/library/security/MS16-028
Critical - Remote Code Execution - May require restart - Microsoft Windows
Microsoft Security Bulletin MS16-029 - Important
Security Update for Microsoft Office to Address Remote Code Execution (3141806)
- https://technet.microsoft.com/library/security/MS16-029
Important - Remote Code Execution - May require restart - Microsoft Office, Microsoft Office Services and Web Apps, Microsoft Server Software
Microsoft Security Bulletin MS16-030 - Important
Security Update for Windows OLE to Address Remote Code Execution (3143136)
- https://technet.microsoft.com/en-us/library/security/MS16-030
Important - Remote Code Execution - Requires restart - Microsoft Windows
Microsoft Security Bulletin MS16-031 - Important
Security Update for Microsoft Windows to Address Elevation of Privilege (3140410)
- https://technet.microsoft.com/en-us/library/security/MS16-031
Important - Elevation of Privilege - Requires restart - Microsoft Windows
Microsoft Security Bulletin MS16-032 - Important
Security Update for Secondary Logon to Address Elevation of Privilege (3143141)
- https://technet.microsoft.com/en-us/library/security/MS16-032
Important - Elevation of Privilege - Requires restart - Microsoft Windows
Microsoft Security Bulletin MS16-033 - Important
Security Update for Windows USB Mass Storage Class Driver to Address Elevation of Privilege (3143142)
- https://technet.microsoft.com/en-us/library/security/MS16-033
Important - Elevation of Privilege - May require restart - Microsoft Windows
Microsoft Security Bulletin MS16-034 - Important
Security Update for Windows Kernel-Mode Drivers to Address Elevation of Privilege (3143145)
- https://technet.microsoft.com/en-us/library/security/MS16-034
Important - Elevation of Privilege - Requires restart - Microsoft Windows
Microsoft Security Bulletin MS16-035 - Important
Security Update for .NET Framework to Address Security Feature Bypass (3141780)
- https://technet.microsoft.com/library/security/MS16-035
Important - Elevation of Privilege - May require restart - Microsoft Windows, Microsoft .NET Framework
___
* https://support.microsoft.com/en-us/kb/3085515
Last Review: 03/09/2016 22:49:00 - Rev: 2.0
"Notice: This update is no longer available from Microsoft Update or the Microsoft Download Center. After you install this update, you may not be able to open Microsoft Visual Basic-enabled apps in Microsoft Access 2010. Also, Access wizards may not run. To work around this problem, -uninstall- this update by following the steps in the "How to uninstall this update"[1] section."
1] https://support.microsoft.com/en-us/kb/3085515#bookmark-uninstall
When a security update is not a security update … Microsoft buried a 'Get Windows 10 ad generator' inside this month's Internet Explorer security patch for Windows 7 and 8.1
- http://www.infoworld.com/article/3042155/microsoft-windows/windows-patch-kb-3139929-when-a-security-update-is-not-a-security-update.html
Mar 9, 2016 - "If Microsoft's documentation is correct, installing Patch Tuesday's KB 3139929* security update for Internet Explorer also installs a new Windows 10 ad-generating routine called KB 3146449**… putting an 'ad generator' inside a security patch crosses way over the line. In fact, you have to ask yourself if there are any lines any more… It's important to note that KB 3146449 is not installed separately. You can't remove it. If you look in your installed updates list, KB 3146449 doesn't appear. Instead, it's baked into the IE security patch KB 3139929. The only way to get rid of the new advertising inside Internet Explorer 11 is to remove the security patch entirely… Rubbing salt in the wound: PCs attached to -corporate- domains are spared the pain - but not the bits - of this decidedly nonsecurity patch. In bypassing domain-joined PCs, Microsoft has avoided the inevitable screams of "foul play" from its largest corporate customers."
Microsoft Security Bulletin MS16-036 - Critical
Security Update for Adobe Flash Player (3144756)
- https://technet.microsoft.com/en-us/library/security/MS16-036
March 10, 2016 - "This security update resolves vulnerabilities in Adobe Flash Player when installed on all supported editions of Windows 8.1, Windows Server 2012, Windows Server 2012 R2, Windows RT 8.1, and Windows 10. This security update is rated Critical. The update addresses the vulnerabilities in Adobe Flash Player by updating the affected Adobe Flash libraries contained within Internet Explorer 10, Internet Explorer 11, and Microsoft Edge…"
- https://technet.microsoft.com/en-us/library/security/ms16-mar
V2.0 (March 10, 2016): Bulletin Summary revised to document the out-of-band release of MS16-036.
V2.1 (March 10, 2016): Added a Known Issues reference to the Executive Summaries table for MS16-035. For more information, see Microsoft Knowledge Base Article 3148821*.
