Microsoft has recently provided some details about the patches that are scheduled to be released on Tuesday, December 13. There are fourteen patches scheduled to be released. Depending on Operating System/application up to three patches are classified as CRITICAL and eleven are classified as IMPORTANT.
As is generally the case, the older the operating system, the more likely the patch is assigned a higher severity. A total of twenty vulnerabilities will be addressed for the following products: Windows, Microsoft Office, Internet Explorer, Microsoft Publisher and Microsoft Media Player.
The breakdown of OS/Application versions and the various criticality of the applicable patches are as follows:
NOTE: Bulletin #1 is assigned a CRITICAL designation for current workstation and Server Operating Systems.
Workstation OS – Bulletin #1
- Windows XP–SP3 32bit – CRITICAL
- Windows XP-SP2 64bit – CRITICAL
- Windows Vista-SP2 – 32 and 64 bit – CRITICAL
- Windows 7 – base and SP1 both 32 and 64 bit – CRITICAL
Server OS – Bulletin #1
- Windows Server 2003-SP2 (32, 64 bit and Itanium systems) – CRITICAL
- Windows Server 2008-SP2 (32, 64 bit and Itanium systems) – CRITICAL
- Windows Server 2008R2- base and SP1 (64 bit and Itanium systems) – CRITICAL
Workstation OS – Bulletin #2
- Windows XP-SP3 32bit – CRITICAL
- Windows XP-SP2 64bit – CRITICAL
- Windows Vista-SP2 – NOT APPLICABLE for 32 or 64 bit Vista systems
- Windows 7-SP1 – NOT APPLICABLE for 32 or 64 bit Windows 7 systems
Server OS – Bulletin #2
- Windows Server 2003-SP2 (32, 64 bit and Itanium) – CRITICAL
- Windows Server 2008-SP2 (32, 64 bit and Itanium) – NOT APPLICABLE for Server 2008 installations
- Windows Server 2008R2-base and SP1 (64 bit and Itanium) – NOT APPLICABLE for Server 2008R2 installations
Workstation OS- Bulletin #3
- Windows XP–SP3 32bit – CRITICAL
- Windows XP-SP2 64bit – CRITICAL
- Windows Vista-SP2 (32 and 64 bit) – CRITICAL
- Windows 7-SP1 (32 and 64 bit) – IMPORTANT
Server OS – Bulletin #3
- Windows Server 2003-SP2 – (32, 64 bit and Itanium) NOT APPLICABLE for Server 2003 installations
- Windows Server 2008-SP2 – (32, 64 bit and Itanium) NOT APPLICABLE for Server 2008 installations
- Windows Server 2008R2-base and SP1 – (64bit and Itanium) NOT APPLICABLE for Server 2008R2 installations
Windows OS – Bulletin #4
- Windows XP-SP3 (32 bit) – IMPORTANT
- Windows XP-SP2 (64 bit) – IMPORTANT
- Windows Vista-SP2 (32 and 64 bit) – IMPORTANT
- Windows 7-SP1 (32 and 64 bit) – IMPORTANT
Server OS – Bulletin #4
- Windows Server 2003-SP2 (32, 64 bit and Itanium) – IMPORTANT
- Windows Server 2008-SP2 (32, 64 bit and Itanium) – IMPORTANT
- Windows Server 2008R2-base and SP1 (64 bit and Itanium) – IMPORTANT
Microsoft Office suites – Bulletin #5
- Office 2003-SP3 – NOT APPLICABLE
- Office 2007-SP2 and SP3 – IMPORTANT
- Office 2010-base and SP1 (32 and 64 bit) – IMPORTANT
- Office 2004 for Mac – NOT APPLICABLE
- Office 2008 for Mac – NOT APPLICABLE
- Office 2011 for Mac – IMPORTANT
Microsoft Office suites – Bulletin #6
- Office 2003-SP3 – Publisher – IMPORTANT
- Office 2007-SP2 and SP3 – Publisher – IMPORTANT
- Office 2010-base and SP1 (32 and 64 bit) – NOT APPLICABLE
- Office 2004 for Mac – NOT APPLICABLE
- Office 2008 for Mac – NOT APPLICABLE
- Office 2011 for Mac – NOT APPLICABLE
Workstation OS – Bulletin #7
- Windows XP–SP3 32bit – IMPORTANT
- Windows XP-SP2 64bit – IMPORTANT
- Windows Vista-SP2 – 32 and 64 bit – NOT APPLICABLE
- Windows 7 – base and SP1 both 32 and 64 bit – NOT APPLICABLE
Server OS – Bulletin #7
- Windows Server 2003-SP2 (32, 64 bit and Itanium) – IMPORTANT
- Windows Server 2008-SP2 (32, 64 bit and Itanium) – NOT APPLICABLE
- Windows Server 2008R2-base and SP1 (64 bit and Itanium) – NOT APPLICABLE
Microsoft Office suites – Bulletin #8
- Office 2003-SP3 – NOT APPLICABLE
