RETIRED: Microsoft December 2012 Advance Notification Multiple Vulnerabilities
BID:56838
Info
RETIRED: Microsoft December 2012 Advance Notification Multiple Vulnerabilities
| Bugtraq ID: | 56838 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Dec 06 2012 12:00AM |
| Updated: | Dec 26 2012 07:00AM |
| Credit: | Microsoft |
| Vulnerable: |
Microsoft Word Viewer 0 Microsoft Word 2007 SP3 Microsoft Word 2007 SP2 Microsoft Word 2003 SP3 Microsoft Word 2003 SP2 Microsoft Word 2003 SP1 Microsoft Word 2003 Microsoft Windows XP Service Pack 3 0 Microsoft Windows XP Professional x64 Edition SP3 Microsoft Windows XP Professional x64 Edition SP2 Microsoft Windows Vista x64 Edition SP2 Microsoft Windows Vista Service Pack 2 0 Microsoft Windows Server 2008 R2 Itanium SP1 Microsoft Windows Server 2008 R2 Itanium 0 Microsoft Windows Server 2008 R2 for x64-based Systems SP1 Microsoft Windows Server 2008 R2 for x64-based Systems 0 Microsoft Windows Server 2008 for x64-based Systems SP2 Microsoft Windows Server 2008 for x64-based Systems R2 Microsoft Windows Server 2008 for x64-based Systems 0 Microsoft Windows Server 2008 for Itanium-based Systems SP2 Microsoft Windows Server 2008 for Itanium-based Systems 0 Microsoft Windows Server 2008 for 32-bit Systems SP2 Microsoft Windows Server 2008 for 32-bit Systems 0 Microsoft Windows Server 2003 x64 SP2 Microsoft Windows Server 2003 x64 SP1 Microsoft Windows Server 2003 Itanium SP2 Microsoft Windows Server 2003 Itanium SP1 Microsoft Windows Server 2003 Itanium 0 Microsoft Windows Server 2003 SP2 Microsoft Windows Server 2003 SP1 Microsoft Windows 7 for x64-based Systems SP1 Microsoft Windows 7 for x64-based Systems 0 Microsoft Windows 7 for 32-bit Systems SP1 Microsoft Windows 7 for 32-bit Systems 0 Microsoft SharePoint Server 2010 SP1 Microsoft Office Web Apps 2010 SP1 Microsoft Office Compatibility Pack SP3 Microsoft Office Compatibility Pack SP2 Microsoft Internet Explorer 9 Microsoft Exchange Server 2007 SP3 Microsoft Exchange Server 2007 SP2 Microsoft Exchange Server 2007 SP 1 |
| Not Vulnerable: | |
Discussion
RETIRED: Microsoft December 2012 Advance Notification Multiple Vulnerabilities
Microsoft has released advance notification that on December 11, 2012, they will be releasing seven security bulletins addressing eleven vulnerabilities.
The bulletins and their affected components are as follows:
Five bulletins rated 'Critical' affecting Windows, Word, Windows Server, and Internet Explorer
Two bulletins rated 'Important' affecting Windows
This BID is being retired. The following individual records exist to better document the issues:
56443 Microsoft Windows CVE-2012-4774 Remote Code Execution Vulnerability
56828 Microsoft Internet Explorer InjectHTMLStream Use-After-Free Remote Code Execution Vulnerability
56829 Microsoft Internet Explorer CMarkup Use-After-Free Remote Code Execution Vulnerability
56830 Microsoft Internet Explorer Improper Ref Counting Use-After-Free Remote Code Execution Vulnerability
56840 Microsoft Windows IP-HTTPS Server Revoked SSL Certificate Validation Security Bypass Vulnerability
56839 Microsoft DirectX DirectPlay CVE-2012-1537 Heap Overflow Remote Code Execution Vulnerability
56841 Microsoft Windows OpenType Font (OTF) Driver CVE-2012-2556 Remote Code Execution Vulnerability
56842 Microsoft Windows TrueType Font CVE-2012-4786 Remote Code Execution Vulnerability
55977 Oracle Outside In Technology CVE-2012-3214 Local Security Vulnerability
55993 Oracle Outside In Technology CVE-2012-3217 Local Security Vulnerability
56836 Microsoft Exchange Server RSS Feed Remote Denial of Service Vulnerability
56834 Microsoft Word RTF File 'listoverridecount' Remote Code Execution Vulnerability
Microsoft has released advance notification that on December 11, 2012, they will be releasing seven security bulletins addressing eleven vulnerabilities.
The bulletins and their affected components are as follows:
Five bulletins rated 'Critical' affecting Windows, Word, Windows Server, and Internet Explorer
Two bulletins rated 'Important' affecting Windows
This BID is being retired. The following individual records exist to better document the issues:
56443 Microsoft Windows CVE-2012-4774 Remote Code Execution Vulnerability
56828 Microsoft Internet Explorer InjectHTMLStream Use-After-Free Remote Code Execution Vulnerability
56829 Microsoft Internet Explorer CMarkup Use-After-Free Remote Code Execution Vulnerability
56830 Microsoft Internet Explorer Improper Ref Counting Use-After-Free Remote Code Execution Vulnerability
56840 Microsoft Windows IP-HTTPS Server Revoked SSL Certificate Validation Security Bypass Vulnerability
56839 Microsoft DirectX DirectPlay CVE-2012-1537 Heap Overflow Remote Code Execution Vulnerability
56841 Microsoft Windows OpenType Font (OTF) Driver CVE-2012-2556 Remote Code Execution Vulnerability
56842 Microsoft Windows TrueType Font CVE-2012-4786 Remote Code Execution Vulnerability
55977 Oracle Outside In Technology CVE-2012-3214 Local Security Vulnerability
55993 Oracle Outside In Technology CVE-2012-3217 Local Security Vulnerability
56836 Microsoft Exchange Server RSS Feed Remote Denial of Service Vulnerability
56834 Microsoft Word RTF File 'listoverridecount' Remote Code Execution Vulnerability
Exploit / POC
Microsoft December 2012 Advance Notification Multiple Vulnerabilities
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
RETIRED: Microsoft December 2012 Advance Notification Multiple Vulnerabilities
Solution:
Microsoft plans to release fixes to address these issues on December 11, 2012.
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Microsoft plans to release fixes to address these issues on December 11, 2012.
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED: Microsoft December 2012 Advance Notification Multiple Vulnerabilities
References:
References:
- Microsoft Homepage (Microsoft)