RETIRED: Microsoft October 2014 Advance Notification Multiple Vulnerabilities
BID:70367
Info
RETIRED: Microsoft October 2014 Advance Notification Multiple Vulnerabilities
| Bugtraq ID: | 70367 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Oct 09 2014 12:00AM |
| Updated: | Nov 12 2014 09:03PM |
| Credit: | Microsoft |
| Vulnerable: |
Microsoft Windows Vista x64 Edition SP2 Microsoft Windows Vista SP2 Microsoft Windows Server 2008 R2 for x64-based Systems SP1 Microsoft Windows Server 2008 for x64-based Systems SP2 Microsoft Windows Server 2008 for Itanium-based Systems SP2 Microsoft Windows Server 2008 for 32-bit Systems SP2 Microsoft Windows Server 2003 x64 SP2 Microsoft Windows Server 2003 Itanium SP2 Microsoft Windows Server 2003 SP2 Microsoft Windows 7 for x64-based Systems SP1 Microsoft Windows 7 for 32-bit Systems SP1 Microsoft Office Web Apps 2010 SP1 Microsoft Office Web Apps 2010 0 Microsoft Office SharePoint Server 2010 SP1 Microsoft Office 2010 (64-bit edition) SP1 Microsoft Office 2010 (32-bit edition) SP1 Microsoft Office 2007 SP3 Microsoft Internet Explorer 9 Microsoft Internet Explorer 8 Microsoft Internet Explorer 7.0 Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
RETIRED: Microsoft October 2014 Advance Notification Multiple Vulnerabilities
Microsoft has released advance notification that on October 14, 2014, they will be releasing nine security bulletins addressing multiple vulnerabilities.
The bulletins and their affected components are as follows:
Three bulletin rated 'Critical' affecting Microsoft Windows, Internet Explorer and Microsoft .NET Framework.
Five bulletins rated 'Important' affecting Microsoft Windows, Microsoft Office, Microsoft Office Services, Microsoft Office Web Apps and Microsoft Developer Tools
One bulletin rated 'Moderate' affecting Microsoft Windows and Microsoft Office.
This BID is being retired. The following individual records exist to better document the issues:
70364 Microsoft Windows Kernel 'Win32k.sys' CVE-2014-4113 Local Privilege Escalation Vulnerability
70419 Microsoft Windows CVE-2014-4114 OLE Package Manager Remote Code Execution Vulnerability
70429 Microsoft Windows 'Win32k.sys' TrueType Font Handling Remote Code Execution Vulnerability
70326 Microsoft Internet Explorer CVE-2014-4123 Remote Privilege Escalation Vulnerability
70336 Microsoft Internet Explorer CVE-2014-4134 Remote Memory Corruption Vulnerability
70339 Microsoft Internet Explorer CVE-2014-4137 Remote Memory Corruption Vulnerability
70334 Microsoft Internet Explorer CVE-2014-4132 Remote Memory Corruption Vulnerability
70340 Microsoft Internet Explorer CVE-2014-4138 Remote Memory Corruption Vulnerability
70330 Microsoft Internet Explorer CVE-2014-4128 Remote Memory Corruption Vulnerability
70331 Microsoft Internet Explorer CVE-2014-4129 Remote Memory Corruption Vulnerability
70349 Microsoft Internet Explorer CVE-2014-4124 Remote Privilege Escalation Vulnerability
70332 Microsoft Internet Explorer CVE-2014-4130 Remote Memory Corruption Vulnerability
70328 Microsoft Internet Explorer CVE-2014-4126 Remote Memory Corruption Vulnerability
70329 Microsoft Internet Explorer CVE-2014-4127 Remote Memory Corruption Vulnerability
70325 Microsoft Internet Explorer CVE-2014-4140 ASLR Security Bypass Vulnerability
70342 Microsoft Internet Explorer CVE-2014-4141 Remote Memory Corruption Vulnerability
70335 Microsoft Internet Explorer CVE-2014-4133 Remote Memory Corruption Vulnerability
70343 Microsoft Windows FAT32 Disk Partition Driver CVE-2014-4115 Local Privilege Escalation Vulnerability
70351 Microsoft .NET Framework 'iriParsing' Remote Code Execution Vulnerability
70313 Microsoft .NET Framework ClickOnce CVE-2014-4073 Remote Privilege Escalation Vulnerability
70312 Microsoft .NET Framework CVE-2014-4122 ASLR Security Bypass Vulnerability
68764 Multiple Microsoft Products Arbitrary Memory Write Privilege Escalation Vulnerabilities
70360 Microsoft Office Word File Processing CVE-2014-4117 Remote Code Execution Vulnerability
70352 Microsoft ASP.NET MVC CVE-2014-4075 Cross Site Scripting Vulnerability
Microsoft has released advance notification that on October 14, 2014, they will be releasing nine security bulletins addressing multiple vulnerabilities.
The bulletins and their affected components are as follows:
Three bulletin rated 'Critical' affecting Microsoft Windows, Internet Explorer and Microsoft .NET Framework.
Five bulletins rated 'Important' affecting Microsoft Windows, Microsoft Office, Microsoft Office Services, Microsoft Office Web Apps and Microsoft Developer Tools
One bulletin rated 'Moderate' affecting Microsoft Windows and Microsoft Office.
This BID is being retired. The following individual records exist to better document the issues:
70364 Microsoft Windows Kernel 'Win32k.sys' CVE-2014-4113 Local Privilege Escalation Vulnerability
70419 Microsoft Windows CVE-2014-4114 OLE Package Manager Remote Code Execution Vulnerability
70429 Microsoft Windows 'Win32k.sys' TrueType Font Handling Remote Code Execution Vulnerability
70326 Microsoft Internet Explorer CVE-2014-4123 Remote Privilege Escalation Vulnerability
70336 Microsoft Internet Explorer CVE-2014-4134 Remote Memory Corruption Vulnerability
70339 Microsoft Internet Explorer CVE-2014-4137 Remote Memory Corruption Vulnerability
70334 Microsoft Internet Explorer CVE-2014-4132 Remote Memory Corruption Vulnerability
70340 Microsoft Internet Explorer CVE-2014-4138 Remote Memory Corruption Vulnerability
70330 Microsoft Internet Explorer CVE-2014-4128 Remote Memory Corruption Vulnerability
70331 Microsoft Internet Explorer CVE-2014-4129 Remote Memory Corruption Vulnerability
70349 Microsoft Internet Explorer CVE-2014-4124 Remote Privilege Escalation Vulnerability
70332 Microsoft Internet Explorer CVE-2014-4130 Remote Memory Corruption Vulnerability
70328 Microsoft Internet Explorer CVE-2014-4126 Remote Memory Corruption Vulnerability
70329 Microsoft Internet Explorer CVE-2014-4127 Remote Memory Corruption Vulnerability
70325 Microsoft Internet Explorer CVE-2014-4140 ASLR Security Bypass Vulnerability
70342 Microsoft Internet Explorer CVE-2014-4141 Remote Memory Corruption Vulnerability
70335 Microsoft Internet Explorer CVE-2014-4133 Remote Memory Corruption Vulnerability
70343 Microsoft Windows FAT32 Disk Partition Driver CVE-2014-4115 Local Privilege Escalation Vulnerability
70351 Microsoft .NET Framework 'iriParsing' Remote Code Execution Vulnerability
70313 Microsoft .NET Framework ClickOnce CVE-2014-4073 Remote Privilege Escalation Vulnerability
70312 Microsoft .NET Framework CVE-2014-4122 ASLR Security Bypass Vulnerability
68764 Multiple Microsoft Products Arbitrary Memory Write Privilege Escalation Vulnerabilities
70360 Microsoft Office Word File Processing CVE-2014-4117 Remote Code Execution Vulnerability
70352 Microsoft ASP.NET MVC CVE-2014-4075 Cross Site Scripting Vulnerability
Exploit / POC
RETIRED: Microsoft October 2014 Advance Notification Multiple Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
RETIRED: Microsoft October 2014 Advance Notification Multiple Vulnerabilities
Solution:
Microsoft plans to release fixes to address these issues on October 14, 2014.
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Microsoft plans to release fixes to address these issues on October 14, 2014.
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED: Microsoft October 2014 Advance Notification Multiple Vulnerabilities
References:
References:
- Microsoft Homepage (Microsoft)