MS Sec Notification mailing list archives

The following CVEs and Microsoft security bulletin have undergone a minor revision increment


From: "Microsoft" <securitynotifications () e-mail microsoft com>
Date: Wed, 23 Aug 2017 12:03:04 -0600

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

********************************************************************
Title: Microsoft Security Update Minor Revisions
Issued: August 23, 2017
********************************************************************

Summary
=======

The following CVEs and Microsoft security bulletin have undergone a 
minor revision increment 

* CVE-2016-7292
* CVE-2017-0167
* MS16-149

Revision Information:
=====================

CVE-2016-7292

 - Title: CVE-2016-7292 | Windows Installer Elevation of Privilege
   Vulnerability
 - https://portal.msrc.microsoft.com/en-us/security-guidance
 - Reason for Revision: Corrected the Updates Replaced for security 
   update 3196726 to None. This is an informational change only. 
   Customers who have already successfully installed the update do
   not need to take any further action.
 - Originally posted: December 13, 2016
 - Updated: August 23, 2017
 - CVE Severity Rating: Important
 - Version: 1.1

 CVE-2017-0167

 - Title: CVE-2017-0167 | Windows Kernel Information Disclosure 
   Vulnerability
 - https://portal.msrc.microsoft.com/en-us/security-guidance
 - Reason for Revision: Corrected the Monthly Rollup and Security
   Update information for Windows 7 and Windows Server 2008 R2 in 
   the Affected Products table to Monthly Rollup 4022719 and 
   Security Update 4022722. Microsoft recommends that customers 
   running supported editions of Windows 7 or Windows Server 2008 R2 
   install the Monthly Rollup or the Security Update to be fully 
   protected from CVE-2017-0167. Customers who have already 
   successfully installed the updates do not need to take any further
   action.
 - Originally posted: April 11, 2017
 - Updated: August 23, 2017
 - CVE Severity Rating: Important
 - Version: 2.1

MS16-149

 - Title: Security Update for Microsoft Windows (3205655)
 - https://technet.microsoft.com/library/security/ms16-149
 - Reason for Revision: Corrected the Updates Replaced for security 
   update 3196726 to None. This is an informational change only. 
   Customers who have already successfully installed the update do 
   not need to take any further action.
 - Originally posted: December 13, 2016 
 - Updated: August 23, 2017 
 - CVE Severity Rating: Important
 - Version: 1.1


Other Information
=================

Recognize and avoid fraudulent email to Microsoft customers:
=============================================================
If you receive an email message that claims to be distributing 
a Microsoft security update, it is a hoax that may contain 
malware or pointers to malicious websites. Microsoft does 
not distribute security updates via email. 

The Microsoft Security Response Center (MSRC) uses PGP to digitally 
sign all security notifications. However, PGP is not required for 
reading security notifications, reading security bulletins, or 
installing security updates. You can obtain the MSRC public PGP key
at <https://technet.microsoft.com/security/dn753714>.

********************************************************************
THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************

Microsoft respects your privacy. Please read our online Privacy
Statement at <http://go.microsoft.com/fwlink/?LinkId=81184>.

If you would prefer not to receive future technical security
notification alerts by email from Microsoft and its family of
companies please visit the following website to unsubscribe:
<https://profile.microsoft.com/RegSysProfileCenter/subscriptionwizar
d.aspx?wizid=5a2a311b-5189-4c9b-9f1a-d5e913a26c2e&%3blcid=1033>.

These settings will not affect any newsletters you’ve requested or
any mandatory service communications that are considered part of
certain Microsoft services.

For legal Information, see:
<http://www.microsoft.com/info/legalinfo/default.mspx>.

This newsletter was sent by:
Microsoft Corporation
1 Microsoft Way
Redmond, Washington, USA
98052

-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 10.2.0 (Build 1950) - not licensed for commercial use: www.pgp.com
Charset: utf-8

wsFVAwUBWZ2/W/sCXwi14Wq8AQhmhBAAoALGwE69wjZFiM/KrPU24siCWGiRKlcj
gYEUJERtSyhN7msco47PWIYi8gTrqdfuv2oCIU6pWoIasN1cShE2yu0ZOjXvr7XL
IWOFXqxMHCPl+oEyMyKT0wSokc43EWV5mWIBFI9ycThypXp7+jodZtdSyAvQYKzU
0Ts08Rj3kLrf59buGAyQbRv+DcjjCAvG33fp7GkawdaIdtC5eXEgYJGsSjoXU4Wy
e5B2IYma2KayWoSeOr98pkz8IOo5+otxk80xhwg4VtejZ8p1IkEnnXhqzK6EEiro
AG54HzousOdoIGtFwFzfPVYhf/4XUnH8Jrr3MrYrTzrDe6vwYGzpu3xQJgRmQjve
31PulwWuXJxmFvYlS69+SUe9azstO+cRs7MtVgiNz83NTzbfSzTPBG9mcQwJD6QB
b9i88Lg/qZipH7TXsBwubrwzVEpmgw1w5SIPc3shJ94f/69rcnHR/Yba0qexFj+M
SowTcK+hSq6KxN1qZiZvfUgdoNlR6NA0DW2SqfP1QmwwUKxJ6qyRb9RHOXgFSeUA
EE5C9T8oViM7i/Dv55qrMXbJNHELOQwguv2bL5+OUGCvF9hTJjR2/ajvK5sOpoKw
cgXK5bag90VORSHhZvtSouxn5qBfiJ4hD5X+MNHmKidiwNtAcCTu0xFbnFXga8On
NlpTajAVMAU=
=+hiM
-----END PGP SIGNATURE-----


Current thread: