Sales
0161 215 3814
0800 953 0642
Support
0800 230 0032
0161 215 3711

Microsoft Security Bulletin – February 2013

This month there are seven security bulletins in the Microsoft Security Bulletin release:

  • 5 bulletins is rated as Critical
  • 7 bulletins are rated as Important
  • 6 bulletins addressing vulnerabilities that could lead to Remote Code Execution
Bulletin ID Maximum Severity Rating and Vulnerability Impact Restart Requirement Affected Software
MS13-009 Critical
Remote Code Execution
Requires restart Microsoft Windows,Internet Explorer
Cumulative Security Update for Internet Explorer (2792100)
This security update resolves thirteen privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
MS13-010 Critical
Remote Code Execution
May require restart Microsoft Windows,
Internet Explorer
Vulnerability in Vector Markup Language Could Allow Remote Code Execution (2797052)
This security update resolves a privately reported vulnerability in the Microsoft implementation of Vector Markup Language (VML). The vulnerability could allow remote code execution if a user viewed a specially crafted webpage using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
MS13-011 Critical
Remote Code Execution
May require restart Microsoft Windows
Vulnerability in Media Decompression Could Allow Remote Code Execution (2780091)
This security update resolves one publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted media file (such as an .mpg file), opens a Microsoft Office document (such as a .ppt file) that contains a specially crafted embedded media file, or receives specially crafted streaming content. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
MS13-012 Critical
Remote Code Execution
May require restart Microsoft Server Software
Vulnerabilities in Microsoft Exchange Server Could Allow Remote Code Execution (2809279)
This security update resolves publicly disclosed vulnerabilities in Microsoft Exchange Server. The most severe vulnerability is in Microsoft Exchange Server WebReady Document Viewing, and could allow remote code execution in the security context of the transcoding service on the Exchange server if a user previews a specially crafted file using Outlook Web App (OWA). The transcoding service in Exchange that is used for WebReady Document Viewing is running in the LocalService account. The LocalService account has minimum privileges on the local computer and presents anonymous credentials on the network.
MS13-020 Critical
Remote Code Execution
Requires restart Microsoft Windows
Vulnerability in Windows Kernel-Mode Driver Could Allow Elevation of Privilege (2778930)
This security update resolves one privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker runs a specially crafted application.
MS13-013 Important
Remote Code Execution
May requires restart Microsoft Office, Microsoft Server Software
Vulnerabilities in FAST Search Server 2010 for SharePoint Parsing Could Allow Remote Code Execution (2784242)
This security update resolves publicly disclosed vulnerabilities in Microsoft FAST Search Server 2010 for SharePoint. The vulnerabilities could allow remote code execution in the security context of a user account with a restricted token. FAST Search Server for SharePoint is only affected by this issue when Advanced Filter Pack is enabled. By default, Advanced Filter Pack is disabled.
MS13-014 Important
Denial of Service
Requires restart Microsoft Windows,
Vulnerability in NFS Server Could Allow Denial of Service (2790978)
This security update resolves a privately reported vulnerability in the This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if an attacker attempts a file operation on a read only share. An attacker who exploited this vulnerability could cause the affected system to stop responding and restart. The vulnerability only affects Windows servers with the NFS role enabled.
MS13-015 Important
Elevation of Privilege
May require restart Microsoft Windows,
Microsoft .NET Framework
Vulnerability in .NET Framework Could Allow Elevation of Privilege (2800277)
This security update resolves one privately reported vulnerability in the .NET Framework. The vulnerability could allow elevation of privilege if a user views a specially crafted webpage using a web browser that can run XAML Browser Applications (XBAPs). The vulnerability could also be used by Windows .NET applications to bypass Code Access Security (CAS) restrictions. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
MS13-016 Important
Elevation of Privilege
Requires restart Microsoft Windows,
Vulnerabilities in Windows Kernel-Mode Driver Could Allow Elevation of Privilege (2778344)
This security update resolves 30 privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logs on to the system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerabilities.
MS13-017 Important
Elevation of Privilege
Requires restart Microsoft Windows
Vulnerabilities in Windows Kernel-Mode Driver Could Allow Elevation of Privilege (2778344)
This security update resolves 30 privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logs on to the system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerabilities.
MS13-018 Important
Denial of Service
Requires restart Microsoft Windows
Vulnerability in TCP/IP Could Allow Denial of Service (2790655)
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if an unauthenticated attacker sends a specially crafted connection termination packet to the server.
MS13-019 Important
Elevation of Privilege
Requires restart Microsoft Windows
Vulnerability in Windows Client/Server Run-time Subsystem (CSRSS) Could Allow Elevation of Privilege (2790113)
This security update resolves a publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to a system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.

In summary, we are likely to see updates requiring reboots of servers this month. As usual, as a UKFast customer, you will benefit from these updates being applied automatically unless you have opted out of this service.

Share with:

Enjoy this article?