I sent it to all my customers. And before you skim it without reading it… no, it’s NOT old. And update to this was issued recently, hence the advisory.
——————-
Today, Microsoft released MS12-063 to protect customers against the issue described in Security Advisory 2757760. The security update resolves one publicly disclosed and four privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer.
Microsoft encourages customers to test and deploy the update as soon as possible.
What is the purpose of this alert?
This alert is to provide you with an overview of the new security bulletin being released (out of band) on September 21, 2012, for new vulnerabilities in Internet Explorer.
Microsoft is also releasing one new security advisory today for Adobe Flash Player in Internet Explorer 10 on Windows 8 and Windows Server 2012.
New Security Bulletin
Microsoft is releasing one new security bulletin (out-of-band) for newly discovered vulnerabilities:
|
Bulletin Identifier |
Microsoft Security Bulletin MS12-063 |
|
Bulletin Title |
Cumulative Security Update for Internet Explorer (2744842) |
|
Executive Summary |
This security update resolves one publicly disclosed and four privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the current user. The security update addresses the vulnerabilities by modifying the way that Internet Explorer handles objects in memory. This security update also addresses the vulnerability first described in Microsoft Security Advisory 2757760. |
|
Severity Ratings and Affected Software |
|
|
Attack Vectors |
|
|
Mitigating Factors |
|
|
Restart Requirement |
This update requires a restart. |
|
Bulletins Replaced by This Update |
MS12-052 |
|
Full Details |
New Security Advisory
Microsoft published one new security advisory on September 21, 2012. Here is an overview of this new security advisory:
|
Security Advisory 2755801 |
Update for Vulnerabilities in Adobe Flash Player in Internet Explorer 10 |
|
Affected Software |
Internet Explorer 10 on Windows 8 and Windows Server 2012 |
|
Executive Summary |
Microsoft is announcing the availability of an update for Adobe Flash Player in Internet Explorer 10 on all supported editions of Windows 8 and Windows Server 2012. The update addresses the vulnerabilities in Adobe Flash Player by updating the affected Adobe Flash libraries contained within Internet Explorer 10. |
|
Mitigations |
|
|
More Information |
http://technet.microsoft.com/en-us/security/advisory/2755801 |
Public Bulletin Webcast
Microsoft will host a webcast to address customer questions on the new security bulletin:
- Title: Information About Microsoft’s September 2012 Out-of-Band Security Bulletin Release
- Date: Friday, September 21, 2012, 12:00 P.M. Pacific Time (U.S. and Canada)
- URL: https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032529852
Resources related to this alert
- Security Bulletin MS12-063 – Cumulative Security Update for Internet Explorer (2744842): http://technet.microsoft.com/security/bulletin/MS12-063
- Security Advisory 2757760 – Vulnerability in Internet Explorer Could Allow Remote Code Execution: http://technet.microsoft.com/en-us/security/advisory/2757760
- Security Advisory 2755801 – Update for Vulnerabilities in Adobe Flash Player in Internet Explorer 10: http://technet.microsoft.com/en-us/security/advisory/2755801
- Microsoft Security Response Center (MSRC) Blog: http://blogs.technet.com/msrc/
- Microsoft Security Research & Defense (SRD) Blog: http://blogs.technet.com/srd/
- Security Notification Service: http://technet.microsoft.com/en-us/security/dd252948.aspx: email regarding these security bulletins has been sent to IT professionals who have subscribed to receive this notification (both Basic and Comprehensive).
Regarding Information Consistency
We strive to provide you with accurate information in static (this mail) and dynamic (web-based) content. Microsoft’s security content posted to the web is occasionally updated to reflect late-breaking information. If this results in an inconsistency between the information here and the information in Microsoft’s web-based security content, the information in Microsoft’s web-based security content is authoritative.
