Microsoft Security Bulletin: April 2013 Release!

7103_securitybulletin_thumb_32407BF9

Welcome to another security bulletin update! This month we have 9 bulletins and I have posted the details below. Make sure you consider these in your environments and update where appropriate. And if you have a Surface RT device there is another update available to improve Wi-Fi reliability.

MS13-028 - Cumulative Security Update for Internet Explorer (2817183) This security update resolves two privately reported vulnerabilities in Internet Explorer. These vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Maximum Severity Rating - Critical
Vulnerability Impact - Remote Code Execution
Restart Requirement - Requires restart
Affected Software - Microsoft Windows, Internet Explorer

MS13-029 - Vulnerability in Remote Desktop Client Could Allow Remote Code Execution (2828223) This security update resolves a privately reported vulnerability in Windows Remote Desktop Client. The vulnerability could allow remote code execution if a user views a specially crafted webpage. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Maximum Severity Rating - Critical
Vulnerability Impact - Remote Code Execution
Restart Requirement - May require restart
Affected Software - Microsoft Windows

MS13-030 - Vulnerability in SharePoint Could Allow Information Disclosure (2827663) This security update resolves a publicly disclosed vulnerability in Microsoft SharePoint Server. The vulnerability could allow information disclosure if an attacker determined the address or location of a specific SharePoint list and gained access to the SharePoint site where the list is maintained. The attacker would need to be able to satisfy the SharePoint site's authentication requests to exploit this vulnerability.

Maximum Severity Rating - Important
Vulnerability Impact - Information Disclosure
Restart Requirement - May require restart
Affected Software - Microsoft Office, Microsoft Server Software

MS13-031 - Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2813170) This security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logs on to the system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities.

Maximum Severity Rating - Important
Vulnerability Impact - Elevation of Privilege
Restart Requirement - Requires restart
Affected Software - Microsoft Windows

MS13-032 - Vulnerability in Active Directory Could Lead to Denial of Service (2830914) This security update resolves a privately reported vulnerability in Active Directory. The vulnerability could allow denial of service if an attacker sends a specially crafted query to the Lightweight Directory Access Protocol (LDAP) service.

Maximum Severity Rating - Important
Vulnerability Impact - Denial of Service
Restart Requirement - Requires restart
Affected Software - Microsoft Windows

MS13-033 - Vulnerability in Windows Client/Server Run-time Subsystem (CSRSS) Could Allow Elevation of Privilege (2820917) This security update resolves a privately reported vulnerability in all supported editions of Windows XP, Windows Vista, Windows Server 2003, and Windows Server 2008. The vulnerability could allow elevation of privilege if an attacker logs on to a system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.

Maximum Severity Rating - Important
Vulnerability Impact - Elevation of Privilege
Restart Requirement - Requires restart
Affected Software - Microsoft Windows

MS13-034 - Vulnerability in Microsoft Antimalware Client Could Allow Elevation of Privilege (2823482) This security update resolves a privately reported vulnerability in the Microsoft Antimalware Client. The vulnerability could allow elevation of privilege due to the pathnames used by the Microsoft Antimalware Client. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected system. The attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker must have valid logon credentials to exploit this vulnerability. The vulnerability could not be exploited by anonymous users.

Maximum Severity Rating - Important
Vulnerability Impact - Elevation of Privilege
Restart Requirement - Requires restart
Affected Software - Microsoft Security Software

MS13-035 - Vulnerability in HTML Sanitization Component Could Allow Elevation of Privilege (2821818) This security update resolves a privately reported vulnerability in Microsoft Office. The vulnerability could allow elevation of privilege if an attacker sends specially crafted content to a user.

Maximum Severity Rating - Important
Vulnerability Impact - Elevation of Privilege
Restart Requirement - May require restart
Affected Software - Microsoft Office, Microsoft Server Software

MS13-036 - Vulnerabilities in Kernel-Mode Driver Could Allow Elevation Of Privilege (2829996)

This security update resolves three privately reported vulnerabilities and one publicly disclosed vulnerability in Microsoft Windows. The most severe of these vulnerabilities could allow elevation of privilege if an attacker logs on to the system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the most severe vulnerabilities.

Maximum Severity Rating - Important
Vulnerability Impact - Elevation of Privilege
Restart Requirement - Requires restart
Affected Software - Microsoft Windows

Go forth an update!

Jeffa

Technorati Tags: Update,Patching,Security

Digg This