Security 10756 Published by

Microsoft published the following security bulletin updates:

- MS11-031 - Critical: Vulnerability in JScript and VBScript Scripting Engines Could Allow Remote Code Execution (2514666) - Version:1.1
- MS11-024 - Important: Vulnerability in Windows Fax Cover Page Editor Could Allow Remote Code Execution (2527308) - Version:1.1
- MS11-022 - Important: Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (2489283) - Version:1.1
- MS10-070 - Important: Vulnerability in ASP.NET Could Allow Information Disclosure (2418042) - Version:4.1



MS11-031 - Critical: Vulnerability in JScript and VBScript Scripting Engines Could Allow Remote Code Execution (2514666) - Version:1.1
Severity Rating: Critical - Revision Note: V1.1 (April 20, 2011): Bulletin updated to clarify that the JScript 5.8 and VBScript 5.8 update (KB2510531) also replaces MS09-045, in addition to MS10-022, for all supported editions of Windows XP, Windows Server 2003, and Windows Vista.

Summary: This security update resolves a privately reported vulnerability in the JScript and VBScript scripting engines. The vulnerability could allow remote code execution if a user visited a specially crafted Web site. An attacker would have no way to force users to visit the Web site. Instead, an attacker would have to convince users to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker's Web site.
Read more

MS11-024 - Important: Vulnerability in Windows Fax Cover Page Editor Could Allow Remote Code Execution (2527308) - Version:1.1
Severity Rating: Important - Revision Note: V1.1 (April 20, 2011): Added a link to Microsoft Knowledge Base Article 2527308 under Known Issues in the Executive Summary.

Summary: This security update resolves one publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opened a specially crafted fax cover page file (.cov) using the Windows Fax Cover Page Editor. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Read more

MS11-022 - Important: Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (2489283) - Version:1.1
Severity Rating: Important - Revision Note: V1.1 (April 20, 2011): Corrected the bulletin replacement information for the Microsoft PowerPoint Web App update (KB2520047). This is an informational change only. There were no changes to the detection logic or the update files.

Summary: This security update resolves three privately reported vulnerabilities in Microsoft PowerPoint. The vulnerabilities could allow remote code execution if a user opens a specially crafted PowerPoint file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The automated Microsoft Fix it solution for PowerPoint 2010, "Disable Edit in Protected View for PowerPoint 2010," available in Microsoft Knowledge Base Article 2501584, blocks the attack vectors for exploiting the vulnerabilities described in CVE-2011-0655 and CVE-2011-0656.
Read more

MS10-070 - Important: Vulnerability in ASP.NET Could Allow Information Disclosure (2418042) - Version:4.1
Severity Rating: Important - Revision Note: V4.1 (April 20, 2011): Corrected registry key verification for Microsoft .NET Framework 3.5 Service Pack 1 when installed on Windows XP and Windows Server 2003.

Summary: This security update resolves a publicly disclosed vulnerability in ASP.NET. The vulnerability could allow information disclosure. An attacker who successfully exploited this vulnerability could read data, such as the view state, which was encrypted by the server. This vulnerability can also be used for data tampering, which, if successfully exploited, could be used to decrypt and tamper with the data encrypted by the server. Microsoft .NET Framework versions prior to Microsoft .NET Framework 3.5 Service Pack 1 are not affected by the file content disclosure portion of this vulnerability.
Read more