Microsoft March 2013 Black Tuesday Overview

Published: 2013-03-12
Last Updated: 2013-03-13 08:48:46 UTC
by Swa Frantzen (Version: 1)
4 comment(s)

Overview of the March 2013 Microsoft patches and their status.

# Affected Contra Indications - KB Known Exploits Microsoft rating(**) ISC rating(*)
clients servers
MS13-021 The usual MSIE cumulative patch, adding fixes for eight more vulnerabilities. All 8 are of the "use after free" type and they all allow random code execution.  
Replaces MS13-009.
KB 2809289 CVE-2013-1288 was made public according to Microsoft. Severity:Critical
Critical Important
MS13-022 A double dereference vulnerability that allows random code execution in Silverlight.
This also affects the mac version of silverlight 5. The update is expected via the auto-update feature on Macs.
Replaces MS12-034.

KB 2814124 No publicly known exploits Severity:Critical
Critical Important
MS13-023 A memory management vulnerability allow random code execution in the Visio viewer. The full package is exempt from this problem. 
Replaces MS12-059.
Visio Viewer

KB 2801261 No publicly known exploits Severity:Critical
Critical Important
MS13-024 Four different privilege escalation vulnerabilities in Sharepoint. Of note: it includes an XSS and a directory traversal vulnerability in addition to a problem with callback functions and a buffer overflow.
Replaces MS12-066.

KB 2780176 No publicly known exploits. Severity:Critical
N/A Critical
MS13-025 A buffer management problem allows leaking arbitrary data in memory. It could expose usernames and passwords of accounts.

KB 2816264 No publicly known exploits. Severity:Important
Important Less Urgent
MS13-026 When previewing or opening an email that contain HTML5, outlook for Mac can load content from random webservers without user interaction.
The note is quite confusing. E.g.: every mac capable of running the affected versions has a webkit browser installed together with the OS; Office for Mac 2008 did not have outlook - it had entourage instead; Outlook isn't part of all Office for Mac 2011 licenses either. 
Replaces MS12-076.
Outlook for Mac

KB 2813682 No publicly known exploits Severity:Important
Less Urgent Less Urgent
MS13-027 3 similar problems exist with the windows USB drivers that allow privilege escalation to full administrative rights.  
USB Kernel Mode Drivers

KB 2807986 No publicly known exploits Severity:Important
Important Less Urgent