- Office 2007-SP2 – Powerpoint – IMPORTANT
- Office 2010-base and SP1 – (32 and 64 bit) Powerpoint – IMPORTANT
- Office 2004 for Mac – NOT APPLICABLE
- Office 2008 for Mac – IMPORTANT
- Office 2011 for Mac – NOT APPLICABLE
Other Microsoft products
- Powerpoint viewer 2007-SP2 – IMPORTANT
- Office Compatibility pack for Word/Excel and Powerpoint 2007 file formats-SP2 – IMPORTANT
Workstation OS – Bulletin #9
- Windows XP–SP3 32bit – IMPORTANT
- Windows XP-SP2 64bit – IMPORTANT
- Windows Vista-SP2 – 32 and 64 bit – IMPORTANT
- Windows 7 – base and SP1 both 32 and 64 bit – IMPORTANT
Server OS – Bulletin #9
- Windows Server 2003-SP2 (32, 64 bit and Itanium) – IMPORTANT
- Windows Server 2008-SP2 (32 and 64 bit) – IMPORTANT NOTE – NOT APPLICABLE for Itanium
- Windows Server 2008R2-base and SP1 (64 bit) – IMPORTANT NOTE – NOT APPLICABLE for Itanium
Microsoft Office Suites – Bulletin #10
- Office 2003-SP3 Excel – IMPORTANT
- Office 2007-SP2 and SP3 – NOT APPLICABLE
- Office 2010 – base and SP1 (32 and 64 bit) – NOT APPLICABLE
- Office 2004 for Mac – IMPORTANT
- Office 2008 for Mac – NOT APPLICABLE
- Office 2011 for Mac – NOT APPLICABLE
Workstation OS – Bulletin #11
- Windows XP-SP3 (32 bit) – IMPORTANT
- Windows XP-SP2 (64 bit) – IMPORTANT
- Windows Vista-SP2 (32 and 64 bit) – IMPORTANT
- Windows 7-base and SP1 (32 and 64 bit) – IMPORTANT
Server OS – Bulletin #11
- Server 2003-SP2 (32, 64 bit and Itanium) – IMPORTANT
- Server 2008-SP2 (32, 64 bit and Itanium) – IMPORTANT
- Server 2008R2 – base and SP1 (64 bit and Itanium) – IMPORTANT
Workstation OS – Bulletin #12
- Windows XP-SP3 (32bit) – IMPORTANT
- Windows XP-SP2 (64 bit) – NOT APPLICABLE
- Windows Vista-SP2 (32 bit) – IMPORTANT – NOTE – NOT APPLICABLE for the 64 bit version of Vista
- Windows 7-base and SP1 (32 bit) – IMPORTANT – NOTE – NOT APPLICABLE for the 64 bit version of Windows 7
Server OS – Bulletin #12
- Server 2003-SP2 (32 bit) – IMPORTANT – NOTE – NOT APPLICABLE for 64 bit and Itanium installations
- Server 2008-SP2 (32 bit) – IMPORTANT – NOTE – NOT APPLICABLE for 64 bit and Itanium installations
- Server 2008R2-base and SP1 – NOT APPLICABLE
Internet Explorer versions 6-9
Workstation OS – Bulletin #13
- Windows XP-SP3 (32 bit) – IMPORTANT – (Internet Explorer version 9 does not run on the 32 bit version of Windows XP)
- Windows XP-SP2 (64 bit) – IMPORTANT – (Internet Explorer version 9 does not run on the 64 bit version of Windows XP)
- Windows Vista-SP2 (64 bit ) – IMPORTANT – (Internet Explorer version 6 does not run on Windows Vista)
- Windows 7-base and SP1 – (32 and 64 bit) – IMPORTANT ( Internet Explorer version 8 and 9 are the only applicable versions for Windows 7)
Server OS – Bulletin #13
- Server 2003-SP2 (32, 64 bit and Itanium) – LOW
- Server 2008-SP2 (32, 64 bit and Itanium) – LOW
- Server 2008R2- base and SP1 (64 bit and Itanium) – IMPORTANT for Internet Explorer version 9 – LOW for Internet Explorer 8
Microsoft Office suites – Bulletin #14
- Office 2003-SP3 – NOT APPLICABLE
- Office 2007-SP2 and SP3 – NOT APPLICABLE
- Office 2010-base and SP1 (32 and 64 bit) – IMPORTANT
Additional details will be available at – http://technet.microsoft.com/en-us/security/bulletin/ms11-dec
Update December 13, 2011
Microsoft has provided additional details on the patches that are being released today. Information is available from the following URLs –
- http://blogs.technet.com/b/msrc/archive/2011/12/13/the-december-bulletins-are-released.aspx
- http://isc.sans.edu/diary/December+2011+Microsoft+Black+Tuesday+Summary/12193
In short, there is at least one vulnerability (MS11-087 – http://technet.microsoft.com/en-us/security/bulletin/ms11-087 ) that is currently being exploited. For that reason, it is recommended that the December patches be applied to both servers and workstations as soon as possible.