Microsoft Releases 9 Security Updates to Patch 34 Vulnerabilities

In Brief
Microsoft’s August Patch Tuesday offers nine security bulletins with five rated critical, resolving 34 security vulnerabilities in Internet Explorer (IE), Edge, and Office, as well as some serious high-profile security issues with Windows.

A security bulletin, MS16-102, patches a single vulnerability (CVE-2016-3319) that could allow an attacker to control your computer just by

SEC Consult SA-20160810-0 :: Multiple vulnerabilities in LINE instant messenger platform

Posted by SEC Consult Vulnerability Lab on Aug 10

SEC Consult Vulnerability Lab Security Advisory < 20160810-0 >
=======================================================================
title: Multiple vulnerabilities
product: LINE instant messenger platform
vulnerable version: before June 2016
fixed version: after June/July 2016
impact: removed (as per bounty program policy)
homepage: http://line.me/en/
found:…

CVE-2016-3237

Kerberos in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows man-in-the-middle attackers to bypass authentication via vectors related to a fallback to NTLM authentication during a domain account password change, aka “Kerberos Elevation of Privilege Vulnerability.”

CVE-2016-3288

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web page, aka “Internet Explorer Memory Corruption Vulnerability,” a different vulnerability than CVE-2016-3290.