MS Sec Notification mailing list archives

Microsoft Security Update Minor Revisions


From: "Microsoft" <securitynotifications () e-mail microsoft com>
Date: Wed, 28 Jun 2017 18:44:01 -0600

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

********************************************************************
Title: Microsoft Security Update Minor Revisions
Issued: June 28, 2017
********************************************************************

Summary
=======

The following CVE has been added to June 2017 security release. 

* CVE-2017-8554

Revision Information:
=====================

- - Title: CVE-2017-8554 | Win32k Information Disclosure 
   Vulnerability
 - https://portal.msrc.microsoft.com/en-us/security-guidance
 - Reason for Revision: Information published. 
 - Originally posted: June 28, 2017  
 - CVE Severity Rating: Important
 - Version: 1.0 
 

Summary
=======

The following CVEs have been revised in the June 2017 Security Updates. 

* CVE-2017-8529
* CVE-2017-8579

Revision Information:
=====================

CVE-2017-8529

 - Title: CVE-2017-8529 | Microsoft Browser Information Disclosure
   Vulnerability
 - https://portal.msrc.microsoft.com/en-us/security-guidance
 - Reason for Revision: Corrected severity entries for Internet 
   Explorer and Microsoft Edge on the affected client platforms 
   in the Affected Products table. This is an informational change
   only. Customers who have successfully installed the update do not 
   need to take any further action.
 - Originally posted: June 13, 2017  
 - CVE Severity Rating: Moderate
 - Version: 4.1

CVE-2017-8579

 - Title: CVE-2017-8579 | DirectX Elevation of Privilege Vulnerability
 - https://portal.msrc.microsoft.com/en-us/security-guidance
 - Reason for Revision: Corrected the language in the CVE 
   description from "information disclosure" to "elevation of 
   privilege". This is an informational change only.
 - Originally posted: June 19, 2017  
 - CVE Severity Rating: Important
 - Version: 4.1


Other Information
=================

Recognize and avoid fraudulent email to Microsoft customers:
=============================================================
If you receive an email message that claims to be distributing 
a Microsoft security update, it is a hoax that may contain 
malware or pointers to malicious websites. Microsoft does 
not distribute security updates via email. 

The Microsoft Security Response Center (MSRC) uses PGP to digitally 
sign all security notifications. However, PGP is not required for 
reading security notifications, reading security bulletins, or 
installing security updates. You can obtain the MSRC public PGP key
at <https://technet.microsoft.com/security/dn753714>.

********************************************************************
THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************

Microsoft respects your privacy. Please read our online Privacy
Statement at <http://go.microsoft.com/fwlink/?LinkId=81184>.

If you would prefer not to receive future technical security
notification alerts by email from Microsoft and its family of
companies please visit the following website to unsubscribe:
<https://profile.microsoft.com/RegSysProfileCenter/subscriptionwizar
d.aspx?wizid=5a2a311b-5189-4c9b-9f1a-d5e913a26c2e&%3blcid=1033>.

These settings will not affect any newsletters you’ve requested or
any mandatory service communications that are considered part of
certain Microsoft services.

For legal Information, see:
<http://www.microsoft.com/info/legalinfo/default.mspx>.

This newsletter was sent by:
Microsoft Corporation
1 Microsoft Way
Redmond, Washington, USA
98052

-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 10.2.0 (Build 1950)
Charset: utf-8

wsFVAwUBWVRDevsCXwi14Wq8AQg5WQ/8DZELFQDiBSGvNO6RCV+tXzkVshLgxGc0
t982R2Ng6gcjPOW9A1yIrIk6KrQOrRQfz2bGHfBzf5lmQEccn3QHKfloZPnrhLUM
sL5vI3OeoH9OE0aq+3cHENZdrxR7QxYh88G9KTqL/63d07RUaCzAiFdJGFF/1zQm
1vE4fcrF17uYg39FUPl73cwNi7jpxfhLWdhWKwqo4a4gWwImHqoFEScHDLHR9NXi
ZdSDWPN6L37bElJggWHAzeOumL32juHk/A9KXB84nI2Gl+ZDc8S1T44+iARgYvWg
wkhQmWrQxHqp4bP+osgTz+SjpJWbf3bFy+U7hUT5Q3OdybMw5oapO1mZKFYN7/Vj
ZuTatgd2Pb90ITX+0NTJDuVIv+3mXf/8lqGSDDfdD/ag8+lmwR8Mto5LwPce1P9U
4deV6mhriuiac8fD77x47tTXN3W4KBA6ZcIeuJoUz9Fxnz4svxGHaquvBRC6Fz3u
dNMGTIKra3NwyYv7mB4DR/2lHTenmUgHg4FVsfPCNqGnxJw3Lr0B70EPAiv6Xo13
l/g+Fyn8+R9QTYYNHj13oJLkrN8ZQ3g5E90UBhV3QvkSw/USTuIwhTKeyrCGNEXg
AAHg6Z7NPeRmlSI2JtXpwm8VgZ8M54GRDghSacAhjhcrihcM3O6NLE59w/A+uGpg
PbV9vM83mqU=
=btU/
-----END PGP SIGNATURE-----


Current thread: