Last Updated on Wednesday, 13 April 2011 16:02
[ Summary ]
Microsoft has released seventeen security bulletins addressing vulnerabilities in .Net Framework, Microsoft Windows, Internet Explorer, Office and Microsoft Developer Tools and Software.
These vulnerabilities allow information disclosure and remote code execution.
[ Affected Systems ]
These vulnerabilities affect:
1) Windows operating systems and components - Windows XP, Server 2003, Vista, Server 2008 and Windows 7
2) Microsoft Office Suites and Software - Office XP, Office 2003-2010 and Office Compatibility Pack
3) Microsoft Developer Tools and Software - Visual Studio 2005-2010 and Visual C++ 2005-2010
[ Impact Analysis ]
|
# |
Affected |
Contra Indications |
Known Exploits |
Microsoft rating |
ISC rating(*) |
|
|
clients |
servers |
|||||
|
Cumulative Security Update for Internet Explorer ( Replaces MS11-003 ) |
||||||
|
Internet Explorer 6-8 |
ACTIVELY EXPLOITED. |
Severity:Critical |
PATCH NOW! |
Critical |
||
|
Vulnerabilities in SMB Client Could Allow Remote Code Execution ( Replaces MS10-020 ) |
||||||
|
Windows |
POC Available. |
Severity:Critical |
Critical |
Critical |
||
|
Vulnerability in SMB Server Could Allow Remote Code Execution ( Replaces MS10-012 MS10-054 ) |
||||||
|
Windows |
No Known Exploits. |
Severity:Critical |
Critical |
Critical |
||
|
Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution ( Replaces MS10-080 MS10-087 ) |
||||||
|
Office XP SP3-2010, Office 2004-2011 for Mac, Open XML File Format Converter, Excel Viewer SP2, Office Compatibility Pack for 2007 file formats |
No Known Exploits. |
Severity:Important |
Important |
Important |
||
|
Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution ( Replaces MS09-017 MS10-036 MS10-087 MS10-088 ) |
||||||
|
PowerPoint |
No Known Exploits. |
Severity:Important |
Important |
Important |
||
|
Vulnerabilities in Microsoft Office Could Allow Remote Code Execution ( Replaces MS10-087 ) |
||||||
|
Office XP - 2007, Office 2004 - 2008 for Mac, Open XML File Format Converter |
POC Available. |
Severity:Important |
Important |
Important |
||
|
Vulnerability in Windows Fax Cover Page Editor Could Allow Remote Code Execution |
||||||
|
Fax Services, Fax Server Role |
POC Available. |
Severity:Important |
Critical |
Important |
||
|
Vulnerability in Microsoft Foundation Class (MFC) Library Could Allow Remote Code Execution |
||||||
|
Visual Studio .NET 2003 - 2010, Visual C++ 2005 - 2010 Redistributable Package |
No Known Exploits. |
Severity:Important |
Important |
Important |
||
|
Vulnerability in MHTML Could Allow Information Disclosure |
||||||
|
MHTML |
ACTIVELY EXPLOITED. |
Severity:Important |
PATCH NOW! |
Important |
||
|
Cumulative Security Update of ActiveX Kill Bits ( Replaces MS10-034 ) |
||||||
|
Windows XP- 7, Server 2003-2008 |
POC Available. |
Severity:Critical |
Critical |
Critical |
||
|
Vulnerability in .NET Framework Could Allow Remote Code Execution ( Replaces MS09-061 MS10-060 MS10-077 ) |
||||||
|
.NET framework (all supported version) |
No Known Exploits. |
Severity:Critical |
Critical |
Critical |
||
|
Vulnerability in GDI+ Could Allow Remote Code Execution ( Replaces MS09-062 MS10-087 ) |
||||||
|
Windows XP-Vista, Windows Server 2003-2008, Office XP |
No Known Exploits. |
Severity:Critical |
Critical |
Critical |
||
|
Vulnerability in DNS Resolution Could Allow Remote Code Execution ( Replaces MS08-020 MS08-037 MS08-066 ) |
||||||
|
Windows XP - 7, Windows Server 2008 |
No Known Exploits. |
Severity:Critical |
Critical |
Critical |
||
|
Vulnerability in JScript and VBScript Scripting Engines Could Allow Remote Code Execution ( Replaces MS09-045 MS10-022 MS11-009 ) |
||||||
|
OpenType Compact Font Format (CFF) driver |
No Known Exploits. |
Severity:Critical |
Critical |
Important |
||
|
Vulnerability in the OpenType Compact Font Format (CFF) Driver Could Allow Remote Code Execution ( Replaces MS11-007 ) |
||||||
|
OpenType Compact Font Format (CFF) driver |
No Known Exploits. |
Severity:Critical |
Critical |
Important |
||
|
Vulnerability in WordPad Text Converters Could Allow Remote Code Execution ( Replaces MS10-067 ) |
||||||
|
Microsoft Wordpad |
No Known Exploits. |
Severity:Important |
Important |
Important |
||
|
Elevation of Privilege Vulnerabilities in Windows Kernel-Mode Drivers (Replaces MS10-012 ) |
||||||
|
Kernel Mode Drivers |
No Known Exploits. |
Severity:Important |
Important |
Important |
||
[ Solution/Workaround ]
Updates are available. Agencies are advised to install all applicable updates as soon as possible.
[ Reference]
| < Prev | Next > |
|---|