Skip to main content

Microsoft Security Bulletin Release for November, 2016


Petrovic
Gold VIP
Forum|alt.badge.img+52
November Security Update Details:

Microsoft released fourteen (14) bulletins.  six (6) bulletins are identified as Critical and eight (8) rated Moderate in severity. 

The updates address vulnerabilities in Microsoft Windows, Internet Explorer, Microsoft Edge, Microsoft Office, Microsoft Office Services and Web Apps, Microsoft SQL Server and Adobe Flash Player for Windows 8.1 and above. 

Addressed in the updates are Remote Code Execution, Elevation of Privilege and Security Feature Bypass.

Information about the update for Windows 10 is available at Windows 10 update history.

Critical:
  • MS16-129 -- Cumulative Security Update for Microsoft Edge (3199057)
  • MS16-130 -- Security Update for Microsoft Windows (3199172)
  • MS16-131  -- Security Update for Microsoft Video Control (3199151)
  • MS16-132 -- Security Update for Microsoft Graphics Component (3199120
  • MS16-141 -- Security Update for Adobe Flash Player (3202790)
  • MS16-142 -- Cumulative Security Update for Internet Explorer (3198467)
Important:
  • MS16-133 -- Security Update for Microsoft Office (3199168)
  • MS16-134 -- Security Update for Common Log File System Driver (3193706)
  • MS16-135 -- Security Update for Windows Kernel-Mode Drivers (3199135)
  • MS16-136 -- Security Update for SQL Server (3199641)
  • MS16-137 -- Security Update for Windows Authentication Methods (3199173)
  • MS16-138 -- Security Update to Microsoft Virtual Hard Disk Driver (3199647)
  • MS16-139 -- Security Update for Windows Kernel (3199720)
  • MS16-140 -- Security Update for Boot Manager (3193479)
Additional Update Notes
  • Adobe Flash Player -- For Windows Server 2012, Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10, and Windows 10 Version 1511, Adobe Flash Player is now a security bulletin rather than a security advisory and is included with the updates.
  • MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center. 
  • Windows 8.x and Windows 10 -- Non-security new features and improvements for Windows 8.1 and Windows 10 are included with the updates.
  • Windows 10 -- A summary of important product developments included in each update, with links to more details is available at Windows 10 Update History. The page will be regularly refreshed, as new updates are released.
Release Notes
TechNet: Microsoft Security Bulletin for November 2016 
Windows 10 Update History

7 replies

RetiredTripleHelix
Gold VIP
Forum|alt.badge.img+56
Thanks Petr!
 
Daniel

Baldrick
Gold VIP
  • Gold VIP
  • 16060 replies
  • November 8, 2016
Cheers, Petr...much obliged. I thinthat the updates have come through here as I had an automatic reboot so hopefully am now fully up to date. ;)

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54
Thank you Petr.
All installed now here.

Ssherjj
Moderator
Forum|alt.badge.img+62
  • Moderator
  • 21892 replies
  • November 8, 2016
Boondabah Petr. Thank you! 

RetiredTripleHelix
Gold VIP
Forum|alt.badge.img+56
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
 
********************************************************************
Microsoft Security Bulletin Summary for November 2016
Issued: November 8, 2016
********************************************************************
 
This bulletin summary lists security bulletins released for November 2016.
 
The full version of the Microsoft Security Bulletin Summary for November 2016 can be found at <https://technet.microsoft.com/library/security/ms16-nov>.
 
Critical Security Bulletins
============================
 
MS16-142
 
  - Affected Software:
    - Windows Vista Service Pack 2:
      - Internet Explorer 9
    - Windows Vista x64 Edition Service Pack 2:
      - Internet Explorer 9
    - Windows Server 2008 for 32-bit Systems Service Pack 2:
      - Internet Explorer 9
      (Windows Server 2008 Server Core installation not affected)
    - Windows Server 2008 for x64-based Systems Service Pack 2:
      - Internet Explorer 9
      (Windows Server 2008 Server Core installation not affected)
    - Windows 7 for 32-bit Systems Service Pack 1:
    - Windows Server 2012:
      - Internet Explorer 10
      (Windows Server 2012 Server Core installation not affected)
      - Internet Explorer 11
    - Windows 7 for x64-based Systems Service Pack 1:
      - Internet Explorer 11
    - Windows Server 2008 R2 for x64-based Systems
      Service Pack 1:
      - Internet Explorer 11
      (Windows Server 2008 R2 Server Core installation
      not affected)
    - Windows 8.1 for 32-bit Systems:
      - Internet Explorer 11
    - Windows 8.1 for x64-based Systems:
      - Internet Explorer 11
    - Windows Server 2012 R2:
      - Internet Explorer 11
      (Windows Server 2012 R2 Server Core installation not affected)
    - Windows RT 8.1:
      - Internet Explorer 11
    - Windows 10 for 32-bit Systems:
      - Internet Explorer 11
    - Windows 10 for x64-based Systems:
      - Internet Explorer 11
    - Windows 10 Version 1511 for 32-bit Systems:
      - Internet Explorer 11
    - Windows 10 Version 1511 for x64-based Systems:
      - Internet Explorer 11
    - Windows 10 Version 1607 for 32-bit Systems:
      - Internet Explorer 11
    - Windows 10 Version 1607 for x64-based Systems:
      - Internet Explorer 11
  - Impact: Remote Code Execution
  - Version Number: 1.0
 
