Microsoft Critical Security Bulletins Summary for February 2016

Number: AV16-024
Date: 9 February 2016


The purpose of this advisory is to bring attention to the monthly Microsoft Security Bulletin Summary for February 2016.


The summary covers 13 bulletins (6 Critical and 7 Important), which addresses multiple vulnerabilities in Internet Explorer, Microsoft Edge, Microsoft Office Services and Web Apps, Microsoft Office, Microsoft Windows, Microsoft Server, Microsoft Windows , Adobe Flash Player and Microsoft .NET Framework.

MS16-009 Cumulative Security Update for Internet Explorer (3134220)
MS16-011 Cumulative Security Update for Microsoft Edge (3134225) 
MS16-012 Security Update for Microsoft Windows PDF Library to Address Remote Code Execution (3138938)
MS16-013 Security Update for Windows Journal to Address Remote Code Execution (3134811)
MS16-015 Security Update for Microsoft Office to Address Remote Code Execution (3134226) 
MS16-022 Security Update for Adobe Flash Player (3135782)

MS16-014 Security Update for Microsoft Windows to Address Remote Code Execution (3134228) 
MS16-016 Security Update for WebDAV to Address Elevation of Privilege (3136041)
MS16-017 Security Update for Remote Desktop Display Driver to Address Elevation of Privilege (3134700) 
MS16-018 Security Update for Windows Kernel-Mode Drivers to Address Elevation of Privilege (3136082) 
MS16-019 Security Update for .NET Framework to Address Denial of Service (3137893) 
MS16-020 Security Update for Active Directory Federation Services to Address Denial of Service (3134222)
MS16-021 Security Update for NPS RADIUS Server to Address Denial of Service (3133043) 

Suggested Action

CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.


Note to Readers

In support of Public Safety's mission to build a safe and resilient Canada, CCIRC's mandate is to help ensure the security and resilience of the vital non-federal government cyber systems that underpin Canada's national security, public safety and economic prosperity. As Canada's computer security incident response team, CCIRC is Canada's national coordination centre for the prevention and mitigation of, preparedness for, response to, and recovery from cyber incidents on non-federal government systems. It does this by providing authoritative advice and support, and coordinating information sharing and incident response.

Please note, CCIRC PGP key has recently been updated.

For general information, please contact Public Safety Canada's Public Affairs division at:

Telephone: 613-944-4875 or 1-800-830-3118
Fax: 613-998-9589

Date modified: