Click any highlighted term for further explanation. For more information, contact technical support.
|
|
Details
|
|
Vulnerability name/brief description
|
MS12-034 - Combined Security Update for Microsoft Office, Windows, .NET Framework, and Silverlight (2681578)
|
|
CVE/CAN name
|
|
|
Vendor threat level
|
Critical
|
|
SophosLabs threat level
|
High
|
|
Solution
|
MS12-034
|
|
Vendor description
|
This security update resolves three publicly disclosed vulnerabilities and seven privately reported vulnerabilities in Microsoft Office, Microsoft Windows, the Microsoft .NET Framework, and Microsoft Silverlight. The most severe of these vulnerabilities could allow remote code execution if a user opens a specially crafted document or visits a malicious webpage that embeds TrueType font files. An attacker would have no way to force users to visit a malicious website. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes them to the attacker's website.
|
|
SophosLabs comments
|
This security update resolves ten vulnerabilities and it affects a wide variety of software; including Microsoft Office, Microsoft Windows, the Microsoft .NET Framework, and Microsoft Silverlight. Due to its wide impact on not only software but also operating systems (some of the vulnerabilities also target both workstations and servers alike), it is highly recommended that this update be applied as soon as possible.
|
|
SophosLabs testing result
|
No SophosLabs testing result found
|
|
Currently known exploits
|
-
Troj/DexFont-A
-
Troj/DexFont-B
-
Exp/20113402-A
|
|
First sample seen
|
No samples found
|
|
Discovery date
|
08 May 2012
|
|
Affected software
|
Windows XP Service Pack 3 (Tablet PC Edition 2005 Service Pack 3 only)
Windows XP Service Pack 3
Windows XP Professional x64 Edition Service Pack 2
Windows Server 2003 Service Pack 2
Windows Server 2003 x64 Edition Service Pack 2
Windows Server 2003 with SP2 for Itanium-based Systems
Windows Vista Service Pack 2
Windows Vista x64 Edition Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for Itanium-based Systems Service Pack 2
Windows 7 for 32-bit Systems
Windows 7 for 32-bit Systems Service Pack 1
Windows 7 for x64-based Systems
Windows 7 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for Itanium-based Systems
Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
Windows XP Service Pack 3 Microsoft .NET Framework 3.0 Service Pack 2
Windows XP Professional x64 Edition Service Pack 2 with Microsoft .NET Framework 3.0 Service Pack 2
Windows Server 2003 Service Pack 2 with Microsoft .NET Framework 3.0 Service Pack 2
Windows Server 2003 x64 Edition Service Pack 2 with Microsoft .NET Framework 3.0 Service Pack 2
Windows Vista Service Pack 2 with Microsoft .NET Framework 3.0 Service Pack 2
Windows Vista x64 Edition Service Pack 2 with Microsoft .NET Framework 3.0 Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 with Microsoft .NET Framework 3.0 Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2 with Microsoft .NET Framework 3.0 Service Pack 2
Windows 7 for 32-bit Systems with Microsoft .NET Framework 3.5.1
Windows 7 for 32-bit Systems Service Pack 1 with Microsoft .NET Framework 3.5.1
Windows 7 for x64-based Systems with Microsoft .NET Framework 3.5.1
Windows 7 for x64-based Systems Service Pack 1 with Microsoft .NET Framework 3.5.1
Windows Server 2008 R2 for x64-based Systems with Microsoft .NET Framework 3.5.1
Windows Server 2008 R2 for x64-based Systems Service Pack 1 with Microsoft .NET Framework 3.5.1
Windows XP Service Pack 3 with Microsoft .NET Framework 4
Windows XP Professional x64 Edition Service Pack 2 with Microsoft .NET Framework 4
Windows Server 2003 Service Pack 2 with Microsoft .NET Framework 4
Windows Server 2003 x64 Edition Service Pack 2 with Microsoft .NET Framework 4
Windows Vista Service Pack 2 with Microsoft .NET Framework 4
Windows Vista x64 Edition Service Pack 2 with Microsoft .NET Framework 4
Windows Server 2008 for 32-bit Systems Service Pack 2 with Microsoft .NET Framework 4
Windows Server 2008 for x64-based Systems Service Pack 2 with Microsoft .NET Framework 4
Windows 7 for 32-bit Systems with Microsoft .NET Framework 4
Windows 7 for 32-bit Systems Service Pack 1 with Microsoft .NET Framework 4
Windows 7 for x64-based Systems with Microsoft .NET Framework 4
Windows 7 for x64-based Systems Service Pack 1 with Microsoft .NET Framework 4
Windows Server 2008 R2 for x64-based Systems with Microsoft .NET Framework 4
Windows Server 2008 R2 for x64-based Systems Service Pack 1 with Microsoft .NET Framework 4
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 R2 for x64-based Systems
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems with Microsoft .NET Framework 3.5.1
Windows Server 2008 R2 for x64-based Systems Service Pack 1 with Microsoft .NET Framework 3.5.1
Windows Server 2008 R2 for x64-based Systems Service Pack 1 with Microsoft .NET Framework 4
Microsoft Office 2003 Service Pack 3
Microsoft Office 2007 Service Pack 2
Microsoft Office 2007 Service Pack 3
Microsoft Office 2007 Service Pack 3
Microsoft Office 2010 (32-bit editions)
Microsoft Office 2010 Service Pack 1 (32-bit editions)
Microsoft Office 2010 (64-bit editions)
Microsoft Office 2010 Service Pack 1 (64-bit editions)
Microsoft Silverlight 4 when installed on Mac
Microsoft Silverlight 4 when installed on all supported releases of Microsoft Windows clients
Microsoft Silverlight 4 when installed on all supported releases of Microsoft Windows servers
Microsoft Silverlight 5 when installed on Mac
Microsoft Silverlight 5 when installed on all supported releases of Microsoft Windows clients
Microsoft Silverlight 5 when installed on all supported releases of Microsoft Windows servers
|
|
References
|
|
|
Credits
|
|
|
Revisions
|
-
May 8th, 2012 - Initial analysis written
|
Explanation of terms
Vulnerability Name/Brief Description:
Vendor identifier plus a brief description of the type of attack.
CVE/CAN Name:
Currently assigned CVE name. If a CVE name doesn't exist the CAN name will be used until a CVE has been assigned.
Vendor Threat Level:
Threat level assigned by the vendor
SophosLabs Threat Level:
Threat level assigned by SophosLabs
- LOW RISK - There is little chance of this vulnerability being actively exploited by malware.
- MEDIUM RISK - There is a possibility of this vulnerability being actively exploited by malware.
- HIGH RISK - There is a strong possibility of this vulnerability being actively exploited by malware.
- CRITICAL RISK - This vulnerability will almost certainly be actively exploited by malware.
Solution:
Vendor-supplied Patch identifier and recommended solution, or workaround if applicable.
Vendor Description:
Summary of the cause and potential effect of the vulnerability provided by the vendor.
SophosLabs Comments:
SophosLabs' opinions and observations of the vulnerability in question.
SophosLabs Testing Result:
Details of completed lab testing, if applicable. Please note that the lab test environment may differ significantly from user environments.
Currently Known Exploits:
List of identities for known exploits, if applicable.
First Sample Seen:
Date of the first sample seen by SophosLabs.
Discovery Date:
Date of the earliest known publically disclosed advisory.
Affected Software:
Vulnerable platforms and software versions.