Quantcast
Channel: TechNet Blogs
Viewing all articles
Browse latest Browse all 17778

Microsoft Security Bulletin: January 2014 Release

$
0
0

3823_7103_securitybulletin_thumb_32407BF9_thumb_12CC8186
Hello everyone and welcome to 2014 and the first security bulletin for the new year!  This month is a bit of a quiet month with only 4 major bulletins to consider for your environments.  Details are below so make sure you look at these and apply where necessary.

Bulletin ID Bulletin Title and Executive SummaryMaximum Severity Rating and Vulnerability ImpactRestart RequirementAffected Software
MS14-001Vulnerabilities in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (2916605)

This security update resolves three privately reported vulnerabilitiesin Microsoft Office. The vulnerabilities could allow remote code execution if a specially crafted file is opened in an affected version of Microsoft Word or other affected Microsoft Office software. An attacker who successfully exploited the vulnerabilities could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Important 
Remote Code Execution
May require restartMicrosoft Office,
Microsoft Server Software
MS14-002Vulnerability in Windows Kernel Could Allow Elevation of Privilege (2914368)

This security update resolves a publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to a system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.
Important 
Elevation of Privilege
Requires restartMicrosoft Windows
MS14-003Vulnerability in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2913602)

This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if a user logs on to a system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.
Important 
Elevation of Privilege
Requires restartMicrosoft Windows
MS14-004Vulnerability in Microsoft Dynamics AX Could Allow Denial of Service (2880826)

This security update resolves one privately reported vulnerability in Microsoft Dynamics AX. The vulnerability could allow denial of service if an authenticated attacker submits specially crafted data to an affected Microsoft Dynamics AX Application Object Server (AOS) instance. An attacker who successfully exploited this vulnerability could cause the target AOS instance to stop responding to client requests.
Important 
Denial of Service
May require restartMicrosoft Dynamics AX

Jeffa

Technorati Tags: ,,

Viewing all articles
Browse latest Browse all 17778

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>