Qualys Vulnerability R&D Lab has released new vulnerability checks in the Enterprise TruRisk Platform to protect organizations against 31 vulnerabilities that were fixed in 7 bulletins announced today by Microsoft. Customers can immediately audit their networks for these and other new vulnerabilities by accessing their Qualys subscription. Visit Qualys Security Blog to prioritize remediation.
Non-Qualys customers can audit their network for these and other vulnerabilities by signing up for a Qualys Free Trial, or by trying Qualys Community Edition.
Microsoft has released 7 security bulletins to fix newly discovered flaws in their software. Qualys has released the following checks for these new vulnerabilities:
The security update addresses the vulnerability by correcting the way that MSXML verifies same-origin policy of URLs.
Affected Software:
This security update is rated Important for affected Windows clients and rated Low for affected Windows servers.
Prevent MSXML 3.0 binary behaviors from being used in Internet Explorer.
Set Internet and Local intranet security zone settings to "High" to block ActiveX Controls and Active Scripting in these zones
Configure Internet Explorer to prompt before running Active Scripting or to disable Active Scripting in the Internet and Local intranet security zone.
Add sites that you trust to the Internet Explorer Trusted sites zone.
Refer to the following link for further details: MS14-005
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS14-005 Windows 7 for 32-bit Systems Service Pack 1
MS14-005 Windows 7 for x64-based Systems Service Pack 1
MS14-005 Windows 8 for 32-bit Systems
MS14-005 Windows 8 for x64-based Systems
MS14-005 Windows 8.1 for 32-bit Systems
MS14-005 Windows 8.1 for x64-based Systems
MS14-005 Windows Server 2003 Service Pack 2
MS14-005 Windows Server 2003 with SP2 for Itanium-based Systems
MS14-005 Windows Server 2003 x64 Edition Service Pack 2
MS14-005 Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
MS14-005 Windows Server 2008 R2 for x64-based Systems Service Pack 1
MS14-005 Windows Server 2008 R2 for x64-based Systems Service Pack 1
MS14-005 Windows Server 2008 for 32-bit Systems Service Pack 2
MS14-005 Windows Server 2008 for 32-bit Systems Service Pack 2
MS14-005 Windows Server 2008 for Itanium-based Systems Service Pack 2
MS14-005 Windows Server 2008 for x64-based Systems Service Pack 2
MS14-005 Windows Server 2008 for x64-based Systems Service Pack 2
MS14-005 Windows Server 2012
MS14-005 Windows Server 2012
MS14-005 Windows Server 2012 R2
MS14-005 Windows Server 2012 R2
MS14-005 Windows Vista Service Pack 2
MS14-005 Windows Vista x64 Edition Service Pack 2
MS14-005 Windows XP Professional x64 Edition Service Pack 2
MS14-005 Windows XP Service Pack 3
The vulnerability occurs when an attacker sends large amounts of crafted IPv6 router advertisement packets over a targeted subnet.
Affected Software:
This security update is rated Important for affected Windows 8, Windows Server 2012 and Windows RT.
Refer to Microsoft Security Bulletin MS14-006 for further details.
Workaround:
Any of the configuration changes below would not correct the underlying vulnerability but would help block known attack vectors.
- Disable the Router Discovery Protocol
- Disable Internet Protocol version 6 (IPv6)
- Disable the "Core Networking - Router Advertisement (ICMPv6-In)" inbound firewall rule
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS14-006 Windows 8 for 32-bit Systems
MS14-006 Windows 8 for x64-based Systems
MS14-006 Windows Server 2012
MS14-006 Windows Server 2012
A remote code execution vulnerability exists in the way affected Windows components handle specially crafted 2D geometric figures. The vulnerability occurs when Direct2D fails to properly handle a specially crafted 2D geometric figure.
This security update is rated Critical for all supported editions of Windows 7, Windows 2008 R2, Windows 8, Windows Server 2012, Windows RT, Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1.
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS14-007 Windows 7 for 32-bit Systems Service Pack 1
MS14-007 Windows 7 for x64-based Systems Service Pack 1
MS14-007 Windows 8 for 32-bit Systems
MS14-007 Windows 8 for x64-based Systems
MS14-007 Windows 8.1 for 32-bit Systems
MS14-007 Windows 8.1 for x64-based Systems
MS14-007 Windows Server 2008 R2 for x64-based Systems Service Pack 1
MS14-007 Windows Server 2012
MS14-007 Windows Server 2012 R2
The security update addresses the vulnerability by removing the vulnerable code from Microsoft Forefront Protection for Exchange Server.
