RETIRED: Microsoft November 2014 Advance Notification Multiple Vulnerabilities
BID:70966
Info
RETIRED: Microsoft November 2014 Advance Notification Multiple Vulnerabilities
| Bugtraq ID: | 70966 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Nov 06 2014 12:00AM |
| Updated: | Nov 12 2014 09:03PM |
| Credit: | Microsoft |
| Vulnerable: |
Microsoft Word Viewer 0 Microsoft Windows Vista x64 Edition SP2 Microsoft Windows Vista SP2 Microsoft Windows Server 2008 R2 for x64-based Systems SP1 Microsoft Windows Server 2008 for x64-based Systems SP2 Microsoft Windows Server 2008 for Itanium-based Systems SP2 Microsoft Windows Server 2008 for 32-bit Systems SP2 Microsoft Windows Server 2003 x64 SP2 Microsoft Windows Server 2003 Itanium SP2 Microsoft Windows Server 2003 SP2 Microsoft Windows 7 for x64-based Systems SP1 Microsoft Windows 7 for 32-bit Systems SP1 Microsoft Office 2007 SP3 Microsoft Internet Explorer 9 Microsoft Internet Explorer 8 Microsoft Internet Explorer 7.0 Microsoft Internet Explorer 6.0 Microsoft Exchange Server 2007 SP3 |
| Not Vulnerable: | |
Discussion
RETIRED: Microsoft November 2014 Advance Notification Multiple Vulnerabilities
Microsoft has released advance notification that on November 11, 2014, they will be releasing sixteen security bulletins addressing multiple vulnerabilities.
The bulletins and their affected components are as follows:
Five bulletin rated 'Critical' affecting Microsoft Windows, and Internet Explorer.
Nine bulletins rated 'Important' affecting Microsoft Windows, Microsoft Server Software, Microsoft .NET Framework, Microsoft Office, and Microsoft Exchange.
Two bulletins rated 'Moderate' affecting Microsoft Windows, and Microsoft Office.
This BID is being retired. The following individual records exist to better document the issues:
70948 Microsoft Internet Explorer CVE-2014-6339 ASLR Security Bypass Vulnerability
70947 Microsoft Internet Explorer CVE-2014-6323 Clipboard Information Disclosure Vulnerability
70946 Microsoft Internet Explorer CVE-2014-6346 Cross Domain Information Disclosure Vulnerability
70949 Microsoft Windows Kernel TrueType Font Parsing CVE-2014-6317 Denial of Service Vulnerability
70942 Microsoft Internet Explorer CVE-2014-6345 Cross Domain Information Disclosure Vulnerability
70941 Microsoft Internet Explorer CVE-2014-6340 Cross Domain Information Disclosure Vulnerability
70979 Microsoft .NET Framework CVE-2014-4149 Remote Privilege Escalation Vulnerability
70940 Microsoft Internet Explorer CVE-2014-6350 Remote Privilege Escalation Vulnerability
70981 Microsoft Windows Remote Desktop Protocol CVE-2014-6318 Security Bypass Vulnerability
70939 Microsoft Internet Explorer CVE-2014-6349 Remote Privilege Escalation Vulnerability
70348 Microsoft Internet Explorer CVE-2014-6348 Remote Memory Corruption Vulnerability
70347 Microsoft Internet Explorer CVE-2014-6347 Remote Memory Corruption Vulnerability
70346 Microsoft Internet Explorer CVE-2014-6344 Remote Memory Corruption Vulnerability
70980 Microsoft SharePoint Server CVE-2014-4116 Remote Privilege Escalation Vulnerability
70345 Microsoft Internet Explorer CVE-2014-4143 Remote Memory Corruption Vulnerability
70952 Microsoft Windows CVE-2014-6332 OLE Remote Code Execution Vulnerability
70344 Microsoft Internet Explorer CVE-2014-6343 Remote Memory Corruption Vulnerability
70341 Microsoft Internet Explorer CVE-2014-6342 Remote Memory Corruption Vulnerability
70690 Microsoft Windows CVE-2014-6352 OLE Remote Code Execution Vulnerability
70338 Microsoft Internet Explorer CVE-2014-6341 Remote Memory Corruption Vulnerability
70337 Microsoft Internet Explorer CVE-2014-6337 Remote Memory Corruption Vulnerability
70944 Microsoft Input Method Editor (IME) for Japanese Remote Privilege Escalation Vulnerability
70333 Microsoft Internet Explorer CVE-2014-6353 Remote Memory Corruption Vulnerability
70978 Microsoft Windows CVE-2014-6322 Remote Privilege Escalation Vulnerability
70323 Microsoft Internet Explorer CVE-2014-6351 Remote Memory Corruption Vulnerability
70938 Microsoft Active Directory Federation Services CVE-2014-6331 Information Disclosure Vulnerability
70976 Microsoft Windows TCP/IP CVE-2014-4076 Local Privilege Escalation Vulnerability
70937 Microsoft Internet Information Services CVE-2014-4078 Security Bypass Vulnerability
70954 Microsoft Secure Channel CVE-2014-6321 Remote Code Execution Vulnerability
70957 Microsoft XML Core Services CVE-2014-4118 Remote Code Execution Vulnerability
70963 Microsoft Office Invalid Pointer CVE-2014-6335 Memory Corruption Vulnerability
70962 Microsoft Office Bad Index CVE-2014-6334 Memory Corruption Vulnerability
70961 Microsoft Office Double Delete CVE-2014-6333 Remote Code Execution Vulnerability
Microsoft has released advance notification that on November 11, 2014, they will be releasing sixteen security bulletins addressing multiple vulnerabilities.
