Last updated at Thu, 31 Aug 2017 14:12:59 GMT
December continues this quarter's trend, 10 bulletins addressing remote code execution (RCE) vulnerabilities, while the remaining two address elevation of privilege. The vulnerabilities affect Internet Explorer (7 and onwards), Edge, Office, Silverlight, VBScript scripting engine and Windows (Vista and onwards). It is advisable for users and administrators to patch the affected platforms.
Microsoft released 12 security bulletins this month, two thirds of them rates as critical, resolving a total of 58 vulnerabilities. All of the critical bulletins (MS15-124, MS15-125, MS15-126, MS15-127, MS15-128, MS15-129, MS15-130, MS15-131) are remote code execution issues affecting a variety of products and platforms including Edge, Internet Explorer, Live Meeting, Lync, Office, Office for Mac, Office Web Apps, Silverlight, Skype, VBScript and all supported releases of Microsoft Windows.
Specifically, MS15-124, MS15-125 and MS15-128 are the bulletins to watch out for this month, addressing 33 vulnerabilities. Since a wide range of products are affected this month almost all Microsoft users should be on alert. Microsoft's update addresses the vulnerabilities by resolving underlaying issues with how certain functions in VBScript handle objects in memory, preventing cross site scripting (XSS) from incorrectly disabled HTML attributes, proper enforcement of content types and cross–domain policies.
From the bulletins released in December, the following vulnerabilities are know to have been exploited:
- MS15-131 (CVE-2015-6124) - Microsoft Office Memory Corruption Vulnerability
- MS15-135 (CVE-2015-6175) - Windows Kernel Memory Elevation of Privilege Vulnerability
Users should be wary of untrusted sources as maliciously crafted content could allow an attacker to remotely execute code and gain the same rights as the user. Your best protection against these threats is to patch as quickly as possible.
Resolved Vulnerability Reference:
- CVE-2015-6040 (MS15-131)
- CVE-2015-6083 (MS15-124)
- CVE-2015-6106 (MS15-128)
- CVE-2015-6107 (MS15-128)
- CVE-2015-6108 (MS15-128)
- CVE-2015-6114 (MS15-129)
- CVE-2015-6118 (MS15-131)
- CVE-2015-6122 (MS15-131)
- CVE-2015-6124 (MS15-131)
- CVE-2015-6125 (MS15-127)
- CVE-2015-6126 (MS15-133)
- CVE-2015-6127 (MS15-134)
- CVE-2015-6128 (MS15-132)
- CVE-2015-6130 (MS15-130)
- CVE-2015-6131 (MS15-134)
- CVE-2015-6132 (MS15-132)
- CVE-2015-6133 (MS15-132)
- CVE-2015-6134 (MS15-124)
- CVE-2015-6135 (MS15-124, MS15-126)
- CVE-2015-6136 (MS15-124, MS15-126)
- CVE-2015-6138 (MS15-124)
- CVE-2015-6139 (MS15-124, MS15-125)
- CVE-2015-6140 (MS15-124, MS15-125)
- CVE-2015-6141 (MS15-124)
- CVE-2015-6142 (MS15-124, MS15-125)
- CVE-2015-6143 (MS15-124)
- CVE-2015-6144 (MS15-124)
- CVE-2015-6145 (MS15-124)
- CVE-2015-6146 (MS15-124)
- CVE-2015-6147 (MS15-124)
- CVE-2015-6148 (MS15-124, MS15-125)
- CVE-2015-6149 (MS15-124)
- CVE-2015-6150 (MS15-124)
- CVE-2015-6151 (MS15-124, MS15-125)
- CVE-2015-6152 (MS15-124)
- CVE-2015-6153 (MS15-124, MS15-125)
- CVE-2015-6154 (MS15-124, MS15-125)
- CVE-2015-6155 (MS15-124, MS15-125)
- CVE-2015-6156 (MS15-124)
- CVE-2015-6157 (MS15-124)
- CVE-2015-6158 (MS15-124, MS15-125)
- CVE-2015-6159 (MS15-124, MS15-125)
- CVE-2015-6160 (MS15-124)
- CVE-2015-6161 (MS15-124, MS15-125)
- CVE-2015-6162 (MS15-124)
- CVE-2015-6164 (MS15-124)
- CVE-2015-6165 (MS15-129)
- CVE-2015-6166 (MS15-129)
- CVE-2015-6168 (MS15-125)
- CVE-2015-6169 (MS15-125)
- CVE-2015-6170 (MS15-125)
- CVE-2015-6171 (MS15-135)
- CVE-2015-6172 (MS15-131)
- CVE-2015-6173 (MS15-135)
- CVE-2015-6174 (MS15-135)
- CVE-2015-6175 (MS15-135)
- CVE-2015-6176 (MS15-123)
- CVE-2015-6177 (MS15-131)