This security update is rated Critical for all supported builds of Microsoft Forefront Protection for Exchange 2010.
Refer to Microsoft Security Bulletin MS14-008 for further details.
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS14-008 Microsoft Forefront Protection 2010 for Exchange Server
Microsoft .NET Framework is exposed to the following vulnerabilities:
A denial of service vulnerability exists in Microsoft ASP.NET that could allow an attacker to cause an ASP.NET server to become unresponsive (CVE-2014-0253).
An elevation of privilege vulnerability exists in the Microsoft.NET Framework that could allow an attacker to elevate privileges on the targeted system (CVE-2014-0257).
A security feature bypass exists in a .NET Framework component that does not properly implement Address Space Layout Randomization (ASLR). The vulnerability could allow an attacker to bypass the ASLR security feature, after which the attacker could load additional malicious code in the process in an attempt to exploit another vulnerability (CVE-2014-0295).
This security update is rated Important for Microsoft .NET Framework 1.0 Service Pack 3, Microsoft .NET Framework 1.1 Service Pack 1, Microsoft .NET Framework 2.0 Service Pack 2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4, Microsoft .NET Framework 4.5, and Microsoft .NET Framework 4.5.1 on affected editions of Microsoft Windows.
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS14-009 Windows 7 for 32-bit Systems Service Pack 1(Microsoft .NET Framework 3.5.1)
MS14-009 Windows 7 for 32-bit Systems Service Pack 1(Microsoft .NET Framework 3.5.1)
MS14-009 Windows 7 for 32-bit Systems Service Pack 1(Microsoft .NET Framework 3.5.1)
MS14-009 Windows 7 for 32-bit Systems Service Pack 1(Microsoft .NET Framework 4)
MS14-009 Windows 7 for 32-bit Systems Service Pack 1(Microsoft .NET Framework 4)
MS14-009 Windows 7 for 32-bit Systems Service Pack 1(Microsoft .NET Framework 4.5)
MS14-009 Windows 7 for 32-bit Systems Service Pack 1(Microsoft .NET Framework 4.5)
MS14-009 Windows 7 for 32-bit Systems Service Pack 1(Microsoft .NET Framework 4.5.1)
MS14-009 Windows 7 for 32-bit Systems Service Pack 1(Microsoft .NET Framework 4.5.1)
MS14-009 Windows 7 for x64-based Systems Service Pack 1(Microsoft .NET Framework 3.5.1)
MS14-009 Windows 7 for x64-based Systems Service Pack 1(Microsoft .NET Framework 3.5.1)
MS14-009 Windows 7 for x64-based Systems Service Pack 1(Microsoft .NET Framework 3.5.1)
MS14-009 Windows 7 for x64-based Systems Service Pack 1(Microsoft .NET Framework 4)
MS14-009 Windows 7 for x64-based Systems Service Pack 1(Microsoft .NET Framework 4)
MS14-009 Windows 7 for x64-based Systems Service Pack 1(Microsoft .NET Framework 4.5)
MS14-009 Windows 7 for x64-based Systems Service Pack 1(Microsoft .NET Framework 4.5)
MS14-009 Windows 7 for x64-based Systems Service Pack 1(Microsoft .NET Framework 4.5.1)
MS14-009 Windows 7 for x64-based Systems Service Pack 1(Microsoft .NET Framework 4.5.1)
MS14-009 Windows 8 for 32-bit Systems(Microsoft .NET Framework 3.5)
MS14-009 Windows 8 for 32-bit Systems(Microsoft .NET Framework 3.5)
MS14-009 Windows 8 for 32-bit Systems(Microsoft .NET Framework 4.5)
MS14-009 Windows 8 for 32-bit Systems(Microsoft .NET Framework 4.5)
MS14-009 Windows 8 for 32-bit Systems(Microsoft .NET Framework 4.5.1)
MS14-009 Windows 8 for 32-bit Systems(Microsoft .NET Framework 4.5.1)
MS14-009 Windows 8 for x64-based Systems(Microsoft .NET Framework 3.5)
MS14-009 Windows 8 for x64-based Systems(Microsoft .NET Framework 3.5)
MS14-009 Windows 8 for x64-based Systems(Microsoft .NET Framework 4.5)
MS14-009 Windows 8 for x64-based Systems(Microsoft .NET Framework 4.5)
MS14-009 Windows 8 for x64-based Systems(Microsoft .NET Framework 4.5.1)
