Patch Tuesday Report 9th August

Executive Summary

With this August Microsoft Patch Tuesday update, we see a moderate set of updates in comparison to those lists of updates released by Microsoft for the months of June and July. In total there are 13 Microsoft Security Updates with the following rating; 2 rated as Critical, 9 rated as Important and 2 as Moderate by Microsoft. Given the scope of this month’s update, the ChangeBASE team expects to find a small number of issues raised by the AOK Automated Patch Impact Assessment. In particular, Microsoft Security Update M11-060 will require careful testing prior to deployment due to the core operating system DLL’s contained within this update.

 

Due to the nature of the changes and updates included in each of these patches, most systems will require a reboot to successfully implement any and all of the patches and updates released in this August Patch Tuesday release cycle.

 

Sample Results 1: MS11-060 Vulnerability in VISIO Could Allow Remote Code Execution

patch aug 1.png 

 

Testing Summary

 

MS11-057

Cumulative Security Update for Internet Explorer (2559049)

MS11-058

Vulnerabilities in DNS Server Could Allow Remote Code Execution (2562485)

MS11-059

Vulnerability in Data Access Components Could Allow Remote Code Execution (2560656)

MS11-060

Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (2560978)

MS11-061

Vulnerability in Remote Desktop Web Access Could Allow Elevation of Privilege (2546250)

MS11-062

Vulnerability in Remote Access Service NDISTAPI Driver Could Allow Elevation of Privilege (2566454)

MS11-063

Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2567680)

MS11-064

Vulnerabilities in TCP/IP Stack Could Allow Denial of Service (2563894)

MS11-065

Vulnerability in Remote Desktop Protocol Could Allow Denial of Service (2570222)

MS11-066

Vulnerability in Microsoft Chart Control Could Allow Information Disclosure (2567943)

MS11-067

Vulnerability in Microsoft Report Viewer Could Allow Information Disclosure (2578230)

MS11-068

Vulnerability in Windows Kernel Could Allow Denial of Service (2556532)

MS11-069

Vulnerability in .NET Framework Could Allow Information Disclosure (2567951)

patch aug 3.PNGPatch aug 4.PNG

Security Update Detailed Summary

MS11-057

Cumulative Security Update for Internet Explorer (2559049)

Description

This security update resolves five privately reported vulnerabilities and two publicly disclosed vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Payload

 

Impact

Critical – Remote Code Execution

 

MS11-058

Vulnerabilities in DNS Server Could Allow Remote Code Execution (2562485)

Description

This security update resolves two privately reported vulnerabilities in Windows DNS server. The more severe of these vulnerabilities could allow remote code execution if an attacker registers a domain, creates an NAPTR DNS resource record, and then sends a specially crafted NAPTR query to the target DNS server. Servers that do not have the DNS role enabled are not at risk.

Payload

Afd.sys, Dns.exe, Dnsperf.dll, Dnsperf.h, Dnsperf.ini, Mswsock.dll, Tcpip.sys, Tcpip6.sys, W03a3409.dll, Wdnsperf.dll, Wmswsock.dll, Ww03a3409.dll, Update.exe, Update.ver, Updspapi.dll

Impact

Critical – Remote Code Execution

 

MS11-059

Vulnerability in Data Access Components Could Allow Remote Code Execution (2560656)

Description

This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate Excel file (such as a .xlsx file) that is located in the same network directory as a specially crafted library file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Payload

 

Impact

Important – Remote Code Execution

 

 

MS11-060

Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (2560978)

Description

This security update resolves two privately reported vulnerabilities in Microsoft Visio. The vulnerabilities could allow remote code execution if a user opens a specially crafted Visio file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Payload

Aec.dll, Brtview.dll, Dbshare.dll, Dwgcnv.dll, Dwgdp.dll, Imcommon.dll, Imutil.dll, Ixacs.pdl, Ixdb2.pdl, Ixgenerc.pdl, Ixinfx.pdl, Ixoledb.pdl, Ixoracle.pdl, Ixssrv.pdl, Ixsybase.pdl, Modeleng.dll, Orgchart.dll, Orgchwiz.dll, Ormelems.dll, Ormmodel.mdl, Pdsbase.dll, Sg.dll, Sqlshare.dll, Uml.dll, Umlsys.dll, Visbrgr.dll, Visfilt.dll, Visio.exe, Vislib.dll, Visocx.dll

Impact

Important – Remote Code Execution

 

MS11-061

Vulnerability in Remote Desktop Web Access Could Allow Elevation of Privilege (2546250)

Description

This security update resolves a privately reported vulnerability in Remote Desktop Web Access. The vulnerability is a cross-site scripting (XSS) vulnerability that could allow elevation of privilege, enabling an attacker to execute arbitrary commands on the site in the context of the target user. The XSS Filter in Internet Explorer 8 and Internet Explorer 9 prevents this attack for its users when browsing to a Remote Desktop Web Access server in the Internet Zone. The XSS Filter in Internet Explorer 8 and Internet Explorer 9 is not enabled by default in the Intranet Zone.

