
====================================================================

                               CERT-Renater

                  Note d'Information No. 2016/VULN164
_____________________________________________________________________

DATE                : 13/04/2016

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S):Windows versions Vista, Server 2008, 7, 8.1,
                      RT 8.1, Server 2012 running Windows OLE.

======================================================================
KB3146706
https://technet.microsoft.com/en-us/library/security/MS16-044
_____________________________________________________________________

Microsoft Security Bulletin MS16-044: Security Update for Windows OLE 
(3146706)

Bulletin Number: MS16-044

Bulletin Title: Security Update for Windows OLE

Severity: Important

KB Article: 3146706

Version: 1.0

Published Date: April 12, 2016


Executive Summary
This security update resolves a vulnerability in Microsoft Windows. The
vulnerability could allow remote code execution if Windows OLE fails to
properly validate user input. An attacker could exploit the
vulnerability to execute malicious code. However, an attacker must
first convince a user to open either a specially crafted file or a
program from either a webpage or an email message.

This security update is rated Important for all supported editions of
Microsoft Windows, except for Windows 10.


Affected Software

Windows Vista Service Pack 2(3146706)

Windows Vista x64 Edition Service Pack 2(3146706)

Windows Server 2008 for 32-bit Systems Service Pack 2(3146706)

Windows Server 2008 for x64-based Systems Service Pack 2(3146706)

Windows Server 2008 for Itanium-based Systems Service Pack 2(3146706)

Windows 7 for 32-bit Systems Service Pack 1(3146706)

Windows 7 for x64-based Systems Service Pack 1(3146706)

Windows Server 2008 R2 for x64-based Systems Service Pack 1(3146706)

Windows Server 2008 R2 for Itanium-based Systems Service Pack 1(3146706)

Windows 8.1 for 32-bit Systems(3146706)

Windows 8.1 for x64-based Systems(3146706)

Windows Server 2012(3146706)

Windows Server 2012 R2(3146706)

Windows RT 8.1[1] (3146706)

Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core
installation) (3146706)

Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core
installation) (3146706)

Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core
installation) (3146706)

Windows Server 2012 (Server Core installation) (3146706)

Windows Server 2012 R2 (Server Core installation) (3146706)

[1]This update is available via Windows Update.


Vulnerability Information

Windows OLE Remote Code Execution Vulnerability - CVE-2016-0153
A remote code execution vulnerability exists when Microsoft Windows OLE
fails to properly validate user input. An attacker could exploit the
vulnerability to execute malicious code.

To exploit the vulnerability, an attacker would have to convince a user
to open either a specially crafted file or a program from either a
webpage or an email message. The update addresses the vulnerability by
correcting how Windows OLE validates user input.

The following table contains links to the standard entry for each
vulnerability in the Common Vulnerabilities and Exposures list:

Vulnerability title    CVE number      Publicly disclosed   Exploited
Windows OLE Remote Code
Execution Vulnerability   CVE-2016-0153     No              No


==========================================================
Serveur de référence du CERT-Renater
https://services.renater.fr/ssi/
==========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44           +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41           +
+ 75013 Paris           | email: cert@support.renater.fr +
==========================================================




