Microsoft Patch Tuesday 2013-11-12

MS13-088
Title Cumulative Security Update for Internet Explorer
Replaces MS13-080
Affected Internet Explorer
KB KB2888505
Known Exploits No
Microsoft Rating Critical
ISC Client Rating Critical
ISC Server Rating Critical
CVE Exploitability
2013-3891 1
2013-3908 2
2013-3909 3
MS13-089
Title Remote Code Execution Vulnerability in Windows Graphics Device Interface
Replaces MS80-71
Affected GDI+
KB KB2876331
Known Exploits No
Microsoft Rating Critical
ISC Client Rating Critical
ISC Server Rating Critical
CVE Exploitability
2013-3940 1
MS13-090
Title Remote Code Execution Vulnerability in InformationCardSigninHelp ActiveX Class
Replaces MS11-090
Affected ActiveX (icardie.dll)
KB KB2900986
Known Exploits Yes
Microsoft Rating Critical
ISC Client Rating Patch now
ISC Server Rating Patch now
CVE Exploitability
2013-3918 1
MS13-091
Title Remote Code Execution Vulnerability in Microsoft Office
Replaces MS90-73
Affected Microsoft Office (Word)
KB KB2885093
Known Exploits No
Microsoft Rating Important
ISC Client Rating Critical
ISC Server Rating Critical
CVE Exploitability
2013-0082 1
2013-1324 3
MS13-092
Title Elevation of Privileges Vulnerability in HyperV
Replaces
Affected HyperV Guests (DoS for Host)
KB KB2893986
Known Exploits No
Microsoft Rating Important
ISC Client Rating Important
ISC Server Rating Important
CVE Exploitability
2013-3898 1
MS13-093
Title Information Disclosure Vulnerability in Ancillary Function Driver
Replaces MS12-009
Affected Ancillary Function Driver
KB KB2875783
Known Exploits No
Microsoft Rating Important
ISC Client Rating Important
ISC Server Rating Important
CVE Exploitability
2013-3887 3
MS13-094
Title Information Disclosure Vulnerability in Outlook
Replaces MS13-068
Affected Outlook
KB KB2894514
Known Exploits No
Microsoft Rating Important
ISC Client Rating Important
ISC Server Rating Important
CVE Exploitability
2013-3905 3
MS13-095
Title Denial of Service Vulnerability in Digital Signatures
Replaces
Affected Digital Signatures
KB KB2868626
Known Exploits No
Microsoft Rating Important
ISC Client Rating N/A
ISC Server Rating N/A
CVE Exploitability
2013-3869 3
We will update issues on this page for about a week or so as they evolve. We appreciate your updates!
US based customers can call Microsoft for free patch related support on 1-866-PCSAFETY
(*): ISC rating
  • We use 4 levels:
    • PATCH NOW: Typically used where we see immediate danger of exploitation. Typical environments will want to deploy these patches ASAP. Workarounds are typically not accepted by users or are not possible. This rating is often used when typical deployments make it vulnerable and exploits are being used or easy to obtain or make.
    • Critical: Anything that needs little to become "interesting" for the dark side. Best approach is to test and deploy ASAP. Workarounds can give more time to test.
    • Important: Things where more testing and other measures can help.
    • Less Urgent: practices for servers such as not using outlook, MSIE, word etc. to do traditional office or leisure work.
    • The rating is not a risk analysis as such. It is a rating of importance of the vulnerability and the perceived or even predicted threatatches.