漏洞信息
The security update addresses the vulnerabilities by correcting how the Windows font library handles embedded fonts.
This security update is rated Critical for:
- All supported releases of Microsoft Windows.
- Affected editions of Microsoft Office 2007 and Microsoft Office 2010.
- Affected editions of Skype for Business 2016, Microsoft Lync 2013, and Microsoft Lync 2010
漏洞危害
The most severe of the vulnerabilities could allow remote code execution if a user opens a specially crafted document or visits an untrusted webpage that contains embedded OpenType fonts.
解决方案
Refer to MS16-097 for more information.
Patch:
Following are links for downloading patches to fix the vulnerabilities:
MS16-097: Windows Vista Service Pack 2
MS16-097: Windows Vista x64 Edition Service Pack 2
MS16-097: Windows Server 2008 for 32-bit Systems Service Pack 2
MS16-097: Windows Server 2008 for x64-based Systems Service Pack 2
MS16-097: Windows Server 2008 for Itanium-based Systems Service Pack 2
MS16-097: Windows 7 for 32-bit Systems Service Pack 1
MS16-097: Windows 7 for x64-based Systems Service Pack 1
MS16-097: Windows Server 2008 R2 for x64-based Systems Service Pack 1
MS16-097: Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
MS16-097: Windows 8.1 for 32-bit Systems
MS16-097: Windows 8.1 for x64-based Systems
MS16-097: Windows Server 2012 R2
MS16-097: Windows 10 for 32-bit Systems
MS16-097: Windows 10 for x64-based Systems
MS16-097: Windows 10 Version 1511 for 32-bit Systems
MS16-097: Windows 10 Version 1511 for x64-based Systems
MS16-097: Windows 10 Version 1607 for 32-bit Systems
MS16-097: Windows 10 Version 1607 for x64-based Systems
MS16-097: Microsoft Office 2007 Service Pack 3
MS16-097: Microsoft Office 2010 Service Pack 2 (32-bit editions)
MS16-097: Microsoft Office 2010 Service Pack 2 (64-bit editions)
MS16-097: Microsoft Word Viewer
MS16-097: Skype for Business 2016
MS16-097: Skype for Business Basic 2016
MS16-097: Skype for Business 2016
MS16-097: Skype for Business Basic 2016
MS16-097: Microsoft Lync 2013 Service Pack 1
MS16-097: Microsoft Lync Basic 2013 Service Pack 1
MS16-097: Microsoft Lync 2013 Service Pack 1
MS16-097: Microsoft Lync Basic 2013 Service Pack 1
MS16-097: Microsoft Lync 2010 Attendee
www.0daybank.org
文章评论