After you apply security update 3141780, .NET Framework applications encounter exception errors or unexpected failures while processing files that contain SignedXml
* https://support.microsoft.com/en-us/kb/3148821
Last Review: 03/16/2016 20:51:00 - Rev: 5.0
Applies to:
Microsoft .NET Framework 4.6.1
Microsoft .NET Framework 4.6
Microsoft .NET Framework 4.5.2
Microsoft .NET Framework 3.5.1
Microsoft .NET Framework 3.5
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 2.0 Service Pack 2
MS16-023: Security update for Internet Explorer
- https://support.microsoft.com/en-us/kb/3139929
"… Additionally, this security update includes several nonsecurity-related fixes for Internet Explorer…"
Last Review: 03/17/2016 08:33:00 - Rev: 3.0
Applies to:
Internet Explorer 11
Internet Explorer 10
Windows Internet Explorer 9
Windows Internet Explorer 8
Updated Internet Explorer 11 capabilities to upgrade Windows 8.1 and Windows 7
> https://support.microsoft.com/en-us/kb/3146449
"This update adds functionality to Internet Explorer 11 on some computers that lets users learn about Windows 10 or start an upgrade to Windows 10…"
Last Review: 03/08/2016 17:37:00 - Rev: 1.0
Empty "textarea" loses its closing tag after conversion from XML to HTML in Internet Explorer 11
> https://support.microsoft.com/en-us/kb/3144523
"… Note This update was first included in the MS16-023: Security update for Internet Explorer: March 8, 2016."
Last Review: 03/08/2016 17:35:00 - Rev: 1.0
(MS Office) Upcoming change to the release schedule for non-security updates
> https://blogs.technet.microsoft.com/office_sustained_engineering/2016/03/28/upcoming-change-to-the-release-schedule-for-non-security-updates/
March 28, 2016 - "We want to let you know about an important change coming to the release schedule for Office updates so that you can plan accordingly. Until now, both security and non-security updates have been released on the second Tuesday of each month.
Starting in April, the non-security updates will be released in Microsoft Update and the Windows Server Update Service (WSUS) on the -first- Tuesday of the month, which is April 5 in this case. This will include all updates that have the Critical or Definition classification. Updates with the Security classification will continue to release on second Tuesday as usual. This change applies only to the MSI version of Office. Office Click-To-Run (C2R) will release on second Tuesday."
Tags: Office Office 2003, Office 2007, Office 2010, Office 2013, Office 2016, Office Public Update, Public Update Security
___
- http://www.infoworld.com/article/3053608/microsoft-windows/windows-781-patches-kb-2952664-2976978-and-2977759-keep-turning-up-like-bad-pennies.html
Apr 8, 2016 - "… They appear in Windows Update as optional and unchecked.
KB 2952664 is a "compatibility update" that eases upgrading from Win7 SP1 to Win10. It now sits at version 20, up from 19 last week.
KB 2976978 does the same thing, but for Windows 8 and 8.1. It's at version 24, up from 22. There's no indication why Microsoft gave it an additional version number bump.
KB 2977759 covers the same bases, but for Windows 7 without SP1. It, too, has been given an extra bump, from version 18 last week to version 20 this week…"
MS16-027 - Critical
Security Update for Windows Media to Address Remote Code Execution
- https://technet.microsoft.com/en-us/library/security/MS16-027
V1.2 (April 7, 2016): Added a note to clarify that Windows Media is only enabled on Windows server operating systems when the Desktop Experience feature is enabled. This is an informational change only.
MS15-115 - Critical
Security Update for Microsoft Windows to Address Remote Code Execution
- https://technet.microsoft.com/en-us/library/security/MS15-115
V2.1 (April 7, 2016): Updated the footnotes following the Affected Software table to further clarify installation order for security update 3101746 in MS15-115, 3081320 in MS15-121, and 3101246 in MS15-122. This is an informational change only. Customers who have already successfully installed the update do not need to take any action.
MS15-121 - Important
Security Update for Schannel to Address Spoofing
- https://technet.microsoft.com/en-us/library/security/MS15-121
V1.1 (April 7, 2016): Updated the footnotes following the Affected Software table to further clarify installation order for security update 3101746 in MS15-115, 3081320 in MS15-121, and 3101246 in MS15-122. This is an informational change only. Customers who have already successfully installed the update do not need to take any action.
MS15-122 - Important
Security Update for Kerberos to Address Security Feature Bypass
- https://technet.microsoft.com/en-us/library/security/MS15-122
V1.2 (April 7, 2016): Updated the footnotes following the Affected Software and Vulnerability Severity Ratings table to further clarify installation order for security update 3101746 in MS15-115, 3081320 in MS15-121, and 3101246 in MS15-122. This is an informational change only. Customers who have already successfully installed the update do not need to take any action.
MS13-082 - Critical
Vulnerabilities in .NET Framework Could Allow Remote Code Execution
- https://technet.microsoft.com/en-us/library/security/MS13-082
V1.2 (April 7, 2016): Corrected download links for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows 2008 R2. This is an informational change only. Customers who have already successfully updated their systems do not need to take any action.