Qualys Vulnerability R&D Lab has released new vulnerability checks in the Enterprise TruRisk Platform to protect organizations against 76 vulnerabilities that were fixed in 14 bulletins announced today by Microsoft. Customers can immediately audit their networks for these and other new vulnerabilities by accessing their Qualys subscription. Visit Qualys Security Blog to prioritize remediation.
Non-Qualys customers can audit their network for these and other vulnerabilities by signing up for a Qualys Free Trial, or by trying Qualys Community Edition.
Microsoft has released 14 security bulletins to fix newly discovered flaws in their software. Qualys has released the following checks for these new vulnerabilities:
The update addresses the vulnerabilities by correcting how Internet Explorer handles:
zone and integrity settings.
cross-origin content.
objects in memory.
.URL files.
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS16-104 Windows 10 Version 1511 for 32-bit Systems
MS16-104 Windows 10 Version 1511 for x64-based Systems
MS16-104 Windows 10 Version 1607 for 32-bit Systems
MS16-104 Windows 10 Version 1607 for x64-based Systems
MS16-104 Windows 10 for 32-bit Systems
MS16-104 Windows 10 for x64-based Systems
MS16-104 Windows 7 for 32-bit Systems Service Pack 1(Internet Explorer 11)
MS16-104 Windows 7 for x64-based Systems Service Pack 1(Internet Explorer 11)
MS16-104 Windows 8.1 for 32-bit Systems(Internet Explorer 11)
MS16-104 Windows 8.1 for x64-based Systems(Internet Explorer 11)
MS16-104 Windows Server 2008 R2 for x64-based Systems Service Pack 1(Internet Explorer 11)
MS16-104 Windows Server 2008 for 32-bit Systems Service Pack 2(Internet Explorer 9)
MS16-104 Windows Server 2008 for x64-based Systems Service Pack 2(Internet Explorer 9)
MS16-104 Windows Server 2012(Internet Explorer 10)
MS16-104 Windows Server 2012 R2(Internet Explorer 11)
MS16-104 Windows Vista Service Pack 2(Internet Explorer 9)
MS16-104 Windows Vista x64 Edition Service Pack 2(Internet Explorer 9)
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS16-105 Windows 10 Version 1511 for 32-bit Systems
MS16-105 Windows 10 Version 1511 for x64-based Systems
MS16-105 Windows 10 Version 1607 for 32-bit Systems
MS16-105 Windows 10 Version 1607 for x64-based Systems
MS16-105 Windows 10 for 32-bit Systems
MS16-105 Windows 10 for x64-based Systems
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS16-106 Windows 10 Version 1511 for 32-bit Systems
MS16-106 Windows 10 Version 1511 for x64-based Systems
MS16-106 Windows 10 Version 1607 for 32-bit Systems
MS16-106 Windows 10 Version 1607 for x64-based Systems
MS16-106 Windows 10 for 32-bit Systems
MS16-106 Windows 10 for x64-based Systems
MS16-106 Windows 7 for 32-bit Systems Service Pack 1
MS16-106 Windows 7 for x64-based Systems Service Pack 1
MS16-106 Windows 8.1 for 32-bit Systems
MS16-106 Windows 8.1 for x64-based Systems
MS16-106 Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
MS16-106 Windows Server 2008 R2 for x64-based Systems Service Pack 1
MS16-106 Windows Server 2008 for 32-bit Systems Service Pack 2
MS16-106 Windows Server 2008 for Itanium-based Systems Service Pack 2
MS16-106 Windows Server 2008 for x64-based Systems Service Pack 2
MS16-106 Windows Server 2012
MS16-106 Windows Server 2012 R2
MS16-106 Windows Vista Service Pack 2
MS16-106 Windows Vista x64 Edition Service Pack 2
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS16-107 Excel Automation Services on Microsoft SharePoint Server 2013 Service Pack 1
