Security Advisory - October 13, 2015
Zscaler Protects against Multiple Security Vulnerabilities in Internet Explorer, Windows kernel and Microsoft edge.
Zscaler, working with Microsoft through their MAPP program, has proactively deployed protections for the following 13 vulnerabilities included in the October 2015 Microsoft security bulletins. Zscaler will continue to monitor exploits associated with all vulnerabilities in the October release and deploy additional protections as necessary.
MS15-111 - Security Update for Windows Kernel to Address Elevation of Privilege
Severity: Important
Affected Software
- Windows Vista
- Windows Server 2008
- Windows 7
- Windows Server 2008 R2
- Windows 8 and Windows 8.1
- Windows Server 2012 and Windows Server 2012 R2
- Windows RT and Windows RT 8.1
- Windows 10
CVE-2015-2549 - Windows Kernel Memory Corruption Vulnerability
CVE-2015-2550 - Windows Elevation of Privilege Vulnerability
Description: This security update resolves vulnerabilities in Microsoft Windows. The more severe of the vulnerabilities could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application
MS15-109 – Security Update for Windows Shell to Address Remote Code Execution
Severity: Critical
Affected Software:
- Windows Vista
- Windows Server 2008
- Windows 7
- Windows Server 2008 R2
- Windows 8 and Windows 8.1
- Windows Server 2012 and Windows Server 2012 R2
- Windows RT and Windows RT 8.1
- Windows 10
CVE-2015-2515 - Toolbar Use After Free Vulnerability
CVE-2015-2548 - Microsoft Tablet Input Band Use After Free Vulnerability
Description: This security update resolves vulnerabilities in Microsoft Windows. The vulnerabilities could allow remote code execution if a user opens a specially crafted toolbar object in Windows or an attacker convinces a user to view specially crafted content online.
MS15-107 – Cumulative Security Update for Microsoft Edge
Severity: Important
Affected Software:
- Microsoft Edge
CVE-2015-6058 - XSS Filter Bypass in Microsoft Edge
Description: This security update resolves vulnerabilities in Microsoft Edge. The most severe of the vulnerabilities could allow information disclosure if a user views a specially crafted webpage using Microsoft Edge. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. Customers whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
MS15-106 – Cumulative Security Update for Internet Explorer
Severity: Critical
Affected Software:
- Internet Explorer 7-11
CVE-2015-6059 - Information Disclosure Vulnerability
CVE-2015-6055 - Scripting Engine Memory Corruption Vulnerability
CVE-2015-6050 - Memory Corruption Vulnerability
CVE-2015-6049 - Memory Corruption Vulnerability
CVE-2015-6048 - Memory Corruption Vulnerability
CVE-2015-6047 - Elevation of Privilege Vulnerability
CVE-2015-6042 - Memory Corruption Vulnerability
CVE-2015-2482 - Scripting Engine Memory Corruption Vulnerability
Description: This security update resolves vulnerabilities in Internet Explorer. The most severe of the vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. Customers whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.