MS14-009 Windows 8 for x64-based Systems(Microsoft .NET Framework 4.5.1)
MS14-009 Windows 8.1 for 32-bit Systems(Microsoft .NET Framework 3.5)
MS14-009 Windows 8.1 for 32-bit Systems(Microsoft .NET Framework 3.5)
MS14-009 Windows 8.1 for 32-bit Systems(Microsoft .NET Framework 4.5.1)
MS14-009 Windows 8.1 for 32-bit Systems(Microsoft .NET Framework 4.5.1)
MS14-009 Windows 8.1 for x64-based Systems(Microsoft .NET Framework 3.5)
MS14-009 Windows 8.1 for x64-based Systems(Microsoft .NET Framework 3.5)
MS14-009 Windows 8.1 for x64-based Systems(Microsoft .NET Framework 4.5.1)
MS14-009 Windows 8.1 for x64-based Systems(Microsoft .NET Framework 4.5.1)
MS14-009 Windows Server 2003 Service Pack 2(Microsoft .NET Framework 1.1 Service Pack 1)
MS14-009 Windows Server 2003 Service Pack 2(Microsoft .NET Framework 1.1 Service Pack 1)
MS14-009 Windows Server 2003 Service Pack 2(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows Server 2003 Service Pack 2(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows Server 2003 Service Pack 2(Microsoft .NET Framework 4)
MS14-009 Windows Server 2003 Service Pack 2(Microsoft .NET Framework 4)
MS14-009 Windows Server 2003 with SP2 for Itanium-based Systems(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows Server 2003 with SP2 for Itanium-based Systems(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows Server 2003 with SP2 for Itanium-based Systems(Microsoft .NET Framework 4)
MS14-009 Windows Server 2003 with SP2 for Itanium-based Systems(Microsoft .NET Framework 4)
MS14-009 Windows Server 2003 x64 Edition Service Pack 2(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows Server 2003 x64 Edition Service Pack 2(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows Server 2003 x64 Edition Service Pack 2(Microsoft .NET Framework 4)
MS14-009 Windows Server 2003 x64 Edition Service Pack 2(Microsoft .NET Framework 4)
MS14-009 Windows Server 2008 R2 for Itanium-based Systems Service Pack 1(Microsoft .NET Framework 3.5.1)
MS14-009 Windows Server 2008 R2 for Itanium-based Systems Service Pack 1(Microsoft .NET Framework 3.5.1)
MS14-009 Windows Server 2008 R2 for Itanium-based Systems Service Pack 1(Microsoft .NET Framework 3.5.1)
MS14-009 Windows Server 2008 R2 for Itanium-based Systems Service Pack 1(Microsoft .NET Framework 4)
MS14-009 Windows Server 2008 R2 for Itanium-based Systems Service Pack 1(Microsoft .NET Framework 4)
MS14-009 Windows Server 2008 R2 for x64-based Systems Service Pack 1(Microsoft .NET Framework 3.5.1)
MS14-009 Windows Server 2008 R2 for x64-based Systems Service Pack 1(Microsoft .NET Framework 3.5.1)
MS14-009 Windows Server 2008 R2 for x64-based Systems Service Pack 1(Microsoft .NET Framework 3.5.1)
MS14-009 Windows Server 2008 R2 for x64-based Systems Service Pack 1(Microsoft .NET Framework 4)
MS14-009 Windows Server 2008 R2 for x64-based Systems Service Pack 1(Microsoft .NET Framework 4)
MS14-009 Windows Server 2008 R2 for x64-based Systems Service Pack 1(Microsoft .NET Framework 4.5)
MS14-009 Windows Server 2008 R2 for x64-based Systems Service Pack 1(Microsoft .NET Framework 4.5)
MS14-009 Windows Server 2008 R2 for x64-based Systems Service Pack 1(Microsoft .NET Framework 4.5.1)
MS14-009 Windows Server 2008 R2 for x64-based Systems Service Pack 1(Microsoft .NET Framework 4.5.1)
MS14-009 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)(Microsoft .NET Framework 3.5.1)
MS14-009 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)(Microsoft .NET Framework 3.5.1)
MS14-009 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)(Microsoft .NET Framework 3.5.1)
MS14-009 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)(Microsoft .NET Framework 4)
MS14-009 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)(Microsoft .NET Framework 4.5)
