August 2016 Patch Tuesday: Microsoft releases 9 security updates, 5 rated critical
Summary
Microsoft released nine security bulletins, five of which were rated critical due to remote code execution (RCE) vulnerabilities. Michael Gray, vice president of technology at Thrive Networks, suggested, “It stands to reason that Microsoft may have kept things simple so as not to over-shadow the release of their Windows 10 Anniversary update.” MS16-095 is the cumulative monthly fix for Internet Explorer. Bobby Kuzma, CISSP, systems engineer at Core Security, added: This Office update includes a fix for an ASLR bypass. It hasnt been publicly disclosed, although with the prevalence of PDF format, its a safe bet that this going to live in the attacker’s toolkits for years to come. If exploited, Microsoft said an attacker “could disable code integrity checks, allowing test-signed executables and drivers to be loaded into a target device.