RETIRED: Microsoft October 2012 Advance Notification Multiple Vulnerabilities

BID:55794

Info

RETIRED: Microsoft October 2012 Advance Notification Multiple Vulnerabilities

Bugtraq ID: 55794
Class: Unknown
CVE:
Remote: Yes
Local: Yes
Published: Oct 04 2012 12:00AM
Updated: Mar 19 2015 09:10AM
Credit: Microsoft
Vulnerable: Microsoft Works 9.0
Microsoft Word Viewer 0
Microsoft Windows XP Service Pack 3 0
Microsoft Windows XP Professional x64 Edition SP2
Microsoft Windows XP Professional x64 Edition
Microsoft Windows Vista x64 Edition SP2
Microsoft Windows Vista x64 Edition SP1
Microsoft Windows Vista Service Pack 2 0
Microsoft Windows Server 2008 R2 x64 SP1
Microsoft Windows Server 2008 R2 x64 0
Microsoft Windows Server 2008 R2 Itanium SP1
Microsoft Windows Server 2008 R2 Itanium 0
Microsoft Windows Server 2008 for x64-based Systems SP2
Microsoft Windows Server 2008 for 32-bit Systems SP2
Microsoft Windows Server 2003 x64 SP2
Microsoft Windows Server 2003 x64 SP1
Microsoft Windows Server 2003 Enterprise Edition Itanium Sp2 Itanium
Microsoft Windows Server 2003 Enterprise Edition Itanium SP2
Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Beta 1
Microsoft Windows Server 2003 Enterprise Edition Itanium SP1
Microsoft Windows Server 2003 SP2
Microsoft Windows 7 for x64-based Systems SP1
Microsoft Windows 7 for x64-based Systems 0
Microsoft Windows 7 for 32-bit Systems SP1
Microsoft Windows 7 for 32-bit Systems 0
Microsoft SQL Server 2008 x64 SP3
Microsoft SQL Server 2008 x64 SP2
Microsoft SQL Server 2008 itanium SP3
Microsoft SQL Server 2008 itanium SP2
Microsoft SQL Server 2008 itanium SP1
Microsoft SQL Server 2008 32-bit SP3
Microsoft SQL Server 2008 32-bit SP2
Microsoft SQL Server 2005 x64 Edition SP4
Microsoft SQL Server 2005 x64 Edition SP3
Microsoft SQL Server 2005 x64 Edition SP2
Microsoft SQL Server 2005 x64 Edition SP1
Microsoft SQL Server 2005 Itanium Edition SP4
Microsoft SQL Server 2005 Itanium Edition SP3
Microsoft SQL Server 2005 Itanium Edition SP2
Microsoft SQL Server 2005 Itanium Edition SP1
Microsoft SQL Server 2005 Express Edition with Advanced Serv SP4
Microsoft SQL Server 2005 Express Edition with Advanced Serv SP3
Microsoft SQL Server 2005 Express Edition with Advanced Serv SP2
Microsoft SQL Server 2005 Express Edition with Advanced Serv SP1
Microsoft SQL Server 2000 Reporting Services SP2
Microsoft SharePoint Foundation 2010 SP1
Microsoft Office Web Apps 2010 SP1
Microsoft Office SharePoint Server 2010 SP1
Microsoft Office Compatibility Pack SP3
Microsoft Office Compatibility Pack SP2
Microsoft Office Communicator 2007 R2
Microsoft Office 2010 (64-bit edition) SP1
Microsoft Office 2010 (32-bit edition) SP1
Microsoft Office 2007 SP3
Microsoft Office 2007 SP2
Microsoft Office 2007 SP1
Microsoft Office 2003 SP3
Microsoft Office 2003 SP2
Microsoft Office 2003 SP1
Microsoft Lync 2010 Attendee 0
Microsoft InfoPath 2007 SP2
Microsoft Groove Server 2010 SP1
Not Vulnerable:

Discussion

RETIRED: Microsoft October 2012 Advance Notification Multiple Vulnerabilities

Microsoft has released advance notification that on October 9, 2012, they will be releasing seven security bulletins addressing twenty vulnerabilities.

The bulletins and their affected components are as follows:

One bulletin rated 'Critical' affecting Microsoft Word
Six bulletins rated 'Important' affecting Windows, Office, and SQL Server

This BID is being retired. The following individual records exist to better document the issues:

55781 Microsoft Word RTF File Use-After-Free Remote Code Execution Vulnerability
55780 Microsoft Word PAPX Section Corruption Remote Code Execution Vulnerability
55796 Microsoft Works CVE-2012-2550 RTF Data Handling Remote Memory Corruption Vulnerability
55778 Microsoft Windows Kerberos CVE-2012-2551 Denial of Service Vulnerability
55797 Microsoft SharePoint And Microsoft Lync HTML Sanitization Cross Site Scripting Vulnerability
55783 Microsoft SQL Server Report Manager CVE-2012-2552 Cross Site Scripting Vulnerability
55793 Microsoft Windows Kernel 'Win32k.sys' Integer Overflow Privilege Escalation Vulnerability
54531 Oracle Outside In Technology CVE-2012-1766 Remote Code Execution Vulnerability
54511 Oracle Outside In Technology CVE-2012-1767 Remote Code Execution Vulnerability
54536 Oracle Outside In Technology CVE-2012-1768 Remote Code Execution Vulnerability
54500 Oracle Outside In Technology CVE-2012-1769 Remote Code Execution Vulnerability
54541 Oracle Outside In Technology CVE-2012-1770 Remote Code Execution Vulnerability
54543 Oracle Outside In Technology CVE-2012-1771 Remote Code Execution Vulnerability
54497 Oracle Outside In Technology CVE-2012-1772 Remote Code Execution Vulnerability
54548 Oracle Outside In Technology CVE-2012-1773 Remote Code Execution Vulnerability
54546 Oracle Outside In Technology CVE-2012-3106 Remote Code Execution Vulnerability
54504 Oracle Outside In Technology CVE-2012-3107 Remote Code Execution Vulnerability
54550 Oracle Outside In Technology CVE-2012-3108 Remote Code Execution Vulnerability
54554 Oracle Outside In Technology CVE-2012-3109 Remote Code Execution Vulnerability
54506 Oracle Outside In Technology CVE-2012-3110 Remote Code Execution Vulnerability

Solution / Fix

RETIRED: Microsoft October 2012 Advance Notification Multiple Vulnerabilities

Solution:
Microsoft plans to release fixes to address these issues on October 9, 2012.

Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].

References

RETIRED: Microsoft October 2012 Advance Notification Multiple Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report