Payload

Config.aspx, Default.aspx, Desktops.aspx, Login.aspx, Logoff.aspx, Rap-help-admin.htm, Rap-help.htm, Tsportalsetup.exe.mui, Tsportalwebpart.resources.dll, Tswa.css

Impact

Important – Elevation of Privilege

 

MS11-062

Vulnerability in Remote Access Service NDISTAPI Driver Could Allow Elevation of Privilege (2566454)

Description

This security update resolves a privately reported vulnerability in all supported editions of Windows XP and Windows Server 2003. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability.

Payload

Ndistapi.sys, Update.exe, Update.ver, Updspapi.dll

Impact

Important – Elevation of Privilege

 

 

MS11-063

Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2567680)

Description

This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application designed to send a device event message to a higher-integrity process. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.

Payload

Winsrv.dll, Update.exe, Update.ver, Updspapi.dll

Impact

Important – Elevation of Privilege

 

MS11-064

Vulnerabilities in TCP/IP Stack Could Allow Denial of Service (2563894)

Description

This security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow denial of service if an attacker sends a sequence of specially crafted Internet Control Message Protocol (ICMP) messages to a target system or sends a specially crafted URL request to a server that is serving Web content and has the URL-based Quality of Service (QoS) feature enabled.

Payload

Tcpipreg.sys, Tcpip.sys

Impact

Important – Denial of Service

 

MS11-065

Vulnerability in Remote Desktop Protocol Could Allow Denial of Service (2570222)

Description

This security update resolves a privately reported vulnerability in the Remote Desktop Protocol. The vulnerability could allow denial of service if an affected system received a sequence of specially crafted RDP packets. Microsoft has also received reports of limited, targeted attacks attempting to exploit this vulnerability. By default, the Remote Desktop Protocol (RDP) is not enabled on any Windows operating system.

Payload

Rdpwd.sys, Update.exe, Update.ver, Updspapi.dll

Impact

Important – Denial of Service

  

MS11-066

Vulnerability in Microsoft Chart Control Could Allow Information Disclosure (2567943)

Description

This security update resolves a privately reported vulnerability in ASP.NET Chart controls. The vulnerability could allow information disclosure if an attacker sent a specially crafted GET request to an affected server hosting the Chart controls. Note that this vulnerability would not allow an attacker to execute code or to elevate the attacker’s user rights directly, but it could be used to retrieve information that could be used to further compromise the affected system. Only web applications using Microsoft Chart Control are affected by this issue. Default installations of the .NET Framework are not affected.

Payload

 

Impact

Important – Information Disclosure

 

MS11-067

Vulnerability in Microsoft Report Viewer Could Allow Information Disclosure (2578230)

Description

This security update resolves a privately reported vulnerability in Microsoft Report Viewer. The vulnerability could allow information disclosure if a user views a specially crafted Web page. In all cases, however, an attacker would have no way to force a user to visit the Web site. Instead, an attacker would have to persuade a user to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes the user to the vulnerable Web site.

Payload

 

Impact

Important – Information Disclosure

 

MS11-068

Vulnerability in Windows Kernel Could Allow Denial of Service (2556532)

Description

This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if a user visits a network share (or visits a Web site that points to a network share) containing a specially crafted file. In all cases, however, an attacker would have no way to force a user to visit such a network share or Web site. Instead, an attacker would have to convince a user to do so, typically by getting the user to click a link in an e-mail message or Instant Messenger message.

Payload

 

Impact

Moderate – Denial of Service

 

MS11-069

Vulnerability in .NET Framework Could Allow Information Disclosure (2567951)

Description

This security update resolves a privately reported vulnerability in Microsoft .NET Framework. The vulnerability could allow information disclosure if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs). In a Web-based attack scenario, an attacker could host a Web site that contains a Web page that is used to exploit this vulnerability. In addition, compromised Web sites and Web sites that accept or host user-provided content or advertisements could contain specially crafted content that could exploit this vulnerability. In all cases, however, an attacker would have no way to force users to visit these Web sites. Instead, an attacker would have to convince users to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker’s Web site. This vulnerability could also be used by Windows .NET applications to bypass Code Access Security (CAS) restrictions.

Payload

 

Impact

Moderate – Information Disclosure

 

*All results are based on an AOK Application Compatibility Lab’s test portfolio of over 1,000 applications.

 

Start the conversation

Send me notifications when other members comment.

Please create a username to comment.

-ADS BY GOOGLE

SearchCIO

SearchSecurity

SearchNetworking

SearchDataCenter

SearchDataManagement

Close