MS14-009 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)(Microsoft .NET Framework 4.5)
MS14-009 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)(Microsoft .NET Framework 4.5.1)
MS14-009 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)(Microsoft .NET Framework 4.5.1)
MS14-009 Windows Server 2008 for 32-bit Systems Service Pack 2(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows Server 2008 for 32-bit Systems Service Pack 2(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows Server 2008 for 32-bit Systems Service Pack 2(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows Server 2008 for 32-bit Systems Service Pack 2(Microsoft .NET Framework 4)
MS14-009 Windows Server 2008 for 32-bit Systems Service Pack 2(Microsoft .NET Framework 4)
MS14-009 Windows Server 2008 for 32-bit Systems Service Pack 2(Microsoft .NET Framework 4.5)
MS14-009 Windows Server 2008 for 32-bit Systems Service Pack 2(Microsoft .NET Framework 4.5)
MS14-009 Windows Server 2008 for 32-bit Systems Service Pack 2(Microsoft .NET Framework 4.5.1)
MS14-009 Windows Server 2008 for 32-bit Systems Service Pack 2(Microsoft .NET Framework 4.5.1)
MS14-009 Windows Server 2008 for Itanium-based Systems Service Pack 2(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows Server 2008 for Itanium-based Systems Service Pack 2(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows Server 2008 for Itanium-based Systems Service Pack 2(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows Server 2008 for Itanium-based Systems Service Pack 2(Microsoft .NET Framework 4)
MS14-009 Windows Server 2008 for Itanium-based Systems Service Pack 2(Microsoft .NET Framework 4)
MS14-009 Windows Server 2008 for x64-based Systems Service Pack 2(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows Server 2008 for x64-based Systems Service Pack 2(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows Server 2008 for x64-based Systems Service Pack 2(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows Server 2008 for x64-based Systems Service Pack 2(Microsoft .NET Framework 4)
MS14-009 Windows Server 2008 for x64-based Systems Service Pack 2(Microsoft .NET Framework 4)
MS14-009 Windows Server 2008 for x64-based Systems Service Pack 2(Microsoft .NET Framework 4.5)
MS14-009 Windows Server 2008 for x64-based Systems Service Pack 2(Microsoft .NET Framework 4.5)
MS14-009 Windows Server 2008 for x64-based Systems Service Pack 2(Microsoft .NET Framework 4.5.1)
MS14-009 Windows Server 2008 for x64-based Systems Service Pack 2(Microsoft .NET Framework 4.5.1)
MS14-009 Windows Server 2012(Microsoft .NET Framework 3.5)
MS14-009 Windows Server 2012(Microsoft .NET Framework 3.5)
MS14-009 Windows Server 2012(Microsoft .NET Framework 4.5)
MS14-009 Windows Server 2012(Microsoft .NET Framework 4.5)
MS14-009 Windows Server 2012(Microsoft .NET Framework 4.5.1)
MS14-009 Windows Server 2012(Microsoft .NET Framework 4.5.1)
MS14-009 Windows Server 2012 (Server Core installation)(Microsoft .NET Framework 3.5)
MS14-009 Windows Server 2012 (Server Core installation)(Microsoft .NET Framework 3.5)
MS14-009 Windows Server 2012 (Server Core installation)(Microsoft .NET Framework 4.5)
MS14-009 Windows Server 2012 (Server Core installation)(Microsoft .NET Framework 4.5)
MS14-009 Windows Server 2012 (Server Core installation)(Microsoft .NET Framework 4.5.1)
MS14-009 Windows Server 2012 (Server Core installation)(Microsoft .NET Framework 4.5.1)
MS14-009 Windows Server 2012 R2(Microsoft .NET Framework 3.5)
MS14-009 Windows Server 2012 R2(Microsoft .NET Framework 3.5)
MS14-009 Windows Server 2012 R2(Microsoft .NET Framework 4.5.1)
MS14-009 Windows Server 2012 R2(Microsoft .NET Framework 4.5.1)
MS14-009 Windows Server 2012 R2 (Server Core installation)(Microsoft .NET Framework 3.5)
MS14-009 Windows Server 2012 R2 (Server Core installation)(Microsoft .NET Framework 3.5)
MS14-009 Windows Server 2012 R2 (Server Core installation)(Microsoft .NET Framework 4.5.1)
MS14-009 Windows Server 2012 R2 (Server Core installation)(Microsoft .NET Framework 4.5.1)
MS14-009 Windows Vista Service Pack 2(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows Vista Service Pack 2(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows Vista Service Pack 2(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows Vista Service Pack 2(Microsoft .NET Framework 4)
MS14-009 Windows Vista Service Pack 2(Microsoft .NET Framework 4)
MS14-009 Windows Vista Service Pack 2(Microsoft .NET Framework 4.5)
MS14-009 Windows Vista Service Pack 2(Microsoft .NET Framework 4.5)
MS14-009 Windows Vista Service Pack 2(Microsoft .NET Framework 4.5.1)
MS14-009 Windows Vista Service Pack 2(Microsoft .NET Framework 4.5.1)
MS14-009 Windows Vista x64 Edition Service Pack 2(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows Vista x64 Edition Service Pack 2(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows Vista x64 Edition Service Pack 2(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows Vista x64 Edition Service Pack 2(Microsoft .NET Framework 4)
MS14-009 Windows Vista x64 Edition Service Pack 2(Microsoft .NET Framework 4)
MS14-009 Windows Vista x64 Edition Service Pack 2(Microsoft .NET Framework 4.5)
MS14-009 Windows Vista x64 Edition Service Pack 2(Microsoft .NET Framework 4.5)
MS14-009 Windows Vista x64 Edition Service Pack 2(Microsoft .NET Framework 4.5.1)
MS14-009 Windows Vista x64 Edition Service Pack 2(Microsoft .NET Framework 4.5.1)
MS14-009 Windows XP Professional x64 Edition Service Pack 2(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows XP Professional x64 Edition Service Pack 2(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows XP Professional x64 Edition Service Pack 2(Microsoft .NET Framework 4)
MS14-009 Windows XP Professional x64 Edition Service Pack 2(Microsoft .NET Framework 4)
MS14-009 Windows XP Service Pack 3(Microsoft .NET Framework 1.0 Service Pack 3)
MS14-009 Windows XP Service Pack 3(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows XP Service Pack 3(Microsoft .NET Framework 2.0 Service Pack 2)
MS14-009 Windows XP Service Pack 3(Microsoft .NET Framework 4)
MS14-009 Windows XP Service Pack 3(Microsoft .NET Framework 4)
Microsoft Internet Explorer is affected by multiple memory corruption vulnerabilities because it improperly handles objects in memory.
Microsoft Internet Explorer is affected by an elevation of privilege vulnerability due to the way it handles validation of local file installation and secure creation of registry keys.
Microsoft Internet Explorer is affected by a remote code execution vulnerability in the way that the VBScript engine handles objects in memory.
Microsoft Internet Explorer is affected by an information disclosure vulnerability that could allow an attacker to gain access to information in another domain or Internet Explorer zone.
An attacker could host a specially crafted website designed to exploit these vulnerabilities through Internet Explorer and then convince a user to view the website.
This security update is rated Critical for Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, Internet Explorer 9, Internet Explorer 10, and Internet Explorer 11 on affected Windows clients, Important for Internet Explorer 8, Internet Explorer 9, Internet Explorer 10, and Internet Explorer 11 on affected Windows servers, and Moderate for Internet Explorer 6 and Internet Explorer 7 on supported editions of Windows Server 2003.
An attacker who successfully exploited these vulnerabilities could execute arbitrary code on affected systems with elevated privileges.
Please refer to MS14-010 for details.
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS14-010 Windows 7 for 32-bit Systems Service Pack 1(Internet Explorer 10)
MS14-010 Windows 7 for 32-bit Systems Service Pack 1(Internet Explorer 11)
MS14-010 Windows 7 for 32-bit Systems Service Pack 1(Internet Explorer 8)
MS14-010 Windows 7 for 32-bit Systems Service Pack 1(Internet Explorer 9)
MS14-010 Windows 7 for x64-based Systems Service Pack 1(Internet Explorer 10)
MS14-010 Windows 7 for x64-based Systems Service Pack 1(Internet Explorer 11)
MS14-010 Windows 7 for x64-based Systems Service Pack 1(Internet Explorer 8)
MS14-010 Windows 7 for x64-based Systems Service Pack 1(Internet Explorer 9)
MS14-010 Windows 8 for 32-bit Systems(Internet Explorer 10)
MS14-010 Windows 8 for x64-based Systems(Internet Explorer 10)
MS14-010 Windows 8.1 for 32-bit Systems(Internet Explorer 11)
MS14-010 Windows 8.1 for x64-based Systems(Internet Explorer 11)
MS14-010 Windows Server 2003 Service Pack 2(Internet Explorer 6)
MS14-010 Windows Server 2003 Service Pack 2(Internet Explorer 7)
MS14-010 Windows Server 2003 Service Pack 2(Internet Explorer 8)
MS14-010 Windows Server 2003 with SP2 for Itanium-based Systems(Internet Explorer 6)
MS14-010 Windows Server 2003 with SP2 for Itanium-based Systems(Internet Explorer 7)
MS14-010 Windows Server 2003 x64 Edition Service Pack 2(Internet Explorer 6)
MS14-010 Windows Server 2003 x64 Edition Service Pack 2(Internet Explorer 7)
MS14-010 Windows Server 2003 x64 Edition Service Pack 2(Internet Explorer 8)
MS14-010 Windows Server 2008 R2 for Itanium-based Systems Service Pack 1(Internet Explorer 8)
MS14-010 Windows Server 2008 R2 for x64-based Systems Service Pack 1(Internet Explorer 10)
MS14-010 Windows Server 2008 R2 for x64-based Systems Service Pack 1(Internet Explorer 11)
MS14-010 Windows Server 2008 R2 for x64-based Systems Service Pack 1(Internet Explorer 8)
MS14-010 Windows Server 2008 R2 for x64-based Systems Service Pack 1(Internet Explorer 9)
MS14-010 Windows Server 2008 for 32-bit Systems Service Pack 2(Internet Explorer 7)
MS14-010 Windows Server 2008 for 32-bit Systems Service Pack 2(Internet Explorer 8)
MS14-010 Windows Server 2008 for 32-bit Systems Service Pack 2(Internet Explorer 9)
MS14-010 Windows Server 2008 for Itanium-based Systems Service Pack 2(Internet Explorer 7)
MS14-010 Windows Server 2008 for x64-based Systems Service Pack 2(Internet Explorer 7)
MS14-010 Windows Server 2008 for x64-based Systems Service Pack 2(Internet Explorer 8)
MS14-010 Windows Server 2008 for x64-based Systems Service Pack 2(Internet Explorer 9)
MS14-010 Windows Server 2012(Internet Explorer 10)
MS14-010 Windows Server 2012 R2(Internet Explorer 11)
MS14-010 Windows Vista Service Pack 2(Internet Explorer 7)
MS14-010 Windows Vista Service Pack 2(Internet Explorer 8)
MS14-010 Windows Vista Service Pack 2(Internet Explorer 9)
MS14-010 Windows Vista x64 Edition Service Pack 2(Internet Explorer 7)
MS14-010 Windows Vista x64 Edition Service Pack 2(Internet Explorer 8)
MS14-010 Windows Vista x64 Edition Service Pack 2(Internet Explorer 9)
MS14-010 Windows XP Professional x64 Edition Service Pack 2(Internet Explorer 6)
MS14-010 Windows XP Professional x64 Edition Service Pack 2(Internet Explorer 7)
MS14-010 Windows XP Professional x64 Edition Service Pack 2(Internet Explorer 8)
MS14-010 Windows XP Service Pack 3(Internet Explorer 6)
MS14-010 Windows XP Service Pack 3(Internet Explorer 7)
MS14-010 Windows XP Service Pack 3(Internet Explorer 8)
This security update is rated Critical for affected versions of the VBScript scripting engine on affected Windows clients and Moderate for affected versions of the VBScript scripting engine on affected Windows servers.
Affected Versions:
VBScript 5.6
VBScript 5.7
VBScript 5.8 (Affecting Internet Explorer 8,9,10,11)
VBScript 5.7 (Affecting Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) and Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation))
VBScript 5.8 (Affecting Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) ,Windows Server 2012 (Server Core installation) and Windows Server 2012 R2 (Server Core installation) )
Please refer to MS14-011 for details.