MS16-107 Excel Services on Microsoft SharePoint Server 2007 Service Pack 3 (32-bit editions)
MS16-107 Excel Services on Microsoft SharePoint Server 2007 Service Pack 3 (64-bit editions)
MS16-107 Excel Services on Microsoft SharePoint Server 2010 Service Pack 2
MS16-107 Microsoft Excel 2007 Service Pack 3
MS16-107 Microsoft Excel 2010 Service Pack 2 (32-bit editions)
MS16-107 Microsoft Excel 2010 Service Pack 2 (64-bit editions)
MS16-107 Microsoft Excel 2013 Service Pack 1 (32-bit editions)
MS16-107 Microsoft Excel 2013 Service Pack 1 (64-bit editions)
MS16-107 Microsoft Excel 2016 (32-bit edition)
MS16-107 Microsoft Excel 2016 (64-bit edition)
MS16-107 Microsoft Excel 2016 for Mac
MS16-107 Microsoft Excel Viewer
MS16-107 Microsoft Office 2007 Service Pack 3
MS16-107 Microsoft Office 2010 Service Pack 2 (32-bit editions)
MS16-107 Microsoft Office 2010 Service Pack 2 (32-bit editions)
MS16-107 Microsoft Office 2010 Service Pack 2 (64-bit editions)
MS16-107 Microsoft Office 2010 Service Pack 2 (64-bit editions)
MS16-107 Microsoft Office 2013 Service Pack 1 (32-bit editions)
MS16-107 Microsoft Office 2013 Service Pack 1 (64-bit editions)
MS16-107 Microsoft Office 2016 (32-bit edition)
MS16-107 Microsoft Office 2016 (64-bit edition)
MS16-107 Microsoft Office Compatibility Pack Service Pack 3
MS16-107 Microsoft Office Compatibility Pack Service Pack 3
MS16-107 Microsoft Office Web Apps 2010 Service Pack 2
MS16-107 Microsoft Office Web Apps Server 2013 Service Pack 1
MS16-107 Microsoft Outlook 2007
MS16-107 Microsoft Outlook 2010 Service Pack 2 (32-bit editions)
MS16-107 Microsoft Outlook 2010 Service Pack 2 (64-bit editions)
MS16-107 Microsoft Outlook 2013 Service Pack 1 (32-bit editions)
MS16-107 Microsoft Outlook 2013 Service Pack 1 (64-bit editions)
MS16-107 Microsoft Outlook 2016 (32-bit edition)
MS16-107 Microsoft Outlook 2016 (64-bit edition)
MS16-107 Microsoft Outlook 2016 for Mac
MS16-107 Microsoft PowerPoint 2007 Service Pack 3
MS16-107 Microsoft PowerPoint 2010 Service Pack 2 (32-bit editions)
MS16-107 Microsoft PowerPoint 2010 Service Pack 2 (64-bit editions)
MS16-107 Microsoft PowerPoint 2013 Service Pack 1 (32-bit editions)
MS16-107 Microsoft PowerPoint 2013 Service Pack 1 (64-bit editions)
MS16-107 Microsoft PowerPoint 2016 for Mac
MS16-107 Microsoft PowerPoint Viewer
MS16-107 Microsoft SharePoint Server 2013 Service Pack 1
MS16-107 Microsoft Word 2016 for Mac
MS16-107 Microsoft Word Viewer
MS16-107 Microsoft Word for Mac 2011
MS16-107 Office Online Server
MS16-107 Word Automation Services on Microsoft SharePoint Server 2010 Service Pack 2
MS16-107 Word Automation Services on Microsoft SharePoint Server 2013 Service Pack 1
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS16-108 Microsoft Exchange Server 2007 Service Pack 3
MS16-108 Microsoft Exchange Server 2010 Service Pack 3
MS16-108 Microsoft Exchange Server 2013 Cumulative Update 12
MS16-108 Microsoft Exchange Server 2013 Cumulative Update 13
MS16-108 Microsoft Exchange Server 2013 Service Pack 1
MS16-108 Microsoft Exchange Server 2016 Cumulative Update 1
MS16-108 Microsoft Exchange Server 2016 Cumulative Update 2
The update addresses the vulnerability by correcting how Microsoft Silverlight allocates memory for inserting and appending strings in StringBuilder.
This security update is rated Important for Microsoft Silverlight 5 and Microsoft Silverlight 5 Developer Runtime when installed on Mac or all supported releases of Microsoft Windows.
