Security 10756 Published by

Microsoft has updated the following security bulletins:

- MS10-082 - Important: Vulnerability in Windows Media Player Could Allow Remote Code Execution (2378111) - Version:1.1
- MS10-079 - Important: Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2293194) - Version:1.1
- MS10-077 - Critical: Vulnerability in .NET Framework Could Allow Remote Code Execution (2160841) - Version:1.1
- MS10-072 - Important: Vulnerabilities in SafeHTML Could Allow Information Disclosure (2412048) - Version:1.1
- MS10-071 - Critical: Cumulative Security Update for Internet Explorer (2360131) - Version:1.1
- MS10-070 - Important: Vulnerability in ASP.NET Could Allow Information Disclosure (2418042) - Version:2.1



MS10-082 - Important: Vulnerability in Windows Media Player Could Allow Remote Code Execution (2378111) - Version:1.1
Severity Rating: Important - Revision Note: V1.1 (October 13, 2010): Corrected the download link in the Affected Software table for Windows Media Player 11 on Windows XP Professional x64 Edition Service Pack 2.

Summary: This security update resolves a privately reported vulnerability in Windows Media Player. The vulnerability could allow remote code execution if Windows Media Player opened specially crafted media content hosted on a malicious Web site. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Read more

MS10-079 - Important: Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2293194) - Version:1.1
Severity Rating: Important - Revision Note: V1.1 (October 13, 2010): Corrected the package name for the Microsoft Office Compatibility Pack (KB2345043) update. This is an informational change only. Customers who have already successfully updated their systems do not need to take any action.

Summary: This security update resolves eleven privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Word file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Read more

MS10-077 - Critical: Vulnerability in .NET Framework Could Allow Remote Code Execution (2160841) - Version:1.1
Severity Rating: Critical - Revision Note: V1.1 (October 13, 2010): Changed the vulnerability severity rating for Windows Server 2008 and Windows Server 2008 R2 to Important. Also added a link to Microsoft Knowledge Base Article 2160841 under Known Issues in the Executive Summary, and revised the vulnerability mitigations.

Summary: This security update resolves a privately reported vulnerability in Microsoft .NET Framework. The vulnerability could allow remote code execution on a client system if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs). Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The vulnerability could also allow remote code execution on a server system running IIS, if that server allows processing ASP.NET pages and an attacker succeeds in uploading a specially crafted ASP.NET page to that server and then executes the page, as could be the case in a Web hosting scenario.
Read more

MS10-072 - Important: Vulnerabilities in SafeHTML Could Allow Information Disclosure (2412048) - Version:1.1
Severity Rating: Important - Revision Note: V1.1 (October 13, 2010): Added a link to Microsoft Knowledge Base Article 2412048 under Known Issues in the Executive Summary.

Summary: This security update resolves one publicly disclosed vulnerability and one privately reported vulnerability in Microsoft SharePoint and Windows SharePoint Services. The vulnerabilities could allow information disclosure if an attacker submits specially crafted script to a target site using SafeHTML.
Read more

MS10-071 - Critical: Cumulative Security Update for Internet Explorer (2360131) - Version:1.1
Severity Rating: Critical - Revision Note: V1.1 (October 13, 2010): Corrected the update package names for Internet Explorer in the Windows Server 2008 deployment reference table. This is an informational change only. Customers who have already successfully updated their systems do not need to take any action.

Summary: This security update resolves seven privately reported vulnerabilities and three publicly disclosed vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Read more

MS10-070 - Important: Vulnerability in ASP.NET Could Allow Information Disclosure (2418042) - Version:2.1
Severity Rating: Important - Revision Note: V2.1 (October 13, 2010): Added three update FAQs to clarify affected software.

Summary: This security update resolves a publicly disclosed vulnerability in ASP.NET. The vulnerability could allow information disclosure. An attacker who successfully exploited this vulnerability could read data, such as the view state, which was encrypted by the server. This vulnerability can also be used for data tampering, which, if successfully exploited, could be used to decrypt and tamper with the data encrypted by the server. Microsoft .NET Framework versions prior to Microsoft .NET Framework 3.5 Service Pack 1 are not affected by the file content disclosure portion of this vulnerability.
Read more