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS14-011 Windows 7 for 32-bit Systems Service Pack 1(VBScript 5.8)
MS14-011 Windows 7 for 32-bit Systems Service Pack 1(VBScript 5.8)
MS14-011 Windows 7 for 32-bit Systems Service Pack 1(VBScript 5.8)
MS14-011 Windows 7 for x64-based Systems Service Pack 1(VBScript 5.8)
MS14-011 Windows 7 for x64-based Systems Service Pack 1(VBScript 5.8)
MS14-011 Windows 7 for x64-based Systems Service Pack 1(VBScript 5.8)
MS14-011 Windows 8 for 32-bit Systems(VBScript 5.8)
MS14-011 Windows 8 for x64-based Systems(VBScript 5.8)
MS14-011 Windows 8.1 for 32-bit Systems(VBScript 5.8)
MS14-011 Windows 8.1 for x64-based Systems(VBScript 5.8)
MS14-011 Windows Server 2003 Service Pack 2(VBScript 5.6)
MS14-011 Windows Server 2003 Service Pack 2(VBScript 5.7)
MS14-011 Windows Server 2003 Service Pack 2(VBScript 5.8)
MS14-011 Windows Server 2003 with SP2 for Itanium-based Systems(VBScript 5.6)
MS14-011 Windows Server 2003 with SP2 for Itanium-based Systems(VBScript 5.7)
MS14-011 Windows Server 2003 x64 Edition Service Pack 2(VBScript 5.6)
MS14-011 Windows Server 2003 x64 Edition Service Pack 2(VBScript 5.7)
MS14-011 Windows Server 2003 x64 Edition Service Pack 2(VBScript 5.8)
MS14-011 Windows Server 2008 R2 for Itanium-based Systems Service Pack 1(VBScript 5.8)
MS14-011 Windows Server 2008 R2 for x64-based Systems Service Pack 1(VBScript 5.8)
MS14-011 Windows Server 2008 R2 for x64-based Systems Service Pack 1(VBScript 5.8)
MS14-011 Windows Server 2008 R2 for x64-based Systems Service Pack 1(VBScript 5.8)
MS14-011 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)(VBScript 5.8)
MS14-011 Windows Server 2008 for 32-bit Systems Service Pack 2(VBScript 5.7)
MS14-011 Windows Server 2008 for 32-bit Systems Service Pack 2(VBScript 5.8)
MS14-011 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)(VBScript 5.7)
MS14-011 Windows Server 2008 for Itanium-based Systems Service Pack 2(VBScript 5.7)
MS14-011 Windows Server 2008 for x64-based Systems Service Pack 2(VBScript 5.7)
MS14-011 Windows Server 2008 for x64-based Systems Service Pack 2(VBScript 5.8)
MS14-011 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)(VBScript 5.7)
MS14-011 Windows Server 2012(VBScript 5.8)
MS14-011 Windows Server 2012 (Server Core installation)(VBScript 5.8)
MS14-011 Windows Server 2012 R2(VBScript 5.8)
MS14-011 Windows Server 2012 R2 (Server Core installation)(VBScript 5.8)
MS14-011 Windows Vista Service Pack 2(VBScript 5.7)
MS14-011 Windows Vista Service Pack 2(VBScript 5.8)
MS14-011 Windows Vista x64 Edition Service Pack 2(VBScript 5.7)
MS14-011 Windows Vista x64 Edition Service Pack 2(VBScript 5.8)
MS14-011 Windows XP Professional x64 Edition Service Pack 2(VBScript 5.6)
MS14-011 Windows XP Professional x64 Edition Service Pack 2(VBScript 5.7)
MS14-011 Windows XP Professional x64 Edition Service Pack 2(VBScript 5.8)
MS14-011 Windows XP Service Pack 3(VBScript 5.7)
MS14-011 Windows XP Service Pack 3(VBScript 5.8)
These new vulnerability checks are included in Qualys vulnerability signature 2.2.651-3. Each Qualys account is automatically updated with the latest vulnerability signatures as they become available. To view the vulnerability signature version in your account, from the Qualys Help menu, select the About tab.
To perform a selective vulnerability scan, configure a scan profile to use the following options:
In addition, prior to running a scan for these new vulnerabilities, you can estimate your exposure to these new threats by running the Risk Analysis Report, available from the Qualys Vulnerability Management Reports tab.
Platforms and Platform Identification
For more information, customers may contact Qualys Technical Support.
The Enterprise TruRisk Platform and its integrated suite of security and compliance applications provides organizations of all sizes with a global view of their security and compliance solutions, while drastically reducing their total cost of ownership. Qualys solutions include: continuous monitoring, vulnerability management, policy compliance, PCI compliance, security assessment questionnaire, web application scanning, web application firewall, malware detection and SECURE Seal for security testing of web sites.