August Microsoft Bulletin
Microsoft Security Bulletin MS12-043 Critical
Version: 2.0
This security update resolves a publicly disclosed vulnerability in Microsoft XML Core Services. The vulnerability could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker would have no way to force users to visit such a website. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes the user to the attacker's website.
This security update is rated Critical for Microsoft XML Core Services 3.0, 4.0, and 6.0 on all supported editions of Windows XP, Windows Vista, and Windows 7 and is rated Moderate on all supported editions of Windows Server 2003, Windows Server 2008, and Windows Server 2008 R2; it is also rated Critical for Microsoft XML Core Services 5.0 for all supported editions of Microsoft Office 2003, Microsoft Office 2007, Microsoft Office Word Viewer, Microsoft Office Compatibility Pack, Microsoft Expression Web, Microsoft Office SharePoint Server 2007, and Microsoft Groove Server 2007. For more information, see the subsection, Affected and Non-Affected Software, in this section.
The security update addresses the vulnerability by modifying the way that MSXML initializes objects in memory before use. For more information about the vulnerability, see the Frequently Asked Questions (FAQ) subsection for the specific vulnerability entry under the next section, Vulnerability Information.
This security update also addresses the vulnerability first described in Microsoft Security Advisory 2719615.
Recommendation. The majority of customers have automatic updating enabled and will not need to take any action because this security update will be downloaded and installed automatically. Customers who have not enabled automatic updating need to check for updates and install this update manually. For information about specific configuration options in automatic updating, see Microsoft Knowledge Base Article 294871.
For administrators and enterprise installations, or end users who want to install this security update manually, Microsoft recommends that customers apply the update immediately using update management software, or by checking for updates using the Microsoft Update service.
See also the section, Detection and Deployment Tools and Guidance, later in this bulletin.
Known Issues. None
Got to http://technet.microsoft.com/en-us/security/bulletin/ms12-043 for a list of affected and non-affected software.
August, 14 2012
- 06/17/2016 - Microsoft Security Bulletin Summary for June 2016
- 06/15/2016 - Microsoft Security Bulletin Releases
- 04/22/2016 - Issued: April 19, 2016
- 02/17/2016 - Microsoft Security Bulletin Releases
- 02/10/2016 - Microsoft Security Bulletin Releases
- 01/18/2016 - Microsoft Security Bulletin Summary for January 2016
- 12/14/2015 - Microsoft Security Bulletin Releases
- 10/15/2015 - Microsoft Security Bulletin Summary for October 2015
- 05/14/2015 - Microsoft Security Bulletin Releases
- 04/15/2015 - Microsoft Security Bulletin Summary for April 2015
- 03/10/2015 - Microsoft Security Bulletin Summary for March 2015
- 02/12/2015 - Microsoft Security Bulletin Releases
- 01/19/2015 - January 13, 2015
- 01/14/2015 - January 13, 2015
- 12/31/2014 - Beware of Scammers
- 12/09/2014 - Microsoft Security Bulletin Releases
- 12/09/2014 - Microsoft Security Bulletin Summary for December 2014
- 11/18/2014 - Microsoft Security Bulletin Releases
- 11/13/2014 - Microsoft Security Bulletin Summary for November 2014
- 10/16/2014 - Microsoft Security Bulletin Summary for October 2014
- 10/13/2014 - Microsoft Security Bulletin Advance Notification for October 2014
- 09/26/2014 - Microsoft Security Bulletin Re-Releases
- 09/16/2014 - Title: Microsoft Security Bulletin Re-Releases
- 08/08/2014 - Russian Crime Ring Steals Billions of Passwords, Online Records
- 07/23/2014 - Integrated Digital Solutions receives 2013 Texas Excellence Award
- 07/08/2014 - Microsoft Security Bulletin Summary
- 06/30/2014 - Microsoft Security Notifications
- 06/11/2014 - Microsoft Security Bulletin Summary for June 2014
- 05/16/2014 - FCC vote on 'net neutrality' will kick off long battle
- 04/30/2014 - What's the cost of FCC proposal?
- 04/01/2014 - Integrated Digital Solutions receives 2013 Texas Excellence Award
- 02/25/2014 - Beware of this Fake Email for Apple iphone users
- 01/16/2014 - Microsoft Security Bulletin Summary for January 2014
- 12/11/2013 - Issued: December 10, 2013
- 12/10/2013 - New Virus Email
- 11/13/2013 - Issued: November 12, 2013
- 09/25/2013 - This email is a virus
- 09/10/2013 - Microsoft Security Bulletin Summary for September 2013
- 08/28/2013 - Issued: August 27, 2013
- 08/20/2013 - Issued: August 19, 2013
- 08/15/2013 - Microsoft Security Bulletin Re-Releases
- 07/09/2013 - Microsoft Security Bulletin Summary for July 2013
- 07/08/2013 - Beware! Scammers are on the Loose
- 07/05/2013 - What to do when you get the Ukash Virus
- 06/26/2013 - Microsoft Security Bulletin Re-Releases
- 06/11/2013 - Microsoft Security Bulletin Summary for June 2013
- 05/29/2013 - Web-savvy thieves getting creative to commit fraud
- 05/14/2013 - Issued: May 14, 2013
- 04/24/2013 - How to Protect Yourself on Public Wi-Fi
- 04/23/2013 - Summary
- 04/08/2013 - New Email scam alert!
- 03/12/2013 - Microsoft Security Bulletin
- 03/04/2013 - Advice 13 Things Facebook Won't Tell You
- 01/29/2013 - Advice 13 Things Facebook Won't Tell you
- 12/10/2012 - Cyber Crime - Big Business for Attackers, Big Costs for Vicims
- 11/19/2012 - LinkedIns Money Machine
- 09/26/2012 - Emails to Watch For!
- 09/25/2012 - IDS Survey
- 09/03/2012 - 2 SCAMS TO BEWARE OF!
- 08/14/2012 - Microsoft Security Bulletin MS12-043 Critical
- 07/10/2012 - Microsoft Security Bulletin Summary for July 2012
- 07/05/2012 - Malware may knock thousands off Internet on Monday
- 06/26/2012 - Tips and Tricks to Stay Out of the Spam Folder
- 06/18/2012 - Microsoft issued a patch to address the vulnerability in IE, but the flaw triggering the warning message was not addressed.
- 06/13/2012 - 7 Questions
- 05/30/2012 - 5 Tips for Using Facebook on Firefox
- 05/14/2012 - Do not open this, there is multiple viruses in the veiw statement.
- 04/16/2012 - Microsoft patches critical Windows zero-day bug that hackers are now exploiting
- 10/10/2011 - Virus Protections
- 06/10/2011 - Success begins with one new key element... an idea!