CVE-2016-0010
published 2016-01-13CVE-2016-0010: Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Excel for Mac 2011, PowerPoint for Mac 2011, Word for Mac 2011…
PriorityP351high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
21.61%
97.4th percentile
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Excel for Mac 2011, PowerPoint for Mac 2011, Word for Mac 2011, Excel 2016 for Mac, PowerPoint 2016 for Mac, Word 2016 for Mac, and Word Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel_for_mac | — | — |
| microsoft | excel_for_mac | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | powerpoint_for_mac | — | — |
| microsoft | powerpoint_for_mac | — | — |
| microsoft | word_for_mac | — | — |
| microsoft | word_for_mac | — | — |
| msrc | microsoft_excel_2016_for_mac | — | — |
| msrc | microsoft_excel_for_mac_2011 | — | — |
| msrc | microsoft_office_2007_service_pack_3 | — | — |
| msrc | microsoft_office_2010_service_pack_2 | — | — |
| msrc | microsoft_office_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_office_2013_service_pack_1 | — | — |
| msrc | microsoft_office_2016 | — | — |
| msrc | microsoft_office_word_viewer | — | — |
| msrc | microsoft_word_2016_for_mac | — | — |
| msrc | microsoft_word_for_mac_2011 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2016-0010 is a Microsoft Office RTF file handling heap overflow vulnerability; detection should focus on crafted RTF/Office documents triggering memory corruption in Office parsing components ↗
- →Fortinet IPS signature referenced for a related Office/hlink memory corruption class; monitor for analogous Office RTF heap overflow signatures in IPS platforms ↗
- ·The provided sources do not contain a dedicated deep-dive article for CVE-2016-0010 itself; the Fortinet blog index references a 'Deep Analysis of CVE-2016-0010 - Microsoft Office RTF File Handling Heap Overflow Vulnerability' article but its content was not included in the supplied documents, so no file hashes, specific byte signatures, or PoC-derived IOCs for CVE-2016-0010 could be extracted ↗
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8CRITICAL
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3m2q-3xcm-4xxf: Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Excel for Mac 2011, PowerPoint for Mac 2011, Word for Ma
ghsa_unreviewed·2022-05-14
CVE-2016-0010 [HIGH] CWE-119 GHSA-3m2q-3xcm-4xxf: Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Excel for Mac 2011, PowerPoint for Mac 2011, Word for Ma
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Excel for Mac 2011, PowerPoint for Mac 2011, Word for Mac 2011, Excel 2016 for Mac, PowerPoint 2016 for Mac, Word 2016 for Mac, and Word Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Red Hat
kernel: mm/huge_memory: do not clobber swp_entry_t during THP split
vendor_redhat·2025-10-07·CVSS 5.5
CVE-2022-50517 [MEDIUM] CWE-826 kernel: mm/huge_memory: do not clobber swp_entry_t during THP split
kernel: mm/huge_memory: do not clobber swp_entry_t during THP split
In the Linux kernel, the following vulnerability has been resolved:
mm/huge_memory: do not clobber swp_entry_t during THP split
The following has been observed when running stressng mmap since commit
b653db77350c ("mm: Clear page->private when splitting or migrating a page")
watchdog: BUG: soft lockup - CPU#75 stuck for 26s! [stress-ng:9546]
CPU: 75 PID: 9546 Comm: stress-ng Tainted: G E 6.0.0-revert-b653db77-fix+ #29 0357d79b60fb09775f678e4f3f64ef0579ad1374
Hardware name: SGI.COM C2112-4GP3/X10DRT-P-Series, BIOS 2.0a 05/09/2016
RIP: 0010:xas_descend+0x28/0x80
Code: cc cc 0f b6 0e 48 8b 57 08 48 d3 ea 83 e2 3f 89 d0 48 83 c0 04 48 8b 44 c6 08 48 89 77 18 48 89 c1 83 e1 03 48 83 f9 02 75 08 3d fd 00 00 00 76 08 88 57 12 c3
VMware
VMware product updates address multiple security issues
vendor_vmware·2016-08-04·CVSS 7.8
CVE-2016-5330 [HIGH] VMware product updates address multiple security issues
VMSA-2016-0010: VMware product updates address multiple security issues
a. DLL hijacking issue in Windows-based VMware Tools A DLL hijacking vulnerability is present in the VMware Tools "Shared Folders" (HGFS) feature running on Microsoft Windows. Exploitation of this issue may lead to arbitrary code execution with the privileges of the victim. In order to exploit this issue, the attacker would need write access to a network share and they would need to entice the local user into opening their document. There are no known workarounds for this issue. VMware would like to thank Yorick Koster of Securify B.V. for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2016-5330 to this issue. Column 5 of the following table
Microsoft
CVE-2016-0010: Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No
vendor_msrc·2016-01-12·CVSS 7.8
CVE-2016-0010 [HIGH] CVE-2016-0010: Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No
No detection rules found.
Fortinet
Phishing Campaign Targeting Mobile Users in India Using India Post Lures | FortiGuard Labs
blogs_fortinet·2024-07-25
Phishing Campaign Targeting Mobile Users in India Using India Post Lures | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Phishing Campaign Targeting Mobile Users in India Using India Post Lures
Domain Names Impersonating India Post
IP Address Analysis
Fraudulent Website Analysis
Modus-Operandi
Recommendations to Mitigate Phishing Scams
Conclusion
Fortinet Protections
IOCs
Sender Email Address
Domain Names
By Bablu Kumar | July 25, 2024
Impacted Users: iPhone users in India
Impact: Possible financial loss; stolen information can be used for future attacks
Severity Level: Medium
The FortiGuard Labs Threat Research team recently observed a number of social media posts commenting on a fraud campaign targeting India Post users. India Post is India’s government-operated postal system. It is part of the Ministry of Communications and has a vast network of over 150,000 post offices
Fortinet
LokiBot Campaign Targets Microsoft Office Document Using Vulnerabilities and Macros | FortiGuard Labs
blogs_fortinet·2023-07-12·CVSS 8.8
CVE-2021-40444 [HIGH] LokiBot Campaign Targets Microsoft Office Document Using Vulnerabilities and Macros | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
LokiBot Campaign Targets Microsoft Office Document Using Vulnerabilities and Macros
By Cara Lin | July 12, 2023
Affected platforms: Microsoft Windows
Impacted parties: Windows users
Impact: Control and collect sensitive information from a victim’s device
Severity level: Critical
In a recent FortiGuard Labs investigation, we came across several malicious Microsoft Office documents designed to exploit known vulnerabilities. Specifically, CVE-2021-40444 and CVE-2022-30190 are remote code execution vulnerabilities. Exploiting these vulnerabilities allowed the attackers to embed malicious macros within Microsoft documents that, when executed, dropped the LokiBot malware onto the victim's system. LokiBot, also known as Loki PWS, has been a well-known informati
Fortinet
Are Internet Macros Dead or Alive? | FortiGuard labs
blogs_fortinet·2023-04-12
Are Internet Macros Dead or Alive? | FortiGuard labs
FORTIGUARD LABS THREAT RESEARCH
Are Internet Macros Dead or Alive?
By Hossein Jazi | April 12, 2023
Affected platforms: Windows
Impacted parties: Windows Users
Impact: Potential to deploy additional malware for additional purposes
Severity level: Medium
In early February of 2022, Microsoft announced that Internet Macros would be blocked by default to improve the security of Microsoft Office. According to their blog published in late Feb 2023, this change began rolling out in some update channels in April 2022. Other channels followed in July and October 2022, with the final rollout in January 2023.
Office uses a specific algorithm to determine whether to run macros in files from the Internet. The process starts by checking the file attribute. If it has a Mark of the Web (MOTW) attribu
Fortinet
Leveraging Microsoft Office Documents to Deliver Agent Tesla and njRat | FortiGuard Labs
blogs_fortinet·2022-10-03
Leveraging Microsoft Office Documents to Deliver Agent Tesla and njRat | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Leveraging Microsoft Office Documents to Deliver Agent Tesla and njRat
By Cara Lin | October 03, 2022
We recently found some malicious Microsoft Office documents that attempted to leverage legitimate websites—MediaFire and Blogger—to execute a shell script and then dropped two malware variants of Agent Tesla and njRat. Agent Tesla is a well-known spyware, first discovered in 2014, which can steal personal data from web browsers, mail clients, and FTP servers, collect screenshots and videos, and capture clipboard data. njRat (also known as Bladabindi) is a remote agent Trojan first discovered in 2013 that is capable of remotely controlling a victim’s device to log keystrokes, access the camera, steal credentials stored in browsers, upload/download files, ma
Fortinet
The Curveball Vulnerability Research Analysis | FortiGuard Labs
blogs_fortinet·2020-01-21
The Curveball Vulnerability Research Analysis | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
The Curveball Vulnerability Research Analysis
By Udi Yavo | January 21, 2020
Introduction to Curveball Exploits
On patch Tuesday for January 2020, Microsoft disclosed a critical vulnerability that had been discovered by the NSA, that has been dubbed CurveBall or ChainOfFools by the security research community. This vulnerability affects Windows 10, Windows 2016, and the 2019 version of the crypt32.dll that implements Windows’ CryptoAPI.
This vulnerability can be exploited by a malicious actor to spoof certificates in a way that will trick any software that leverages Windows CryptoAPI for signature validation into believing it is legitimate. For example, ransomware authors can trick Windows into believing that their samples have been signed by Microsoft.
Fortinet
Multiple D-Link Routers Found Vulnerable To Unauthenticated Remote Code Execution
blogs_fortinet·2019-10-03·CVSS 9.8
CVE-2019-16920 [CRITICAL] Multiple D-Link Routers Found Vulnerable To Unauthenticated Remote Code Execution
FORTIGUARD LABS THREAT RESEARCH
Multiple D-Link Routers Found Vulnerable To Unauthenticated Remote Code Execution
By Thanh Nguyen Nguyen | October 03, 2019
Introduction
In September 2019, Fortinet's FortiGuard Labs discovered and reported an unauthenticated command injection vulnerability (FG-VD-19-117/CVE-2019-16920) in D-Link products that could lead to Remote Code Execution (RCE) upon successful exploitation. We rated this as a critical issue since the vulnerability can be triggered remotely without authentication.
Based on our findings, the vulnerability was found in latest firmware of the following D-Link products:
DIR-655
DIR-866L
DIR-652
DHP-1565
At the time of the writing of this advisory, these products are at End of Life (EOL) support, which means the vendor will not provide
Fortinet
Fortinet Advisory on New Spectre and Meltdown Vulnerabilities
blogs_fortinet·2018-01-04·CVSS 5.6
[MEDIUM] Fortinet Advisory on New Spectre and Meltdown Vulnerabilities
FORTINET NEWS & UPDATES
Fortinet Advisory on New Spectre and Meltdown Vulnerabilities
By Fortinet | January 04, 2018
Earlier this week, it was announced that researchers uncovered two new side channel attacks that exploit newly discovered vulnerabilities found in most CPU processors, including those from Intel, AMD, and ARM. These vulnerabilities allow malicious userspace processes to read kernel memory, thereby potentially causing sensitive kernel information to leak. These vulnerabilities are known as Meltdown and Spectre.
Fortinet’s PSIRT team is actively conducting an extensive review to determine the potential impact to Fortinet solutions, and at this time has classified the risk to Fortinet products as low. Meltdown and Spectre are "Information Disclosure" and "Privilege Escalatio
Fortinet
Rehashed RAT Used in APT Campaign Against Vietnamese Organizations
blogs_fortinet·2017-09-05·CVSS 8.8
CVE-2012-0158 [HIGH] Rehashed RAT Used in APT Campaign Against Vietnamese Organizations
FORTIGUARD LABS THREAT RESEARCH
Rehashed RAT Used in APT Campaign Against Vietnamese Organizations
By Jasper Manuel and Artem Semenchenko | September 05, 2017
Recently, FortiGuard Labs came across several malicious documents that exploit the vulnerability CVE-2012-0158. To evade suspicion from the victim, these RTF files drop decoy documents containing politically themed texts about a variety of Vietnamese government-related information. It was believed in a recent report that the hacking campaign where these documents were used was led by the Chinese hacking group 1937CN. The link to the group was found through malicious domains used as command and control servers by the attacker. In this blog, we will delve into the malware used in this campaign and will try to provide more clues as to
Fortinet
In-Depth Look at New Variant of MONSOON APT Backdoor, Part 1
blogs_fortinet·2017-04-05·CVSS 7.8
CVE-2015-1641 [HIGH] In-Depth Look at New Variant of MONSOON APT Backdoor, Part 1
FORTIGUARD LABS THREAT RESEARCH
In-Depth Look at New Variant of MONSOON APT Backdoor, Part 1
By Jasper Manuel and Artem Semenchenko | April 05, 2017
Three weeks ago, FortiGuard Labs, along with @_ddoxer (Roland de la Paz), using VirusTotal Intelligence queries, spotted a document with the politically themed file name “Senate_panel.doc”. This malicious RTF file takes advantage of the vulnerability CVE-2015-1641. Upon successful exploitation, it drops a malware in the %appdata%\Microsoft directory. To evade suspicion by the victim, it also drops a decoy document which shows the symbol of the Ministry of Foreign Affairs of Pakistan on the first page, but on the next pages shows an article about the Senate of Pakistan.
Decoy document
As we were unable to identify which malware family the d
Fortinet
Analysis of PHPMailer Remote Code Execution Vulnerability (CVE-2016-10033)
blogs_fortinet·2017-01-05·CVSS 9.8
CVE-2016-10033 [CRITICAL] Analysis of PHPMailer Remote Code Execution Vulnerability (CVE-2016-10033)
FORTIGUARD LABS THREAT RESEARCH
Analysis of PHPMailer Remote Code Execution Vulnerability (CVE-2016-10033)
By Zhouyuan Yang | January 05, 2017
PHP is an open source, general-purpose scripting language used for web development that can also be embedded into HTML. It has over 9 million users, and is used by many popular tools, such as WordPress, Drupal, Joomla!, and so on. This week, a high-level security update was released to fix a remote code execution vulnerability (CVE-2016-10033) in PHPMailer, which is an open source PHP library for sending emails from PHP websites.
This critical vulnerability is caused by class.phpmailer.php incorrectly processing user requests. As a result, remote attackers are able to execute code on vulnerable servers.
This vulnerability affects PHPMailer versi
Fortinet
Analysis of OpenSSL ChaCha20-Poly1305 Heap Buffer Overflow (CVE-2016-7054)
blogs_fortinet·2016-11-23·CVSS 7.5
CVE-2016-7054 [HIGH] Analysis of OpenSSL ChaCha20-Poly1305 Heap Buffer Overflow (CVE-2016-7054)
FORTIGUARD LABS THREAT RESEARCH
Analysis of OpenSSL ChaCha20-Poly1305 Heap Buffer Overflow (CVE-2016-7054)
By Dehui Yin | November 23, 2016
AHigh-Severity Heap Buffer Overflow vulnerability was recently fixed in a patch by Openssl Project. This vulnerability affects the remote SSL servers that support the ChaCha20-Poly1305 cipher suite, and can be exploited to crash the SSL service.
This High-Severity Heap Buffer Overflow vulnerability (CVE-2016-7054) is caused by an error when the ChaCha20-Poly1305 cipher suite is decrypting large amounts of application data. We will examine the root cause of this vulnerability in this post.
The ChaCha20-Poly1305 cipher suite is a new form of encryption which can improve mobile performance. It was introduced as a new feature in OpenSSL 1.1.x, and is s
Fortinet
When Half the Internet Goes Down Due to a Cyber-Assault on DNS Infrastructure
blogs_fortinet·2016-10-21
When Half the Internet Goes Down Due to a Cyber-Assault on DNS Infrastructure
INDUSTRY TRENDS & INSIGHTS
When Half the Internet Goes Down Due to a Cyber-Assault on DNS Infrastructure
By Hemant Jain | October 21, 2016
On Oct 21, 2016, yet another cyber assault happened on a large DNS provider's infrastructure, bringing down websites and services on the east coast of the United States. While it is easy to launch these attacks, the solutions available in the market have not kept pace. FortiDDoS is the only hardware logic solution in the market today that easily distinguishes between attack traffic and legitimate traffic at high rates and keep services up during such attacks.
The DDoS attack on the DNS infrastructure of Dyn, a major DNS provider, made Spotify, Twitter, Amazon and many other websites unreachable.
Why is it easy to bring down DNS infrastructure?
It i
Fortinet
CryptXXX Ransomware Emerges For a Slice of the Pie
blogs_fortinet·2016-08-22
CryptXXX Ransomware Emerges For a Slice of the Pie
FORTIGUARD LABS THREAT RESEARCH
CryptXXX Ransomware Emerges For a Slice of the Pie
By Donna Wang and He Xu | August 22, 2016
Introduction
Recently, a new variant of the ransomware family named CryptXXX has begun circulating around the web. Fortiguard Research Lab has discovered several new variants during the life of this family of attacks. In this blog we will discuss a particular variant, which arrived in the form of an executable (.exe), as opposed to previous variants that were based around dynamic-link library (.dll) files.
The unpacked binary of this variant is smaller than its peer ransom families. However, don’t underestimate it. Its sleek executable, classic ransomware behavior, and forthright approach in binary communication is just as effective in achieving the goal of infect
Fortinet
Analysis of CVE-2016-4203 - Adobe Acrobat and Reader CoolType Handling Heap Overflow Vulnerability
blogs_fortinet·2016-07-20·CVSS 9.8
CVE-2016-4203 [CRITICAL] Analysis of CVE-2016-4203 - Adobe Acrobat and Reader CoolType Handling Heap Overflow Vulnerability
FORTIGUARD LABS THREAT RESEARCH
Analysis of CVE-2016-4203 - Adobe Acrobat and Reader CoolType Handling Heap Overflow Vulnerability
By Kai Lu | July 20, 2016
Summary
Recently, Adobe patched some security vulnerabilities in Adobe Acrobat and Reader. One of them is a heap buffer overflow vulnerability (CVE-2016-4203) I recently discovered. In this blog, we want to share our analysis of this vulnerability.
Proof of Concept
This vulnerability can be reproduced by opening the PoC file “poc_minimized.pdf” with Adobe Reader DC. When opened, AcroRd32.exe crashes, and the crash information is shown below:
(8de0.6bc4): Access violation - code c0000005 (first chance)
First chance exceptions are reported before any exception handling.
This exception may be expected and handled.
eax=097eeeed ebx
Fortinet
Analysis of CVE-2016-2414 - Out-of-Bound Write Denial of Service Vulnerability in Android Minikin Library
blogs_fortinet·2016-04-13·CVSS 6.2
CVE-2016-2414 [MEDIUM] Analysis of CVE-2016-2414 - Out-of-Bound Write Denial of Service Vulnerability in Android Minikin Library
FORTIGUARD LABS THREAT RESEARCH
Analysis of CVE-2016-2414 - Out-of-Bound Write Denial of Service Vulnerability in Android Minikin Library
By Kai Lu | April 13, 2016
Google fixed a denial of service vulnerability in Minikin library (CVE-2016-2414) with the Android patches of this month. I reported this vulnerability to Google in early March, 2016 and Google confirmed it was a duplicated report of bug 26413177 which had been reported by another researcher in November, 2015.
In this blog, we will provide an in-depth analysis of this vulnerability. It exists because the Minikin library fails to parse .TTF font files correctly. As a result, it could allow a local attacker to temporarily block access to an affected Android device. The attacker could have an untrusted font file loaded, causing
Fortinet
Analysis of CVE-2016-0059 - Microsoft IE Information Disclosure Vulnerability Discovered by Fortinet
blogs_fortinet·2016-02-19·CVSS 7.8
CVE-2016-0059 [HIGH] Analysis of CVE-2016-0059 - Microsoft IE Information Disclosure Vulnerability Discovered by Fortinet
FORTIGUARD LABS THREAT RESEARCH
Analysis of CVE-2016-0059 - Microsoft IE Information Disclosure Vulnerability Discovered by Fortinet
By Kai Lu | February 19, 2016
Summary
This month Microsoft patched two vulnerabilities which were discovered and reported by me, one is an information disclosure vulnerability in Internet Explorer (IE) (CVE-2016-0059 in MS16-009), the other is a memory corruption vulnerability in Microsoft Office (CVE-2016-0055 in MS16-015). In this blog, we will provide in-depth analysis of CVE-2016-0059. The vulnerability exists because Microsoft Hyperlink Object Library improperly discloses the contents of its memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit the vulnerability,
Fortinet
Deep Analysis of CVE-2016-0010 - Microsoft Office RTF File Handling Heap Overflow Vulnerability
blogs_fortinet·2016-01-20·CVSS 7.8
CVE-2016-0010 [HIGH] Deep Analysis of CVE-2016-0010 - Microsoft Office RTF File Handling Heap Overflow Vulnerability