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS16-109 Microsoft Silverlight 5
MS16-109 Microsoft Silverlight 5 Developer Runtime
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS16-110 Windows 10 Version 1511 for 32-bit Systems
MS16-110 Windows 10 Version 1511 for x64-based Systems
MS16-110 Windows 10 Version 1607 for 32-bit Systems
MS16-110 Windows 10 Version 1607 for x64-based Systems
MS16-110 Windows 10 for 32-bit Systems
MS16-110 Windows 10 for x64-based Systems
MS16-110 Windows 7 for 32-bit Systems Service Pack 1
MS16-110 Windows 7 for x64-based Systems Service Pack 1
MS16-110 Windows 8.1 for 32-bit Systems
MS16-110 Windows 8.1 for 32-bit Systems
MS16-110 Windows 8.1 for x64-based Systems
MS16-110 Windows 8.1 for x64-based Systems
MS16-110 Windows Server 2008 R2 for x64-based Systems Service Pack 1
MS16-110 Windows Server 2008 for 32-bit Systems Service Pack 2
MS16-110 Windows Server 2008 for x64-based Systems Service Pack 2
MS16-110 Windows Server 2012
MS16-110 Windows Server 2012 R2
MS16-110 Windows Vista Service Pack 2
MS16-110 Windows Vista x64 Edition Service Pack 2
Microsoft released a security update that addresses the vulnerabilities by correcting how Windows handles session objects and properly enforcing Windows Kernel API permissions.
This security update is rated Important for all supported releases of Microsoft Windows.
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS16-111 Windows 10 Version 1511 x32
MS16-111 Windows 10 Version 1511 x64
MS16-111 Windows 10 Version 1607 x32
MS16-111 Windows 10 Version 1607 x64
MS16-111 Windows 10 Version 1703 for x64-based Systems
MS16-111 Windows 10 Version 1703 for x86-based Systems
MS16-111 Windows 10 x32
MS16-111 Windows 10 x64
MS16-111 Windows 2008 x32 Service Pack 2
MS16-111 Windows 2008 x64 Service Pack 2
MS16-111 Windows 7 x32 Service Pack 1
MS16-111 Windows 7 x64 Service Pack 1
MS16-111 Windows 8.1 x32
MS16-111 Windows 8.1 x64
MS16-111 Windows RT 8.1
MS16-111 Windows Server 2008 R2 x64 Service Pack 1
MS16-111 Windows Server 2008 R2 x64 Service Pack 1 (CORE)
MS16-111 Windows Server 2008 x32 Service Pack 2 (CORE)
MS16-111 Windows Server 2008 x64 Service Pack 2 (CORE)
MS16-111 Windows Server 2012
MS16-111 Windows Server 2012 (CORE)
MS16-111 Windows Server 2012 R2
MS16-111 Windows Server 2012 R2 (CORE)
MS16-111 Windows Vista Service Pack 2
MS16-111 Windows Vista x64 Service Pack 2
The security update addresses the vulnerability by correcting the behavior of the Windows lock screen to prevent unintended web content from loading.
This security update is rated Important for all supported editions of Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, and Windows 10.
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS16-112 Windows 10 Version 1511 for 32-bit Systems
MS16-112 Windows 10 Version 1511 for x64-based Systems
MS16-112 Windows 10 Version 1607 for 32-bit Systems
MS16-112 Windows 10 Version 1607 for x64-based Systems
MS16-112 Windows 10 for 32-bit Systems
MS16-112 Windows 10 for x64-based Systems
MS16-112 Windows 8.1 for 32-bit Systems
MS16-112 Windows 8.1 for x64-based Systems
MS16-112 Windows Server 2012 R2
MS16-112 Windows Server 2012 R2
his security update is rated Important for all supported editions of Windows 10 and Windows 10 Version 1511.
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS16-113 Windows 10 Version 1511 for 32-bit Systems
MS16-113 Windows 10 Version 1511 for x64-based Systems
MS16-113 Windows 10 for 32-bit Systems
MS16-113 Windows 10 for x64-based Systems
The security update addresses the vulnerability by correcting how the Microsoft SMBv1 Server handles specially crafted requests. The vulnerability could allow remote code execution if an authenticated attacker sends specially crafted packets to an affected Microsoft Server Message Block 1.0 (SMBv1) Server on Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2.
