MS15-025: Description of the security update for Windows kernel: March 10, 2015

Summary

This security update resolves privately reported vulnerabilities in Windows. The most severe effect of the vulnerabilities is elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application. An attacker who has successfully exploited the vulnerabilities could run arbitrary code in the security context of the account of another user who is logged on to the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts that have full user rights. To learn more about the vulnerabilities, see Microsoft Security Bulletin MS15-025.

Known issues

For Windows 7 and Windows Server 2008 R2, the security update 3035131 shares affected binaries with the security update that is described in Security Advisory 3033929. This overlap in affected binaries causes one update to supersede the other. In this case, security advisory update 3033929 supersedes security update 3035131.

If you have automatic updating enabled, you should experience no unusual installation behavior. Both updates should install automatically and both updates appear in the list of installed updates.

However, if you download and install updates manually, you have to install security update 3035131 before you install security advisory update 3033929. Otherwise, when you install security update 3035131, you may receive a message that states that update 3035131 is already installed, and security update 3035131 is not added to the list of installed updates.

How to obtain and install the update

Method 1: Windows Update

This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, see Get security updates automatically.

Note For Windows RT and Windows RT 8.1, this update is available through Windows Update only.

Method 2: Microsoft Download Center

You can obtain the stand-alone update package through the Microsoft Download Center. Follow the installation instructions on the download page to install the update.

Click the download link in the following table that corresponds to the version of Windows you are running.

Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s