MS16-129
 
  - Affected Software:
    - Windows 10 for 32-bit Systems
      - Microsoft Edge
    - Windows 10 for x64-based Systems
      - Microsoft Edge
    - Windows 10 Version 1511 for 32-bit Systems
      - Microsoft Edge
    - Windows 10 Version 1511 for x64-based Systems
      - Microsoft Edge
    - Windows 10 Version 1607 for 32-bit Systems:
      - Microsoft Edge
    - Windows 10 Version 1607 for x64-based Systems:
      - Microsoft Edge
    - Windows Server 2016 for x64-based Systems:
      - Microsoft Edge
      (Windows Server 2016 Server Core installation not affected)
  - Impact: Remote Code Execution
  - Version Number: 1.0
 
MS16-130
 
  - Affected Software:
    - Windows Vista Service Pack 2
    - Windows Vista x64 Edition Service Pack 2
    - Windows Server 2008 for 32-bit Systems Service Pack 2
      (Windows Server 2008 Server Core installation affected)
    - Windows Server 2008 for x64-based Systems Service Pack 2
      (Windows Server 2008 Server Core installation affected)
    - Windows Server 2008 for Itanium-based Systems Service Pack 2
    - Windows 7 for 32-bit Systems Service Pack 1
    - Windows 7 for x64-based Systems Service Pack 1
    - Windows Server 2008 R2 for x64-based Systems Service Pack 1
      (Windows Server 2008 R2 Server Core installation affected)
    - Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
    - Windows 8.1 for 32-bit Systems
    - Windows 8.1 for x64-based Systems
    - Windows Server 2012
      (Windows Server 2012 Server Core installation affected)
    - Windows Server 2012 R2
      (Windows Server 2012 R2 Server Core installation affected)
    - Windows RT 8.1
    - Windows 10 for 32-bit Systems
    - Windows 10 for x64-based Systems
    - Windows 10 Version 1511 for 32-bit Systems
    - Windows 10 Version 1511 for x64-based Systems
    - Windows 10 Version 1607 for 32-bit Systems
    - Windows 10 Version 1607 for x64-based Systems
    - Windows Server 2016 for x64-based Systems
      (Windows Server 2016 Server Core installation affected)
  - Impact: Remote Code Execution
  - Version Number: 1.0
 
MS16-131
 
  - Affected Software:
    - Windows Vista Service Pack 2
    - Windows Vista x64 Edition Service Pack 2
    - Windows 7 for 32-bit Systems Service Pack 1
    - Windows 7 for x64-based Systems Service Pack 1
    - Windows 8.1 for 32-bit Systems
    - Windows 8.1 for x64-based Systems
    - Windows RT 8.1
    - Windows 10 for 32-bit Systems
    - Windows 10 for x64-based Systems
    - Windows 10 Version 1511 for 32-bit Systems
    - Windows 10 Version 1511 for x64-based Systems
    - Windows 10 Version 1607 for 32-bit Systems
    - Windows 10 Version 1607 for x64-based Systems
  - Impact: Remote Code Execution
  - Version Number: 1.0
 
MS16-132
 
  - Affected Software:
    - Windows Vista Service Pack 2
    - Windows Vista x64 Edition Service Pack 2
    - Windows Server 2008 for 32-bit Systems Service Pack 2
      (Windows Server 2008 Server Core installation affected)
    - Windows Server 2008 for x64-based Systems Service Pack 2
      (Windows Server 2008 Server Core installation affected)
    - Windows Server 2008 for Itanium-based Systems Service Pack 2
    - Windows 7 for 32-bit Systems Service Pack 1
    - Windows 7 for x64-based Systems Service Pack 1
    - Windows Server 2008 R2 for x64-based Systems Service Pack 1
      (Windows Server 2008 R2 Server Core installation affected)
    - Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
    - Windows 8.1 for 32-bit Systems
    - Windows 8.1 for x64-based Systems
    - Windows Server 2012
      (Windows Server 2012 Server Core installation affected)
    - Windows Server 2012 R2
      (Windows Server 2012 R2 Server Core installation affected)
    - Windows RT 8.1
    - Windows 10 for 32-bit Systems
    - Windows 10 for x64-based Systems
    - Windows 10 Version 1511 for 32-bit Systems
    - Windows 10 Version 1511 for x64-based Systems
    - Windows 10 Version 1607 for 32-bit Systems
    - Windows 10 Version 1607 for x64-based Systems
    - Windows Server 2016 for x64-based Systems
      (Windows Server 2016 Server Core installation affected)
  - Impact: Remote Code Execution
  - Version Number: 1.0
 
MS16-141
 
  - Affected Software:
    - Windows 8.1 for 32-bit Systems
    - Windows 8.1 for x64-based Systems
    - Windows Server 2012
      (Windows Server 2012 Server Core installation not affected)
    - Windows Server 2012 R2
      (Windows Server 2012 R2 Server Core installation not affected)
    - Windows RT 8.1
    - Windows 10 for 32-bit Systems
    - Windows 10 for x64-based Systems
    - Windows 10 Version 1511 for 32-bit Systems
    - Windows 10 Version 1511 for x64-based Systems
    - Windows 10 Version 1607 for 32-bit Systems
    - Windows 10 Version 1607 for x64-based Systems
    - Windows Server 2016 for x64-based Systems
      (Windows Server 2016 Server Core installation not affected)
  - Impact: Remote Code Execution
  - Version Number: 1.0
 
Important Security Bulletins
============================
 
MS16-133
 
  - Affected Software:
    - Microsoft Excel 2007 Service Pack 3
    - Microsoft Excel 2010 Service Pack 2 (32-bit editions)
    - Microsoft Excel 2010 Service Pack 2 (64-bit editions)
    - Microsoft Excel 2013 RT Service Pack 1
    - Microsoft Excel 2013 Service Pack 1 (32-bit editions)
    - Microsoft Excel 2013 Service Pack 1 (64-bit editions)
    - Microsoft Excel 2016 (32-bit edition)
    - Microsoft Excel 2016 (64-bit edition)
    - Microsoft Excel 2016 for Mac
    - Microsoft Excel for Mac 2011
    - Microsoft Excel Viewer
    - Microsoft Office 2007 Service Pack 3
    - Microsoft Office 2010 Service Pack 2 (32-bit editions)
    - Microsoft Office 2010 Service Pack 2 (64-bit editions)
    - Microsoft Office 2013 RT Service Pack 1
    - Microsoft Office 2013 Service Pack 1 (32-bit editions)
    - Microsoft Office 2013 Service Pack 1 (64-bit editions)
    - Microsoft Office 2016 (32-bit edition)
    - Microsoft Office 2016 (64-bit edition)
    - Microsoft Office Compatibility Pack Service Pack 3
    - Microsoft Office Web Apps 2010 Service Pack 2
    - Microsoft Office Web Apps Server 2013 Service Pack 1
    - Microsoft PowerPoint 2010 Service Pack 2 (32-bit editions)
    - Microsoft PowerPoint 2010 Service Pack 2 (64-bit editions)
    - Microsoft PowerPoint Viewer
    - Microsoft SharePoint Server 2010 Service Pack 2
    - Microsoft SharePoint Server 2013 Service Pack 1
    - Microsoft Word 2007
    - Microsoft Word 2010 Service Pack 2 (32-bit editions)
    - Microsoft Word 2010 Service Pack 2 (64-bit editions)
    - Microsoft Word 2013 RT Service Pack 1
    - Microsoft Word 2013 Service Pack 1 (32-bit editions)
    - Microsoft Word 2013 Service Pack 1 (64-bit editions)
    - Microsoft Word 2016 for Mac
    - Microsoft Word for Mac 2011
    - Microsoft Office Word Viewer
  - Impact: Remote Code Execution
  - Version Number: 1.0
 
MS16-134
 
  - Affected Software:
    - Windows Vista Service Pack 2
    - Windows Vista x64 Edition Service Pack 2
    - Windows Server 2008 for 32-bit Systems Service Pack 2
      (Windows Server 2008 Server Core installation affected)
    - Windows Server 2008 for x64-based Systems Service Pack 2
      (Windows Server 2008 Server Core installation affected)
    - Windows Server 2008 for Itanium-based Systems Service Pack 2
    - Windows 7 for 32-bit Systems Service Pack 1
    - Windows 7 for x64-based Systems Service Pack 1
    - Windows Server 2008 R2 for x64-based Systems Service Pack 1
      (Windows Server 2008 R2 Server Core installation affected)
    - Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
    - Windows 8.1 for 32-bit Systems
    - Windows 8.1 for x64-based Systems
    - Windows Server 2012
      (Windows Server 2012 Server Core installation affected)
    - Windows Server 2012 R2
      (Windows Server 2012 R2 Server Core installation affected)
    - Windows RT 8.1
    - Windows 10 for 32-bit Systems
    - Windows 10 for x64-based Systems
    - Windows 10 Version 1511 for 32-bit Systems
    - Windows 10 Version 1511 for x64-based Systems
    - Windows 10 Version 1607 for 32-bit Systems
    - Windows 10 Version 1607 for x64-based Systems
    - Windows Server 2016 for x64-based Systems
      (Windows Server 2016 Server Core installation affected)
  - Impact: Elevation of Privilege
  - Version Number: 1.0
 
MS16-135
 
  - Affected Software:
    - Windows Vista Service Pack 2
    - Windows Vista x64 Edition Service Pack 2
    - Windows Server 2008 for 32-bit Systems Service Pack 2
      (Windows Server 2008 Server Core installation affected)
    - Windows Server 2008 for x64-based Systems Service Pack 2
      (Windows Server 2008 Server Core installation affected)
    - Windows Server 2008 for Itanium-based Systems Service Pack 2
    - Windows 7 for 32-bit Systems Service Pack 1
    - Windows 7 for x64-based Systems Service Pack 1
    - Windows Server 2008 R2 for x64-based Systems Service Pack 1
      (Windows Server 2008 R2 Server Core installation affected)
    - Windows Server 2008 R2 for Itanium-based Systems Service
      Pack 1
    - Windows 8.1 for 32-bit Systems
    - Windows 8.1 for x64-based Systems
    - Windows Server 2012
      (Windows Server 2012 Server Core installation affected)
    - Windows Server 2012 R2
      (Windows Server 2012 R2 Server Core installation affected)
    - Windows RT 8.1
    - Windows 10 for 32-bit Systems
    - Windows 10 for x64-based Systems
    - Windows 10 Version 1511 for 32-bit Systems
    - Windows 10 Version 1511 for x64-based Systems
    - Windows 10 Version 1607 for 32-bit Systems
    - Windows 10 Version 1607 for x64-based Systems
    - Windows Server 2016 for x64-based Systems
      (Windows Server 2016 Server Core installation affected)
  - Impact: Elevation of Privilege
  - Version Number: 1.0
 
MS16-136
 
  - Affected Software:
    - Microsoft SQL Server 2012 for 32-bit Systems
      Service Pack 2 (CU)
    - Microsoft SQL Server 2012 for x64-based Systems
      Service Pack 2 (CU)
    - Microsoft SQL Server 2012 for 32-bit Systems 
      Service Pack 3 (CU)
    - Microsoft SQL Server 2012 for x64-based Systems
      Service Pack 3 (CU)
    - Microsoft SQL Server 2014 Service Pack 1 for
      32-bit Systems (CU)
    - Microsoft SQL Server 2014 Service Pack 1
      for x64-based Systems (CU)
    - Microsoft SQL Server 2014 Service Pack 2
      for 32-bit Systems (CU)
    - Microsoft SQL Server 2014 Service Pack 2 for
      x64-based Systems (CU)
    - Microsoft SQL Server 2016 for x64-based Systems
    - Microsoft SQL Server 2016 for x64-based Systems (CU)
    - Microsoft SQL Server 2012 for 32-bit Systems Service Pack 2
    - Microsoft SQL Server 2012 for x64-based Systems Service Pack 2
    - Microsoft SQL Server 2012 for 32-bit Systems Service Pack 3
    - Microsoft SQL Server 2012 for x64-based Systems Service Pack 3
    - Microsoft SQL Server 2014 Service Pack 1 for 32-bit Systems
    - Microsoft SQL Server 2014 Service Pack 1 for x64-based Systems
    - Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems
    - Microsoft SQL Server 2014 Service Pack 2 for x64-based Systems
  - Impact: Elevation of Privilege
  - Version Number: 1.0
 
