Microsoft August 2013 Advance Notification Multiple Vulnerabilities
BID:61686
Info
Microsoft August 2013 Advance Notification Multiple Vulnerabilities
| Bugtraq ID: | 61686 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Aug 08 2013 12:00AM |
| Updated: | Aug 08 2013 12:00AM |
| Credit: | Microsoft |
| Vulnerable: |
Microsoft Windows XP Service Pack 3 0 Microsoft Windows XP Professional x64 Edition SP2 Microsoft Windows Vista x64 Edition SP2 Microsoft Windows Vista Service Pack 2 0 Microsoft Windows Server 2008 R2 for x64-based Systems SP1 Microsoft Windows Server 2008 for x64-based Systems SP2 Microsoft Windows Server 2008 for Itanium-based Systems SP2 Microsoft Windows Server 2008 for 32-bit Systems SP2 Microsoft Windows Server 2003 Itanium SP2 Microsoft Windows Server 2003 SP2 Microsoft Windows 7 for x64-based Systems SP1 Microsoft Windows 7 for 32-bit Systems SP1 Microsoft Internet Explorer 9 Microsoft Internet Explorer 8 Microsoft Internet Explorer 7.0 Microsoft Internet Explorer 6.0 Microsoft Exchange Server 2007 SP3 |
| Not Vulnerable: | |
Discussion
RETIRED: Microsoft August 2013 Advance Notification Multiple Vulnerabilities
Microsoft has released advance notification that on August 13, 2013, they will be releasing eight security bulletins addressing multiple vulnerabilities.
The bulletins and their affected components are as follows:
Three bulletins rated 'Critical' affecting Microsoft Windows, Internet Explorer, and Microsoft Exchange Server.
Five bulletins rated 'Important' affecting Microsoft Windows.
This BID is being retired. The following individual records exist to better document the issues:
61673 Microsoft Windows CVE-2013-3175 Remote Privilege Escalation Vulnerability
61685 Microsoft NAT Driver CVE-2013-3182 Denial of Service Vulnerability
61697 Microsoft Windows Uniscribe Font Parsing CVE-2013-3181 Remote Code Execution Vulnerability
58566 Microsoft Windows CVE-2013-2556 ASLR Security Bypass Vulnerability
61682 Microsoft Windows Kernel CVE-2013-3196 Local Privilege Escalation Vulnerability
61683 Microsoft Windows Kernel CVE-2013-3197 Local Privilege Escalation Vulnerability
61684 Microsoft Windows Kernel CVE-2013-3198 Local Privilege Escalation Vulnerability
61663 Microsoft Internet Explorer CVE-2013-3186 Remote Code Execution Vulnerability
61664 Microsoft Internet Explorer CVE-2013-3192 Information Disclosure Vulnerability
61668 Microsoft Internet Explorer CVE-2013-3184 Memory Corruption Vulnerability
61669 Microsoft Internet Explorer CVE-2013-3187 Memory Corruption Vulnerability
61671 Microsoft Internet Explorer CVE-2013-3189 Memory Corruption Vulnerability
61675 Microsoft Internet Explorer CVE-2013-3190 Memory Corruption Vulnerability
61677 Microsoft Internet Explorer CVE-2013-3191 Memory Corruption Vulnerability
61678 Microsoft Internet Explorer CVE-2013-3193 Use After Free Memory Corruption Vulnerability
61679 Microsoft Internet Explorer CVE-2013-3194 Use After Free Memory Memory Corruption Vulnerability
61680 Microsoft Internet Explorer CVE-2013-3199 Use After Free Memory Corruption Vulnerability
61666 Microsoft Windows TCP/IP ICMPv6 CVE-2013-3183 Remote Denial of Service Vulnerability
61672 Microsoft Active Directory Federation Services CVE-2013-3185 Information Disclosure Vulnerability
59129 Oracle Fusion Middleware CVE-2013-2393 Local Security Vulnerability
61234 Oracle Outside In Technology CVE-2013-3776 Local Security Vulnerability
61232 Oracle Outside In Technology CVE-2013-3781 Local Security Vulnerability
Microsoft has released advance notification that on August 13, 2013, they will be releasing eight security bulletins addressing multiple vulnerabilities.
The bulletins and their affected components are as follows:
Three bulletins rated 'Critical' affecting Microsoft Windows, Internet Explorer, and Microsoft Exchange Server.
Five bulletins rated 'Important' affecting Microsoft Windows.
This BID is being retired. The following individual records exist to better document the issues:
61673 Microsoft Windows CVE-2013-3175 Remote Privilege Escalation Vulnerability
61685 Microsoft NAT Driver CVE-2013-3182 Denial of Service Vulnerability
61697 Microsoft Windows Uniscribe Font Parsing CVE-2013-3181 Remote Code Execution Vulnerability
58566 Microsoft Windows CVE-2013-2556 ASLR Security Bypass Vulnerability
61682 Microsoft Windows Kernel CVE-2013-3196 Local Privilege Escalation Vulnerability
61683 Microsoft Windows Kernel CVE-2013-3197 Local Privilege Escalation Vulnerability
61684 Microsoft Windows Kernel CVE-2013-3198 Local Privilege Escalation Vulnerability
61663 Microsoft Internet Explorer CVE-2013-3186 Remote Code Execution Vulnerability
61664 Microsoft Internet Explorer CVE-2013-3192 Information Disclosure Vulnerability
61668 Microsoft Internet Explorer CVE-2013-3184 Memory Corruption Vulnerability
61669 Microsoft Internet Explorer CVE-2013-3187 Memory Corruption Vulnerability
61671 Microsoft Internet Explorer CVE-2013-3189 Memory Corruption Vulnerability
61675 Microsoft Internet Explorer CVE-2013-3190 Memory Corruption Vulnerability
61677 Microsoft Internet Explorer CVE-2013-3191 Memory Corruption Vulnerability
61678 Microsoft Internet Explorer CVE-2013-3193 Use After Free Memory Corruption Vulnerability
61679 Microsoft Internet Explorer CVE-2013-3194 Use After Free Memory Memory Corruption Vulnerability
61680 Microsoft Internet Explorer CVE-2013-3199 Use After Free Memory Corruption Vulnerability
61666 Microsoft Windows TCP/IP ICMPv6 CVE-2013-3183 Remote Denial of Service Vulnerability
61672 Microsoft Active Directory Federation Services CVE-2013-3185 Information Disclosure Vulnerability
59129 Oracle Fusion Middleware CVE-2013-2393 Local Security Vulnerability
61234 Oracle Outside In Technology CVE-2013-3776 Local Security Vulnerability
61232 Oracle Outside In Technology CVE-2013-3781 Local Security Vulnerability
Exploit / POC
Microsoft August 2013 Advance Notification Multiple Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft August 2013 Advance Notification Multiple Vulnerabilities
Solution:
Microsoft plans to release fixes to address these issues on August 13, 2013.
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Microsoft plans to release fixes to address these issues on August 13, 2013.
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft August 2013 Advance Notification Multiple Vulnerabilities
References:
References:
- Microsoft Homepage (Microsoft)