본문 바로가기

취약점 정보1

Microsoft Patch Tuesday - April 2015

728x90

Overview of the April 2015 Microsoft patches and their status.

#AffectedContra Indications - KBKnown ExploitsMicrosoft rating(**)ISC rating(*)
clientsservers
MS15-032Cumulative Security Update for Internet Explorer
(ReplacesMS15-018 )
CVE-2015-1652CVE-2015-1657CVE-2015-1659CVE-2015-1660CVE-2015-1661CVE-2015-1662CVE-2015-1665CVE-2015-1666CVE-2015-1667CVE-2015-1668KB 3038314NoSeverity:Critical
Exploitability:
CriticalImportant
MS15-033Vulnerabilities in Microsoft Office Could Allow Remote Code Execution
(ReplacesMS14-081 MS15-022 )
CVE-2015-1639
CVE-2015-1641
CVE-2015-1649
CVE-2015-1650
CVE-2015-1651
KB 3048019vuln. public.Severity:Critical
Exploitability:
CriticalImportant
MS15-034Vulnerability in HTTP.sys Could Allow Remote Code Execution
CVE-2015-1635KB 3042553NoSeverity:Critical
Exploitability:
CriticalCritical
MS15-035Vulnerability in Microsoft Graphics Component Could Allow Remote Code Execution
CVE-2015-1645KB 3046306NoSeverity:Critical
Exploitability:
CriticalCritical
MS15-036Vulnerabilities in Microsoft SharePoint Server Could Allow Elevation of Privilege
(ReplacesMS15-022 )
CVE-2015-1640
CVE-2015-1653
KB 3052044NoSeverity:Important
Exploitability:
N/AImportant
MS15-037Vulnerability in Windows Task Scheduler Could Allow Elevation of Privilege
CVE-2015-0098KB 3046269NoSeverity:Important
Exploitability:
ImportantImportant
MS15-038Vulnerabilities in Microsoft Windows Could Allow Elevation of Privilege
(ReplacesMS15-025 MS15-031 )
CVE-2015-1643
CVE-2015-1644
KB 3049576NoSeverity:Important
Exploitability:
ImportantImportant
MS15-039Vulnerability in XML Core Services Could Allow Security Feature Bypass
(ReplacesMS14-067 )
CVE-2015-1646KB 3046482NoSeverity:Important
Exploitability:
ImportantImportant
MS15-040Vulnerability in Active Directory Federation Services Could Allow Information Disclosure
CVE-2015-1638KB 3045711NoSeverity:Important
Exploitability:
ImportantImportant
MS15-041Vulnerability in .NET Framework Could Allow Information Disclosure
(ReplacesMS14-009 )
CVE-2015-1648KB 3048010NoSeverity:Important
Exploitability:
ImportantImportant
MS15-042Vulnerability in Windows Hyper-V Could Allow Denial of Service
CVE-2015-1647KB 3047234NoSeverity:Important
Exploitability:
ImportantImportant
We will update issues on this page for about a week or so as they evolve.
We appreciate updates
US based customers can call Microsoft for free patch related support on 1-866-PCSAFETY
(*): ISC rating
  • We use 4 levels:
    • PATCH NOW: Typically used where we see immediate danger of exploitation. Typical environments will want to deploy these patches ASAP. Workarounds are typically not accepted by users or are not possible. This rating is often used when typical deployments make it vulnerable and exploits are being used or easy to obtain or make.
    • Critical: Anything that needs little to become "interesting" for the dark side. Best approach is to test and deploy ASAP. Workarounds can give more time to test.
    • Important: Things where more testing and other measures can help.
    • Less Urt practices for servers such as not using outlook, MSIE, word etc. to do traditional office or leisure work.
    • The rating is not a risk analysis as such. It is a rating of importance of the vulnerability and the perceived or even predicted threatatches.
728x90