MS16-137
 
  - Affected Software:
    - Windows Vista Service Pack 2
    - Windows Vista x64 Edition Service Pack 2
    - Windows Server 2008 for 32-bit Systems Service Pack 2
      (Windows Server 2008 Server Core installation affected)
    - Windows Server 2008 for x64-based Systems Service Pack 2
      (Windows Server 2008 Server Core installation affected)
    - Windows Server 2008 for Itanium-based Systems Service Pack 2
    - Windows 7 for 32-bit Systems Service Pack 1
    - Windows 7 for x64-based Systems Service Pack 1
    - Windows Server 2008 R2 for x64-based Systems Service Pack 1
      (Windows Server 2008 R2 Server Core installation affected)
    - Windows Server 2008 R2 for Itanium-based Systems Service
      Pack 1
    - Windows 8.1 for 32-bit Systems
    - Windows 8.1 for x64-based Systems
    - Windows Server 2012
      (Windows Server 2012 Server Core installation affected)
    - Windows Server 2012 R2
      (Windows Server 2012 R2 Server Core installation affected)
    - Windows RT 8.1
    - Windows 10 for 32-bit Systems
    - Windows 10 for x64-based Systems
    - Windows 10 Version 1511 for 32-bit Systems
    - Windows 10 Version 1511 for x64-based Systems
    - Windows 10 Version 1607 for 32-bit Systems
    - Windows 10 Version 1607 for x64-based Systems
    - Windows Server 2016 for x64-based Systems
      (Windows Server 2016 Server Core installation affected)
  - Impact: Elevation of Privilege
  - Version Number: 1.0
 
MS16-138
 
  - Affected Software:
    - Windows 8.1 for 32-bit Systems
    - Windows 8.1 for x64-based Systems
    - Windows Server 2012
      (Windows Server 2012 Server Core installation affected)
    - Windows Server 2012 R2
      (Windows Server 2012 R2 Server Core installation affected)
    - Windows RT 8.1
    - Windows 10 for 32-bit Systems
    - Windows 10 for x64-based Systems
    - Windows 10 Version 1511 for 32-bit Systems
    - Windows 10 Version 1511 for x64-based Systems
    - Windows 10 Version 1607 for 32-bit Systems
    - Windows 10 Version 1607 for x64-based Systems
    - Windows Server 2016 for x64-based Systems
      (Windows Server 2016 Server Core installation affected)
  - Impact: Elevation of Privilege
  - Version Number: 1.0
 
MS16-139
 
  - Affected Software:
    - Windows Vista Service Pack 2
    - Windows Vista x64 Edition Service Pack 2
    - Windows Server 2008 for 32-bit Systems Service Pack 2
      (Windows Server 2008 Server Core installation affected)
    - Windows Server 2008 for x64-based Systems Service Pack 2
      (Windows Server 2008 Server Core installation affected)
    - Windows Server 2008 for Itanium-based Systems Service Pack 2
    - Windows 7 for 32-bit Systems Service Pack 1
    - Windows 7 for x64-based Systems Service Pack 1
    - Windows Server 2008 R2 for x64-based Systems Service Pack 1
      (Windows Server 2008 R2 Server Core installation affected)
    - Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
  - Impact: Elevation of Privilege
  - Version Number: 1.0
 
MS16-140
 
  - Affected Software:
    - Windows 8.1 for 32-bit Systems
    - Windows 8.1 for x64-based Systems
    - Windows Server 2012
      (Windows Server 2012 Server Core installation affected)
    - Windows Server 2012 R2
      (Windows Server 2012 R2 Server Core installation affected)
    - Windows RT 8.1
    - Windows 10 for 32-bit Systems
    - Windows 10 for x64-based Systems
    - Windows 10 Version 1511 for 32-bit Systems
    - Windows 10 Version 1511 for x64-based Systems
    - Windows 10 Version 1607 for 32-bit Systems
    - Windows 10 Version 1607 for x64-based Systems
    - Windows Server 2016 for x64-based Systems
      (Windows Server 2016 Server Core installation affected)
  - Impact: Security Feature Bypass
  - Version Number: 1.0
 
 
Other Information
=================
 
Recognize and avoid fraudulent email to Microsoft customers:
=============================================================
If you receive an email message that claims to be distributing a Microsoft security update, it is a hoax that may contain malware or pointers to malicious websites. Microsoft does not distribute security updates via email.
 
Daniel

Ssherjj
Moderator
Forum|alt.badge.img+62
  • Moderator
  • 21892 replies
  • November 11, 2016
Wow that's quite a list! Thanks Daniel!:D

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54
Sherry is right, that is quite a large list.
 
Thank you Daniel.

Reply