The bulletins and their affected components are as follows:
Five bulletin rated 'Critical' affecting Microsoft Windows, and Internet Explorer.
Nine bulletins rated 'Important' affecting Microsoft Windows, Microsoft Server Software, Microsoft .NET Framework, Microsoft Office, and Microsoft Exchange.
Two bulletins rated 'Moderate' affecting Microsoft Windows, and Microsoft Office.
This BID is being retired. The following individual records exist to better document the issues:
70948 Microsoft Internet Explorer CVE-2014-6339 ASLR Security Bypass Vulnerability
70947 Microsoft Internet Explorer CVE-2014-6323 Clipboard Information Disclosure Vulnerability
70946 Microsoft Internet Explorer CVE-2014-6346 Cross Domain Information Disclosure Vulnerability
70949 Microsoft Windows Kernel TrueType Font Parsing CVE-2014-6317 Denial of Service Vulnerability
70942 Microsoft Internet Explorer CVE-2014-6345 Cross Domain Information Disclosure Vulnerability
70941 Microsoft Internet Explorer CVE-2014-6340 Cross Domain Information Disclosure Vulnerability
70979 Microsoft .NET Framework CVE-2014-4149 Remote Privilege Escalation Vulnerability
70940 Microsoft Internet Explorer CVE-2014-6350 Remote Privilege Escalation Vulnerability
70981 Microsoft Windows Remote Desktop Protocol CVE-2014-6318 Security Bypass Vulnerability
70939 Microsoft Internet Explorer CVE-2014-6349 Remote Privilege Escalation Vulnerability
70348 Microsoft Internet Explorer CVE-2014-6348 Remote Memory Corruption Vulnerability
70347 Microsoft Internet Explorer CVE-2014-6347 Remote Memory Corruption Vulnerability
70346 Microsoft Internet Explorer CVE-2014-6344 Remote Memory Corruption Vulnerability
70980 Microsoft SharePoint Server CVE-2014-4116 Remote Privilege Escalation Vulnerability
70345 Microsoft Internet Explorer CVE-2014-4143 Remote Memory Corruption Vulnerability
70952 Microsoft Windows CVE-2014-6332 OLE Remote Code Execution Vulnerability
70344 Microsoft Internet Explorer CVE-2014-6343 Remote Memory Corruption Vulnerability
70341 Microsoft Internet Explorer CVE-2014-6342 Remote Memory Corruption Vulnerability
70690 Microsoft Windows CVE-2014-6352 OLE Remote Code Execution Vulnerability
70338 Microsoft Internet Explorer CVE-2014-6341 Remote Memory Corruption Vulnerability
70337 Microsoft Internet Explorer CVE-2014-6337 Remote Memory Corruption Vulnerability
70944 Microsoft Input Method Editor (IME) for Japanese Remote Privilege Escalation Vulnerability
70333 Microsoft Internet Explorer CVE-2014-6353 Remote Memory Corruption Vulnerability
70978 Microsoft Windows CVE-2014-6322 Remote Privilege Escalation Vulnerability
70323 Microsoft Internet Explorer CVE-2014-6351 Remote Memory Corruption Vulnerability
70938 Microsoft Active Directory Federation Services CVE-2014-6331 Information Disclosure Vulnerability
70976 Microsoft Windows TCP/IP CVE-2014-4076 Local Privilege Escalation Vulnerability
70937 Microsoft Internet Information Services CVE-2014-4078 Security Bypass Vulnerability
70954 Microsoft Secure Channel CVE-2014-6321 Remote Code Execution Vulnerability
70957 Microsoft XML Core Services CVE-2014-4118 Remote Code Execution Vulnerability
70963 Microsoft Office Invalid Pointer CVE-2014-6335 Memory Corruption Vulnerability
70962 Microsoft Office Bad Index CVE-2014-6334 Memory Corruption Vulnerability
70961 Microsoft Office Double Delete CVE-2014-6333 Remote Code Execution Vulnerability
Exploit / POC
RETIRED: Microsoft November 2014 Advance Notification Multiple Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
RETIRED: Microsoft November 2014 Advance Notification Multiple Vulnerabilities
Solution:
Microsoft plans to release fixes to address these issues on November 11, 2014.
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Microsoft plans to release fixes to address these issues on November 11, 2014.
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED: Microsoft November 2014 Advance Notification Multiple Vulnerabilities
References:
References:
- Microsoft Homepage (Microsoft)