FORTIGUARD LABS THREAT RESEARCH
Deep Analysis of CVE-2016-0010 - Microsoft Office RTF File Handling Heap Overflow Vulnerability
By Kai Lu | January 20, 2016
Summary
On the patch Tuesday of this month, Microsoft patched 3 Office vulnerabilities in MS16-004. The vulnerability CVE-2016-0010 was discovered by myself and Fortinet's threat research team at the FortiGuard Labs. It is a heap overflow vulnerability in Microsoft Office because it fails to parse RTF documents correctly. Successful exploitation of this vulnerability could allow malicious users to create remote code execution scenarios. The underlying problem involves a typical heap overflow caused by a user-supplied value which is copied into a buffer allocated based on a user-supplied length. In this blog, I want to analyze the ro
Talos
Microsoft Patch Tuesday - January 2016
blogs_talos·2016-01-12·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - January 2016
The first Patch Tuesday of 2016 has arrived. Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release is relatively light with nine bulletins addressing 25 vulnerabilities. Six bulletins are rated critical and address vulnerabilities in Edge, Internet Explorer, JScript/VBScript, Office, Silverlight, and Windows. The remaining three bulletins are rated important and address vulnerabilities in Exchange and several parts of Windows.
### Bulletins Rated Critical Microsoft bulletins MS16-001 through MS16-0006 are rated as critical in this month's release.
MS16-001 and MS16-002 are this month's Internet Explorer and Edge security bulletin respectively. In total, four vulnerabilities were addre
Qualys
Update: Patch Tuesday January 2016 | Qualys
blogs_qualys·2016-01-12·CVSS 8.8
[HIGH] Update: Patch Tuesday January 2016 | Qualys
Update : Kaspersky who is credited with finding MS16-006 ,the critical Silverlight vulnerability just published their story on how the bug was found. Very interesting, has to do with the Hacking Team breach and coding "standards" – take a look at their blog post for more info. They also made clear that this vulnerability is under attack in the wild and that we are looking at a true 0-day here. This changes our priorities – we now put MS16-006 at the top of our list. Take a look at your installations, see if you have Silverlight installed and address the flaw as soon as possible.
Original : The first Patch Tuesday of 2016 turns out to be low in numbers, but broad and packing quite a punch: six of the nine bulletins are rated critical, including the Windows Kernel and Office bulletins. In a
Qualys
Update: Patch Tuesday January 2016 | Qualys
blogs_qualys·2016-01-12
Update: Patch Tuesday January 2016 | Qualys
Update: Kaspersky who is credited with finding MS16-006,the critical Silverlight vulnerability just published their story on how the bug was found. Very interesting, has to do with the Hacking Team breach and coding "standards" – take a look at their blog post for more info. They also made clear that this vulnerability is under attack in the wild and that we are looking at a true 0-day here. This changes our priorities – we now put MS16-006 at the top of our list. Take a look at your installations, see if you have Silverlight installed and address the flaw as soon as possible.
Original: The first Patch Tuesday of 2016 turns out to be low in numbers, but broad and packing quite a punch: six of the nine bulletins are rated critical, including the Windows Kernel and Office bulletins. In addi
Talos
Microsoft Patch Tuesday - January 2016
blogs_talos·2016-01-12·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - January 2016
## Microsoft Patch Tuesday - January 2016
The first Patch Tuesday of 2016 has arrived. Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release is relatively light with nine bulletins addressing 25 vulnerabilities. Six bulletins are rated critical and address vulnerabilities in Edge, Internet Explorer, JScript/VBScript, Office, Silverlight, and Windows. The remaining three bulletins are rated important and address vulnerabilities in Exchange and several parts of Windows.
## Bulletins Rated Critical Microsoft bulletins MS16-001 through MS16-0006 are rated as critical in this month's release.
MS16-001 and MS16-002 are this month's Internet Explorer and Edge security bulletin respectively.
2016-01-13
Published