Critical Product Vulnerability – May 2012 Microsoft Security Bulletin Release
What is the purpose of this alert? |
This alert is to provide you with an
overview of the new security bulletin(s) being released on May 08, 2012.
Security bulletins are released monthly to resolve critical problem vulnerabilities.
New Security Bulletins
Microsoft is releasing the following
seven new security bulletins for newly discovered vulnerabilities:
Bulletin ID | Bulletin Title | Max Severity | Vulnerability | Restart | Affected |
Vulnerability in Microsoft Word | Critical | Remote Code Execution | May require restart | Microsoft Word 2003, Word 2007, | |
Vulnerabilities | Important | Remote Code | May require | Microsoft Excel | |
Vulnerability in Microsoft Visio | Important | Remote Code Execution | May require restart | Microsoft Visio Viewer 2010 | |
Vulnerability | Important | Elevation of | Requires | Microsoft | |
Vulnerability in Windows Partition | Important | Elevation of Privilege | Requires restart | Microsoft Windows Vista, Windows | |
Combined | Critical | Remote Code | May require | Microsoft | |
Vulnerabilities in .NET Framework | Critical | Remote Code Execution | May require restart | Microsoft .NET Framework, Windows |
Summaries for new bulletin(s) may be
found at http://technet.microsoft.com/security/bulletin/MS12-may.
Microsoft Windows Malicious Software
Removal Tool
Microsoft is releasing an updated
version of the Microsoft Windows Malicious Software Removal Tool on Windows
Server Update Services (WSUS), Windows Update (WU), and the Download Center.
Information on the Microsoft Windows Malicious Software Removal Tool is
available at http://www.microsoft.com/security/pc-security/malware-families.aspx.
High Priority Non-Security Updates
High priority non-security updates
Microsoft releases to be available on Microsoft Update (MU), Windows Update
(WU), or Windows Server Update Services (WSUS) will be detailed in the KB
article found at http://support.microsoft.com/?id=894199.
New
Security AdvisorY
Microsoft published one new security
advisory on May 08, 2012. Here is an overview of this new security advisory:
Security | Update Rollup |
Affected Software | · · · · · · |
Executive | Microsoft is · · · |
More Information |
Public
Bulletin Webcast
Microsoft will host a webcast to
address customer questions on these bulletins:
Title: Information about Microsoft May Security Bulletins (Level
200)
Date: Wednesday, May 09, 2012, 11:00 A.M. Pacific Time (UTC-8)
URL: https://msevents.microsoft.com/CUI/EventDetail.aspx?culture=en-US&EventID=1032499667
New
Security Bulletin Technical Details
In the following
tables of affected and non-affected software, software editions that are not
listed are past their support lifecycle. To determine the support lifecycle for
your product and edition, visit the Microsoft Support Lifecycle website at http://support.microsoft.com/lifecycle/.
Bulletin | Microsoft |
Bulletin Title | Vulnerability in |
Executive | This |
Severity Ratings and | · · |
Attack | · · · |
Mitigating Factors | · · |
Restart | This |
Bulletins Replaced | MS11-094, MS11-089, |
Full |
Bulletin | Microsoft |
Bulletin Title | Vulnerabilities in |
Executive | This |
Severity Ratings and | This security update |
Attack | · · · |
Mitigating Factors | · · · |
Restart | This |
Bulletins Replaced | MS11-096, MS11-094, |
Full |
Bulletin | Microsoft |
Bulletin Title | Vulnerability in |
Executive | This |
Severity Ratings and | This security update |
Attack | · · · |
Mitigating Factors | · · · · |
Restart | This |
Bulletins Replaced | MS12-015 |
Full |
Bulletin | Microsoft |
Bulletin Title | Vulnerability in |
Executive | This |
Severity Ratings and | This security update |
Attack | CVE-2012-0174 · CVE-2012-0179 · |
Mitigating Factors | CVE-2012-0174 · CVE-2012-0179 · |
Restart | This |
Bulletins Replaced | MS11-083 |
Full |
Bulletin | Microsoft |
Bulletin Title | Vulnerability in |
Executive | This |
Severity Ratings and | This security update |
Attack | To exploit this |
Mitigating Factors | An attacker must |
Restart | This |
Bulletins Replaced | None |
Full |
Bulletin | Microsoft |
Bulletin Title | Combined Security |
Executive | This |
Severity Ratings and | · · |
Attack | CVE-2011-3402 · · CVE-2012-0159 · · · CVE-2012-0162 · · CVE-2012-0164 · CVE-2012-0165 · · · CVE-2012-0167 · · · CVE-2012-0176 · CVE-2012-0180 · CVE-2012-0181 · CVE-2012-1848 · |
Mitigating Factors | CVE-2011-3402 · · CVE-2012-0162 (.NET · · · CVE-2012-0165 (GDI+ · · CVE-2012-0176 · · · CVE-2012-0180 · CVE-2012-0164 (.NET · |
Restart | This |
Bulletins Replaced | MS11-029, MS12-018, |
Full |
Bulletin | Microsoft |
Bulletin Title | Vulnerabilities in |
Executive | This |
Severity Ratings and | This security update |
Attack | · · |
Mitigating Factors | · · · |
Restart | This |
Bulletins Replaced | MS11-044, MS11-078, |
Full |
Regarding
Information Consistency
We strive to provide you with
accurate information in static (this mail) and dynamic (web-based) content.
Microsoft’s security content posted to the web is occasionally updated to
reflect late-breaking information. If this results in an inconsistency between
the information here and the information in Microsoft’s web-based security
content, the information in Microsoft’s web-based security content is
authoritative.