This security update is rated Important for all supported editions of Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2, Windows Server 2012, 2012 R2, Windows RT 8.1, and Windows 10
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS16-114 Windows 10 Version 1511 for 32-bit Systems
MS16-114 Windows 10 Version 1511 for x64-based Systems
MS16-114 Windows 10 Version 1607 for 32-bit Systems
MS16-114 Windows 10 Version 1607 for x64-based Systems
MS16-114 Windows 10 for 32-bit Systems
MS16-114 Windows 10 for x64-based Systems
MS16-114 Windows 7 for 32-bit Systems Service Pack 1
MS16-114 Windows 7 for x64-based Systems Service Pack 1
MS16-114 Windows 8.1 for 32-bit Systems
MS16-114 Windows 8.1 for x64-based Systems
MS16-114 Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
MS16-114 Windows Server 2008 R2 for x64-based Systems Service Pack 1
MS16-114 Windows Server 2008 R2 for x64-based Systems Service Pack 1
MS16-114 Windows Server 2008 for 32-bit Systems Service Pack 2
MS16-114 Windows Server 2008 for Itanium-based Systems Service Pack 2
MS16-114 Windows Server 2008 for x64-based Systems Service Pack 2
MS16-114 Windows Server 2012
MS16-114 Windows Server 2012 R2
MS16-114 Windows Vista Service Pack 2
MS16-114 Windows Vista x64 Edition Service Pack 2
This security update is rated Important for all supported editions of Windows 8.1, Windows Server 2012, Windows RT 8.1, Windows Server 2012 R2, and Windows 10.
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS16-115 Windows 10 Version 1511 for 32-bit Systems
MS16-115 Windows 10 Version 1511 for x64-based Systems
MS16-115 Windows 10 Version 1607 for 32-bit Systems
MS16-115 Windows 10 Version 1607 for x64-based Systems
MS16-115 Windows 10 for 32-bit Systems
MS16-115 Windows 10 for x64-based Systems
MS16-115 Windows 8.1 for 32-bit Systems
MS16-115 Windows 8.1 for x64-based Systems
MS16-115 Windows Server 2012
MS16-115 Windows Server 2012 R2
The security update affects all supported releases of Microsoft Windows and is rated Critical on client operating systems and Moderate on servers.
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS16-116 Windows 10 Version 1511 for 32-bit Systems
MS16-116 Windows 10 Version 1511 for x64-based Systems
MS16-116 Windows 10 Version 1607 for 32-bit Systems
MS16-116 Windows 10 Version 1607 for x64-based Systems
MS16-116 Windows 10 for 32-bit Systems
MS16-116 Windows 10 for x64-based Systems
MS16-116 Windows 7 for 32-bit Systems Service Pack 1
MS16-116 Windows 7 for x64-based Systems Service Pack 1
MS16-116 Windows 8.1 for 32-bit Systems
MS16-116 Windows 8.1 for x64-based Systems
MS16-116 Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
MS16-116 Windows Server 2008 R2 for x64-based Systems Service Pack 1
MS16-116 Windows Server 2008 for 32-bit Systems Service Pack 2
MS16-116 Windows Server 2008 for Itanium-based Systems Service Pack 2
MS16-116 Windows Server 2008 for x64-based Systems Service Pack 2
MS16-116 Windows Server 2012
MS16-116 Windows Server 2012 R2
MS16-116 Windows Vista Service Pack 2
MS16-116 Windows Vista x64 Edition Service Pack 2
The update addresses the vulnerabilities described in Adobe Security bulletin APSB16-29.
This security update is rated Critical for Adobe Flash Player in Internet Explorer 10, Internet Explorer 11 and Microsoft Edge.
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS16-117 Windows 8.1 for 32-bit Systems(Adobe Flash Player)
MS16-117 Windows 8.1 for x64-based Systems(Adobe Flash Player)
MS16-117 Windows Server 2012(Adobe Flash Player)
MS16-117 Windows Server 2012 R2(Adobe Flash Player)
These new vulnerability checks are included in Qualys vulnerability signature 2.3.427-4. Each Qualys account is automatically updated with the latest vulnerability signatures as they become available. To view the vulnerability signature version in your account, from the Qualys Help menu, select the About tab.
To perform a selective vulnerability scan, configure a scan profile to use the following options:
In addition, prior to running a scan for these new vulnerabilities, you can estimate your exposure to these new threats by running the Risk Analysis Report, available from the Qualys Vulnerability Management Reports tab.
Platforms and Platform Identification
For more information, customers may contact Qualys Technical Support.
The Enterprise TruRisk Platform and its integrated suite of security and compliance applications provides organizations of all sizes with a global view of their security and compliance solutions, while drastically reducing their total cost of ownership. Qualys solutions include: continuous monitoring, vulnerability management, policy compliance, PCI compliance, security assessment questionnaire, web application scanning, web application firewall, malware detection and SECURE Seal for security testing of web sites.