Companies

Microsoft Security Bulletins For February 2016

Microsoft Security Bulletins For February 2016

The Microsoft Security Bulletins overview for February 2016 provides you with detailed information about security and non-security patches that Microsoft released for its Windows operating system and other company products since the January 2016 release.

The overview begins with an executive summary listing the most important facts. What follows afterwards is the patch distribution across different client and server versions of the Windows operating system, and other Microsoft products.

Lists of the security bulletins, advisories, and non-security updates released in February 2016 are listed next. Each offering a short description of the patch or bulletin released, and a link to the Microsoft website for further information.

Last but not least, download instructions are provided and options are listed.

Microsoft Security Bulletins For February 2016

Executive Summary

Operating System Distribution

All client versions of Windows are affected by at least two bulletins that have been rated critical. Windows 8.1 and Windows 10 are affected by the most, with Windows 8.1 being affected by four critical and 3 important bulletins, and Windows 10 by 5 critical and 3 important vulnerabilities.

As has been the case in the past, the additional critical bulletin is for the Microsoft Edge browser which is a Windows 10 exclusive.

Other Microsoft Products

Security Bulletins

MS16-009 - Cumulative Security Update for Internet Explorer (3134220) - Critical - Remote Code Execution

This security update resolves vulnerabilities in Internet Explorer. The most severe of the vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer.

MS16-011 - Cumulative Security Update for Microsoft Edge (3134225) - Critical - Remote Code Execution

This security update resolves vulnerabilities in Microsoft Edge. The most severe of the vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Microsoft Edge.

MS16-012 - Security Update for Microsoft Windows PDF Library to Address Remote Code Execution (3138938) - Critical - Remote Code Execution

This security update resolves vulnerabilities in Microsoft Windows. The more severe of the vulnerabilities could allow remote code execution if Microsoft Windows PDF Library improperly handles application programming interface (API) calls, which could allow an attacker to run arbitrary code on the user's system.

MS16-013 - Security Update for Windows Journal to Address Remote Code Execution (3134811) - Critical - Remote Code Execution

This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted Journal file.

MS16-014  - Security Update for Microsoft Windows to Address Remote Code Execution (3134228)- Important - Remote Code Execution

This security update resolves vulnerabilities in Microsoft Windows. The most severe of the vulnerabilities could allow remote code execution if an attacker is able to log on to a target system and run a specially crafted application.

MS16-015 - Security Update for Microsoft Office to Address Remote Code Execution (3134226)  - Critical - Remote Code Execution

This security update resolves vulnerabilities in Microsoft Office. The most severe of the vulnerabilities could allow remote code execution if a user opens a specially crafted Microsoft Office file.

MS16-016 - Security Update for WebDAV to Address Elevation of Privilege (3136041) - Important -
Elevation of Privilege

This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker uses the Microsoft Web Distributed Authoring and Versioning (WebDAV) client to send specifically crafted input to a server.

MS16-017 - Security Update for Remote Desktop Display Driver to Address Elevation of Privilege (3134700) - Important - Elevation of Privilege

This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an authenticated attacker logs on to the target system using RDP and sends specially crafted data over the connection. By default, RDP is not enabled on any Windows operating system. Systems that do not have RDP enabled are not at risk.

MS16-018 - Security Update for Windows Kernel-Mode Drivers to Address Elevation of Privilege (3136082) - Important - Elevation of Privilege

This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application.

MS16-019 - Security Update for .NET Framework to Address Denial of Service (3137893) - Important -
Denial of Service

This security update resolves vulnerabilities in Microsoft .NET Framework. The more severe of the vulnerabilities could cause denial of service if an attacker inserts specially crafted XSLT into a client-side XML web part, causing the server to recursively compile XSLT transforms.

MS16-020 - Security Update for Active Directory Federation Services to Address Denial of Service (3134222) - Important - Denial of Service

This security update resolves a vulnerability in Active Directory Federation Services (ADFS). The vulnerability could allow denial of service if an attacker sends certain input data during forms-based authentication to an ADFS server, causing the server to become nonresponsive.

MS16-021 - Security Update for NPS RADIUS Server to Address Denial of Service (3133043)  - Important - Denial of Service

This security update resolves a vulnerability in Microsoft Windows. The vulnerability could cause denial of service on a Network Policy Server (NPS) if an attacker sends specially crafted username strings to the NPS, which could prevent RADIUS authentication on the NPS.

MS16-022 - Security Update for Adobe Flash Player (3135782) - Critical - Remote Code Execution

This security update resolves vulnerabilities in Adobe Flash Player when installed on all supported editions of Windows Server 2012, Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10.

Security Advisories and updates

Advisory 3127909 - Vulnerabilities in ASP.NET Templates Could Allow Tampering

Non-security related updates

How to download and install the February 2016 security updates

Windows users can install all security patches for their operating system and also optional non-security patches using Windows Update.

Windows Update is an automated updating tool that is built-in to Windows to download and install patches that Microsoft releases.

Update checks are run frequently but not in real-time. Run a manual check for Windows updates if you want to grab the updates as soon as they are available.

You can do so in the following way:

  1. Tap on the Windows-key, type Windows Update and hit enter.
  2. The Windows Update program opens.
  3. Locate and click on "check for updates". This queries Microsoft's server for updates.

Depending on how Windows Update is configured, Windows may download these updates automatically, or present them to you only giving you options to select the updates that you want installed on your system.

Windows patches are made available on Microsoft's Download Center site as well from where they can be downloaded individually. You may also download a monthly security ISO image that Microsoft releases that contains all patches for all supported operating systems released in that month.

Consult our Windows Update guide linked below for additional options and troubleshooting information.

Additional resources

How to Install and Play Doom on Linux
Introduction to Doom The Doom Series originated in the 90s after the release of the original Doom. It was an instant hit and from that time onwards th...
Vulkan for Linux Users
With each new generation of graphics cards, we see game developers push the limits of graphical fidelity and come one step closer to photorealism. But...
OpenTTD vs Simutrans
Creating your own transport simulation can be fun, relaxing and extremely enticing. That's why you need to make sure that you try out as many games as...