MS Sec Notification mailing list archives

Microsoft Security Update Minor Revisions


From: "Microsoft" <securitynotifications () e-mail microsoft com>
Date: Fri, 15 Sep 2017 18:07:18 -0600

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

********************************************************************
Title: Microsoft Security Update Minor Revisions
Issued: September 15, 2017
********************************************************************

Summary
=======

The following CVEs have been revised in the September 2017 Security
Updates. 

* CVE-2017-8676
* CVE-2017-8682
* CVE-2017-8695
* CVE-2017-8728
* CVE-2017-8742


Revision Information:
=====================

CVE-2017-8676

 - Title: CVE-2017-8676 | Windows GDI+ Information Disclosure    
   Vulnerability
 - https://portal.msrc.microsoft.com/en-us/security-guidance
 - Reason for Revision: Added an FAQ to explain why security update     
   3191848 is not applicable to Office 2010 on Windows Server 2008
   and later versions. This is an informational change only. 
   Customers who have already installed the updates do not need to 
   take any further action.
 - Originally posted: September 12, 2017  
 - Updated: September 14, 2017
 - CVE Severity Rating: Critical
 - Version: 1.1

CVE-2017-8676

 - Title: CVE-2017-8676 | Windows GDI+ Information Disclosure    
   Vulnerability
 - https://portal.msrc.microsoft.com/en-us/security-guidance
 - Reason for Revision: Corrected the Severity entries in the 
   Affected Products table for Microsoft Office 2007 and Microsoft 
   Office 2010 because the Preview Pane is an attack vector for these 
   products. This is an informational change only. Customers who have 
   already successfully installed the updates do not need to take any 
   further action.
 - Originally posted: September 12, 2017  
 - Updated: September 15, 2017
 - CVE Severity Rating: Critical
 - Version: 1.2

CVE-2017-8682

 - Title: CVE-2017-8682 | Win32k Graphics Remote Code Execution       
   Vulnerability
 - https://portal.msrc.microsoft.com/en-us/security-guidance
 - Reason for Revision: Added an FAQ to explain why security update     
   3191848 is not applicable to Office 2010 on Windows Server 2008
   and later versions. This is an informational change only. 
   Customers who have already installed the updates do not need to 
   take any further action.
 - Originally posted: September 12, 2017  
 - Updated: September 14, 2017
 - CVE Severity Rating: Important
 - Version: 1.1

CVE-2017-8695

 - Title: CVE-2017-8695 | Graphics Component Information Disclosure    
   Vulnerability
 - https://portal.msrc.microsoft.com/en-us/security-guidance
 - Reason for Revision: Added an FAQ to explain why security update     
   3191848 is not applicable to Office 2010 on Windows Server 2008
   and later versions. This is an informational change only. 
   Customers who have already installed the updates do not need to 
   take any further action.
 - Originally posted: September 12, 2017  
 - Updated: September 14, 2017
 - CVE Severity Rating: Important
 - Version: 1.1

CVE-2017-8728

 - Title: CVE-2017-8728 | Microsoft PDF Remote Code Execution    
   Vulnerability
 - https://portal.msrc.microsoft.com/en-us/security-guidance
 - Reason for Revision: Updated exploitability assessment for Older    
   Software Release. This is an informational change only.
 - Originally posted: September 12, 2017  
 - Updated: September 14, 2017
 - CVE Severity Rating: Critical
 - Version: 1.1

CVE-2017-8742

 - Title: CVE-2017-8742 | PowerPoint Remote Code Execution
   Vulnerability
 - https://portal.msrc.microsoft.com/en-us/security-guidance
 - Reason for Revision: Corrected the Product to which update 
   3128030 applies in the Affected Products table. Microsoft 
   recommends that customers running PowerPoint Viewer 2010 who 
   have not already installed the update should do so to be protected
   from the vulnerability. Customers who have already successfully 
   installed the update do not need to take any further action.
 - Originally posted: September 12, 2017  
 - Updated: September 115, 2017
 - CVE Severity Rating: Important
 - Version: 1.1



Other Information
=================

Recognize and avoid fraudulent email to Microsoft customers:
=============================================================
If you receive an email message that claims to be distributing 
a Microsoft security update, it is a hoax that may contain 
malware or pointers to malicious websites. Microsoft does 
not distribute security updates via email. 

The Microsoft Security Response Center (MSRC) uses PGP to digitally 
sign all security notifications. However, PGP is not required for 
reading security notifications, reading security bulletins, or 
installing security updates. You can obtain the MSRC public PGP key
at <https://technet.microsoft.com/security/dn753714>.

********************************************************************
THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************

Microsoft respects your privacy. Please read our online Privacy
Statement at <http://go.microsoft.com/fwlink/?LinkId=81184>.

If you would prefer not to receive future technical security
notification alerts by email from Microsoft and its family of
companies please visit the following website to unsubscribe:
<https://profile.microsoft.com/RegSysProfileCenter/subscriptionwizar
d.aspx?wizid=5a2a311b-5189-4c9b-9f1a-d5e913a26c2e&%3blcid=1033>.

These settings will not affect any newsletters you’ve requested or
any mandatory service communications that are considered part of
certain Microsoft services.

For legal Information, see:
<http://www.microsoft.com/info/legalinfo/default.mspx>.

This newsletter was sent by:
Microsoft Corporation
1 Microsoft Way
Redmond, Washington, USA
98052

-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 10.2.0 (Build 1950) - not licensed for commercial use: www.pgp.com
Charset: utf-8

wsFVAwUBWbxbifsCXwi14Wq8AQjqow/+KVltEUVIrhu+VoKUZItOjs+SaXu6O3ES
kz4KNIBUrCB/YMqEgZk+tDnF2f+woserZvdOu2riWrLTW6x9arJmAz67XOF+RV8b
7HtuOvwc6gaEbtEgqScNkXtSKPA1n61gEHyWMB9tykQI4MPJRvXysvN3B+toXHd/
qOD2xZAXfumCd1UKFPh4NaHoiemzgVKo6BZlL66p0IRjYiaQ9fhX0y+0gtHuWj//
nXvHuKTP8MHVFyrZh5Z6F1bEt8T6C7FlCqBa+uq7cTxiDGQ6aLi5H4Lh/5uifoa5
aeOf+JQ6kwkGo5lYmQQ41jr5gFp4rfaSCFTpiaPPdMMXWo/g+GGMQ/X1XETth2Cv
8DJxEl2+nx9r45YNFkJsB/eJznKvDrKR9w/5Z+uJk9bV5vPgV4Scui7j1Oxtwat7
8eXsy1eWdxdZp3JJFHJa6VZ+JNd+/OCHAGgmCZUvSVGwlJqzIP6WV7785k5N6AYK
W+hgReOuCXrr89uFDGS0ZUHk/jJM+GHsS8q+elDpQJrOTqKGzO+wS6NO04VkDEpr
MQcGKIkf9IbVZS9VL1EYCaw+irUeoWUfnuxeRgx5mC2dGxT8h9fcsbV2mVUqYZmv
TnFXaU7gHUPndZPYtwqofcXkg4v9sMi4lel2uTY1ZCo84Mhk9ohiM4LD1pUHrP/m
VlJRQe+A3VE=
=hcz+
-----END PGP SIGNATURE-----


Current thread: