Microsoft Critical Security Bulletins Summary for May 2016

Number: AV16-076
Date: 10 May 2016

Purpose

The purpose of this advisory is to bring attention to the monthly Microsoft Security Bulletin Summary for May 2016.

Assessment

The summary covers 16 bulletins (8 Critical and  8 Important), which addresses multiple vulnerabilitiesin Microsoft .NET Framework, Microsoft Internet Explorer, Microsoft Edge, Microsoft Office, Jscript, VBScript, Microsoft Graphics Component, Windows Journal, Windows Shell, Windows IIS, Windows Media Center, Windows Kernel, Microsoft RPC, Windows Kernel-Mode Drivers, Adobe Flash Player, Virtual Security Mode, and Volume Manager Driver.

***Critical***

MS16-051 Cumulative Security Update for Internet Explorer (3155533)
MS16-052 Cumulative Security Update for Microsoft Edge (3155538)
MS16-053 Cumulative Security Update for JScript and VBScript (3156764)
MS16-054 Security Update for Microsoft Office (3155544)
MS16-055 Security Update for Microsoft Graphics Component (3156754)
MS16-056 Security Update for Windows Journal (3156761)
MS16-057 Security Update for Windows Shell (3156987)
MS16-064 Security Update for Adobe Flash Player (3157993)

***Important***

MS16-058 Security Update for Windows IIS (3141083)
MS16-059 Security Update for Windows Media Center (3150220)
MS16-060 Security Update for Windows Kernel (3154846)
MS16-061 Security Update for Microsoft RPC (3155520)
MS16-062 Security Update for Windows Kernel-Mode Drivers (3158222)
MS16-065 Security Update for .NET Framework (3156757)
MS16-066 Security Update for Virtual Secure Mode (3155451)
MS16-067 Security Update for Volume Manager Driver (3155784)

Suggested Action

CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.

References:

https://technet.microsoft.com/en-us/library/security/ms16-May

Note to Readers

In support of Public Safety's mission to build a safe and resilient Canada, CCIRC's mandate is to help ensure the security and resilience of the vital non-federal government cyber systems that underpin Canada's national security, public safety and economic prosperity. As Canada's computer security incident response team, CCIRC is Canada's national coordination centre for the prevention and mitigation of, preparedness for, response to, and recovery from cyber incidents on non-federal government systems. It does this by providing authoritative advice and support, and coordinating information sharing and incident response.

Please note, CCIRC PGP key has recently been updated.
http://www.publicsafety.gc.ca/cnt/ntnl-scrt/cbr-scrt/_fl/CCIRCPublicPGPKey.txt

For general information, please contact Public Safety Canada's Public Affairs division at:

Telephone: 613-944-4875 or 1-800-830-3118
Fax: 613-998-9589
E-mail: ps.communications-communications.sp@canada.ca

Date modified: