Microsoft today released six security bulletins and updates to address the vulnerabilities disclosed in them. The updates address a total of 29 vulnerabilities.
Update at 2:20 pm ET: This story is updated below to clarify the exploitability of MS14-042.
The Microsoft Exploitability Index this month's updates says that successful exploit code for 28 of the 29 vulnerabilities is "likely." The 29th is rated Moderate and therefore not rated as to exploitability.
As is usually the case, Microsoft will also release a new version of the Windows Malicious Software Removal Tool and a large collection of non-security updates to various Windows versions.
Executive Summary:
Bulletin ID |
Maximum Severity Rating and Vulnerability Impact |
Restart Requirement |
Affected Software |
---|---|---|---|
Bulletin 1 |
Critical |
Requires restart |
Microsoft Windows, |
Bulletin 2 |
Critical |
May require restart |
Microsoft Windows |
Bulletin 3 |
Important |
Requires restart |
Microsoft Windows |
Bulletin 4 |
Important |
Requires restart |
Microsoft Windows |
Bulletin 5 |
Important |
May require restart |
Microsoft Windows |
Bulletin 6 |
Moderate |
Does not require restart |
Microsoft Server Software |
Windows Server 2003 |
|||||
Bulletin Identifier |
Bulletin 1 |
Bulletin 2 |
Bulletin 3 |
Bulletin 4 |
Bulletin 5 |
Aggregate Severity Rating |
None |
None |
None |
||
Windows Server 2003 Service Pack 2 |
Internet Explorer 6 Internet Explorer 7 Internet Explorer 8 |
Not applicable |
Not applicable |
Windows Server 2003 Service Pack 2 |
Not applicable |
Windows Server 2003 x64 Edition Service Pack 2 |
Internet Explorer 6 Internet Explorer 7 Internet Explorer 8 |
Not applicable |
Not applicable |
Windows Server 2003 x64 Edition Service Pack 2 |
Not applicable |
Windows Server 2003 with SP2 for Itanium-based Systems |
Internet Explorer 6 Internet Explorer 7 |
Not applicable |
Not applicable |
Windows Server 2003 with SP2 for Itanium-based Systems |
Not applicable |
Windows Vista |
|||||
Bulletin Identifier |
Bulletin 1 |
Bulletin 2 |
Bulletin 3 |
Bulletin 4 |
Bulletin 5 |
Aggregate Severity Rating |
|||||
Windows Vista Service Pack 2 |
Internet Explorer 7 Internet Explorer 8 Internet Explorer 9 |
Windows Vista Service Pack 2 |
Windows Vista Service Pack 2 |
Windows Vista Service Pack 2 |
Windows Vista Service Pack 2 |
Windows Vista x64 Edition Service Pack 2 |
Internet Explorer 7 Internet Explorer 8 Internet Explorer 9 |
Windows Vista x64 Edition Service Pack 2 |
Windows Vista x64 Edition Service Pack 2 |
Windows Vista x64 Edition Service Pack 2 |
Windows Vista x64 Edition Service Pack 2 |
Windows Server 2008 |
|||||
Bulletin Identifier |
Bulletin 1 |
Bulletin 2 |
Bulletin 3 |
Bulletin 4 |
Bulletin 5 |
Aggregate Severity Rating |
|||||
Windows Server 2008 for 32-bit Systems Service Pack 2 |
Internet Explorer 7 Internet Explorer 8 Internet Explorer 9 |
Windows Server 2008 for 32-bit Systems Service Pack 2 |
Windows Server 2008 for 32-bit Systems Service Pack 2 |
Windows Server 2008 for 32-bit Systems Service Pack 2 |
Windows Server 2008 for 32-bit Systems Service Pack 2 |
Windows Server 2008 for x64-based Systems Service Pack 2 |
Internet Explorer 7 Internet Explorer 8 Internet Explorer 9 |
Windows Server 2008 for x64-based Systems Service Pack 2 |
Windows Server 2008 for x64-based Systems Service Pack 2 |
Windows Server 2008 for x64-based Systems Service Pack 2 |
Windows Server 2008 for x64-based Systems Service Pack 2 |
Windows Server 2008 for Itanium-based Systems Service Pack 2 |
Internet Explorer 7 |
Not applicable |
Windows Server 2008 for Itanium-based Systems Service Pack 2 |
Windows Server 2008 for Itanium-based Systems Service Pack 2 |
Not applicable |
Windows 7 |
|||||
Bulletin Identifier |
Bulletin 1 |
Bulletin 2 |
Bulletin 3 |
Bulletin 4 |
Bulletin 5 |
Aggregate Severity Rating |
|||||
Windows 7 for 32-bit Systems Service Pack 1 |
Internet Explorer 8 Internet Explorer 9 Internet Explorer 10 Internet Explorer 11 |
Windows 7 for 32-bit Systems Service Pack 1 |
Windows 7 for 32-bit Systems Service Pack 1 |
Windows 7 for 32-bit Systems Service Pack 1 |
Windows 7 for 32-bit Systems Service Pack 1 |
Windows 7 for x64-based Systems Service Pack 1 |
Internet Explorer 8 Internet Explorer 9 Internet Explorer 10 Internet Explorer 11 |
Windows 7 for x64-based Systems Service Pack 1 |
Windows 7 for x64-based Systems Service Pack 1 |
Windows 7 for x64-based Systems Service Pack 1 |
Windows 7 for x64-based Systems Service Pack 1 |
Windows Server 2008 R2 |
|||||
Bulletin Identifier |
Bulletin 1 |
Bulletin 2 |
Bulletin 3 |
Bulletin 4 |
Bulletin 5 |
Aggregate Severity Rating |
|||||
Windows Server 2008 R2 for x64-based Systems Service Pack 1 |
Internet Explorer 8 Internet Explorer 9 Internet Explorer 10 Internet Explorer 11 |
Windows Server 2008 R2 for x64-based Systems Service Pack 1 |
Windows Server 2008 R2 for x64-based Systems Service Pack 1 |
Windows Server 2008 R2 for x64-based Systems Service Pack 1 |
Windows Server 2008 R2 for x64-based Systems Service Pack 1 |
Windows Server 2008 R2 for Itanium-based Systems Service Pack 1 |
Internet Explorer 8 |
Not applicable |
Windows Server 2008 R2 for Itanium-based Systems Service Pack 1 |
Windows Server 2008 R2 for Itanium-based Systems Service Pack 1 |
Not applicable |
Windows 8 and Windows 8.1 |
|||||
Bulletin Identifier |
Bulletin 1 |
Bulletin 2 |
Bulletin 3 |
Bulletin 4 |
Bulletin 5 |
Aggregate Severity Rating |
|||||
Windows 8 for 32-bit Systems |
Internet Explorer 10 |
Windows 8 for 32-bit Systems |
Windows 8 for 32-bit Systems |
Windows 8 for 32-bit Systems |
Windows 8 for 32-bit Systems |
Windows 8 for x64-based Systems |
Internet Explorer 10 |
Windows 8 for x64-based Systems |
Windows 8 for x64-based Systems |
Windows 8 for x64-based Systems |
Windows 8 for x64-based Systems |
Windows 8.1 for 32-bit Systems |
Internet Explorer 11 |
Windows 8.1 for 32-bit Systems |
Windows 8.1 for 32-bit Systems |
Windows 8.1 for 32-bit Systems |
Windows 8.1 for 32-bit Systems |
Windows 8.1 for x64-based Systems |
Internet Explorer 11 |
Windows 8.1 for x64-based Systems |
Windows 8.1 for x64-based Systems |
Windows 8.1 for x64-based Systems |
Windows 8.1 for x64-based Systems |
Windows Server 2012 and Windows Server 2012 R2 |
|||||
Bulletin Identifier |
Bulletin 1 |
Bulletin 2 |
Bulletin 3 |
Bulletin 4 |
Bulletin 5 |
Aggregate Severity Rating |
|||||
Windows Server 2012 |
Internet Explorer 10 |
Windows Server 2012 |
Windows Server 2012 |
Windows Server 2012 |
Windows Server 2012 |
Windows Server 2012 R2 |
Internet Explorer 11 |
Windows Server 2012 R2 |
Windows Server 2012 R2 |
Windows Server 2012 R2 |
Windows Server 2012 R2 |
Windows RT and Windows RT 8.1 |
|||||
Bulletin Identifier |
Bulletin 1 |
Bulletin 2 |
Bulletin 3 |
Bulletin 4 |
Bulletin 5 |
Aggregate Severity Rating |
None |
||||
Windows RT |
Internet Explorer 10 |
Windows RT |
Windows RT |
Windows RT |
Not applicable |
Windows RT 8.1 |
Internet Explorer 11 |
Windows RT 8.1 |
Windows RT 8.1 |
Windows RT 8.1 |
Not applicable |
Server Core installation option |
|||||
Bulletin Identifier |
Bulletin 1 |
Bulletin 2 |
Bulletin 3 |
Bulletin 4 |
Bulletin 5 |
Aggregate Severity Rating |
None |
None |
None |
||
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) |
Not applicable |
Not applicable |
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) |
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) |
Not applicable |
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) |
Not applicable |
Not applicable |
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) |
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) |
Not applicable |
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) |
Not applicable |
Not applicable |
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) |
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) |
Not applicable |
Windows Server 2012 (Server Core installation) |
Not applicable |
Not applicable |
Windows Server 2012 (Server Core installation) |
Windows Server 2012 (Server Core installation) |
Not applicable |
Windows Server 2012 R2 (Server Core installation) |
Not applicable |
Not applicable |
Windows Server 2012 R2 (Server Core installation) |
Windows Server 2012 R2 (Server Core installation) |
Not applicable |
Microsoft Server Bus for Windows Server |
|
Bulletin Identifier |
Bulletin 6 |
Aggregate Severity Rating |
|
Microsoft Service Bus for Windows Server |
Microsoft Service Bus for Windows Server |
The Bottom Line: Restart Your Window Computers and Servers first thing Wednesday Morning!
Apple MAC and Linux users - no need