Skip to main content

Microsoft January 2017 Security Bulletin

Microsoft's monthly release of patches in January includes a total of 4 security bulletins with only 1 receiving the highest rating of critical.

Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Microsoft's monthly release of patches in January includes a total of 4 security bulletins with only 1 receiving the highest rating of critical.


Affected platforms

The following platforms are known to be affected:

Threat details

The critical bulletin MS17-003 includes 12 vulnerabilities relating to Adobe Flash Player:

CVE-2017-2925, CVE-2017-2926, CVE-2017-2927, CVE-2017-2928, CVE-2017-2930, CVE-2017-2931, CVE-2017-2932, CVE-2017-2933, CVE-2017-2934, CVE-2017-2935, CVE-2017-2936, CVE-2017-2937.

Deployments on Windows 8.1, Windows 10 and Windows Server are all affected by critical remote code execution vulnerabilities whereas Windows Server 2012 are rated as moderate.

For further information please visit https://technet.microsoft.com/en-us/security/bulletins.aspx


Remediation steps

Type Step
  • Ensure all available patches are applied at the earliest available opportunity.
  • Prioritise vulnerabilities that have received public disclosure due to the heightened risk of attacks.
  • Many of the mentioned vulnerabilities only allow access at the privilege level on the logged in user upon a successful compromise. Therefore good management of user privileges and restricting the use of administrator accounts where possible will help mitigate the impact in the event that an attack is successful.


Last edited: 15 December 2021 12:21 pm