SpiderLabs Blog

Microsoft Advanced Notification for November 2012 - RCE, Yikes! | Trustwave | SpiderLabs | Trustwave

Written by Space Rogue | Nov 8, 2012 6:00:00 AM

Microsoft has released its advance notification for next weeks Patch Tuesday updates.

The good news is that there are only six bulletins this month; the bad news is that four of those are rated as critical and five of them result in Remote Code Execution! Yikes! The RCEs all seem to be at the operating system level affecting everything from XP SP3 up to and including Server 2008 R2. The one bulletin with RCE that is only labeled important and not critical is part of MS Office 2003, 2007 and 2010, including 2008 and 2011 for Mac. The sixth bulletin, rated as Moderate, results in Information Disclosure and impacts Vista SP2, Windows 7 32 and 64 bit as well as multiple flavors of Server 2008.

Stay tuned for a more detailed post once the patches have been released.