Last updated at Thu, 31 Aug 2017 14:17:49 GMT
November sees a mix of remote code execution and elevation of privilege vulnerabilities enabling an attacker to gain the same rights as the user when the victim opens specially crafted content, such as a webpage, journal file or document containing embedded fonts. These vulnerabilities affect Internet Explorer (7 and onwards), Edge, and Windows (Vista and onwards). It is advisable for users and administrators to patch the affected platforms.
Microsoft includes 12 security bulletins, a third of them rated as critical, resolving a total of 49 vulnerabilities. All of the critical bulletins (MS15-112, MS15-113, MS15-114, MS15-115) are remote code execution issues affecting affecting a variety of products and platforms including Edge, Internet Explorer, Lync, Office, Office for Mac, Office Web Apps, Skype for Business, SharePoint Server and all supported releases of Microsoft Windows.
MS15-112 is the bulletin to watch out for this month, it addresses 25 vulnerabilities. It is rated Critical for Internet Explorer 7 - 11 on Windows clients and moderate on Windows servers. Microsoft's update addresses the vulnerabilities by resolving underlaying issues with how objects are handled in memory for JScript and VBScript, properly re-implemeting the ASLR security feature and adding additional permissions to Internet Explorer.
Users should be wary of untrusted sources as maliciously crafted content could allow an attacker to remotely execute code and gain the same rights as the user. Your best protection against these threats is to patch as quickly as possible.
Resolved Vulnerability Reference:
- CVE-2015-2427 (MS15-112)
- CVE-2015-2478 (MS15-119)
- CVE-2015-2503 (MS15-116)
- CVE-2015-6038 (MS15-116)
- CVE-2015-6061 (MS15-123)
- CVE-2015-6064 (MS15-112, MS15-113)
- CVE-2015-6065 (MS15-112)
- CVE-2015-6066 (MS15-112)
- CVE-2015-6068 (MS15-112)
- CVE-2015-6069 (MS15-112)
- CVE-2015-6070 (MS15-112)
- CVE-2015-6071 (MS15-112)
- CVE-2015-6072 (MS15-112)
- CVE-2015-6073 (MS15-112, MS15-113)
- CVE-2015-6074 (MS15-112)
- CVE-2015-6075 (MS15-112)
- CVE-2015-6076 (MS15-112)
- CVE-2015-6077 (MS15-112)
- CVE-2015-6078 (MS15-112, MS15-113)
- CVE-2015-6079 (MS15-112)
- CVE-2015-6080 (MS15-112)
- CVE-2015-6081 (MS15-112)
- CVE-2015-6082 (MS15-112)
- CVE-2015-6084 (MS15-112)
- CVE-2015-6085 (MS15-112)
- CVE-2015-6086 (MS15-112)
- CVE-2015-6087 (MS15-112)
- CVE-2015-6088 (MS15-112, MS15-113)
- CVE-2015-6089 (MS15-112)
- CVE-2015-6091 (MS15-116)
- CVE-2015-6092 (MS15-116)
- CVE-2015-6093 (MS15-116)
- CVE-2015-6094 (MS15-116)
- CVE-2015-6095 (MS15-122)
- CVE-2015-6096 (MS15-118)
- CVE-2015-6097 (MS15-114)
- CVE-2015-6098 (MS15-117)
- CVE-2015-6099 (MS15-118)
- CVE-2015-6100 (MS15-114)
- CVE-2015-6101 (MS15-114)
- CVE-2015-6102 (MS15-114)
- CVE-2015-6103 (MS15-114)
- CVE-2015-6104 (MS15-114)
- CVE-2015-6109 (MS15-114)
- CVE-2015-6111 (MS15-120)
- CVE-2015-6112 (MS15-121)
- CVE-2015-6113 (MS15-114, MS15-115)
- CVE-2015-6115 (MS15-118)
- CVE-2015-6123 (MS15-116)