Summary

This security update resolves vulnerabilities in Windows. The most severe of the vulnerabilities could allow remote code execution if an attacker first places a specially crafted dynamic link library (DLL) file in the target user’s current working directory and then convinces the user to open an RDP file or to launch a program that is designed to load a trusted DLL file but instead loads the attacker’s specially crafted DLL file. An attacker who successfully exploited the vulnerabilities could take complete control of an affected system. An attacker could then install programs, could view, change, or delete data, or could create new accounts that have full user rights.

This security update addresses the vulnerability by correcting how the Remote Desktop Session Host (RDSH) validates certificates and how RDP loads certain binaries.

To learn more about the update, see Microsoft Knowledge Base article 3073094.


To learn more about the vulnerability, see Microsoft Security Bulletin MS15-082.

More Information

Important

  • All future security and nonsecurity updates for Windows RT 8.1, Windows 8.1, and Windows Server 2012 R2 require update 2919355 to be installed. We recommend that you install update 2919355 on your Windows RT 8.1-based, Windows 8.1-based, or Windows Server 2012 R2-based computer so that you receive future updates.

  • If you install a language pack after you install this update, you must reinstall this update. Therefore, we recommend that you install any language packs that you need before you install this update. For more information, see Add language packs to Windows.

Additional information about this security update

The following articles contain additional information about this security update as it relates to individual product versions. The articles may contain known issue information.

  • 3075226 MS15-082: Description of the security update for RDP in Windows: August 11, 2015

  • 3075222 MS15-082: Description of the security update for RDP in Windows: August 11, 2015

    Known issues in security update 3075222:


    • After you install or uninstall this security update, you may have to restart the computer two times.

  • 3075221 MS15-082: Description of the security update for RDP in Windows: August 11, 2015

  • 3075220 MS15-082: Description of the security update for RDP in Windows: August 11, 2015

How to obtain and install the update

Method 1: Windows Update

This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, see
Get security updates automatically.

Note For Windows RT and Windows RT 8.1, this update is available only through Windows Update.

You can obtain the stand-alone update package through the Microsoft Download Center. Follow the installation instructions on the download page to install the update.

Click the download link in Microsoft Security Bulletin MS15-082 that corresponds to the version of Windows that you are running.

More Information

Windows Vista (all editions)Reference Table

The following table contains the security update information for this software.

Security update file names

For all supported 32-bit editions of Windows Vista:
Windows6.0-KB3075220-x86.msu
Windows6.0-KB3075221-x86.msu


For all supported x64-based editions of Windows Vista:
Windows6.0-KB3075220-x64.msu
Windows6.0-KB3075221-x64.msu

Installation switches

See Microsoft Knowledge Base Article 934307

Restart requirement

You must restart your system after you apply this security update.

Removal information

WUSA.exe does not support the removal of updates. To uninstall an update that was installed by WUSA, click Control Panel, and then click Security. Under Windows Update, click View installed updates, and select from the list of updates.

File information

See Microsoft Knowledge Base Article 3045171

Registry key verification

Note A registry key does not exist to validate the presence of this update.

Windows Server 2008 (all editions)Reference Table

The following table contains the security update information for this software.

Security update file names

For all supported 32-bit editions of Windows Server 2008:
Windows6.0-KB3075220-x86.msu


For all supported x64-based editions of Windows Server 2008:
Windows6.0-KB3075220-x64.msu


For all supported Itanium-based editions of Windows Server 2008:
Windows6.0-KB3075220-ia64.msu

Installation switches

See Microsoft Knowledge Base Article 934307

Restart requirement

You must restart your system after you apply this security update.

Removal information

WUSA.exe does not support the removal of updates. To uninstall an update that was installed by WUSA, click Control Panel, and then click Security. Under Windows Update, click View installed updates, and select from the list of updates.

File information

See Microsoft Knowledge Base Article 3045171

Registry key verification

Note A registry key does not exist to validate the presence of this update.

Windows 7 (all editions)Reference Table

The following table contains the security update information for this software.

Security update file name

For all supported 32-bit editions of Windows 7:
Windows6.1-KB3075220-x86.msu
Windows6.1-KB3075222-x86.msu
Windows6.1-KB3075226-x86.msu


For all supported x64-based editions of Windows 7:
Windows6.1-KB3075220-x64.msu
Windows6.1-KB3075222-x64.msu
Windows6.1-KB3075226-x86.msu

Installation switches

See Microsoft Knowledge Base Article 934307

Restart requirement

You must restart your system after you apply this security update.

Removal information

To uninstall an update that was installed by WUSA, use the /Uninstall setup switch or click Control Panel, click System and Security, and then under Windows Update, click View installed updates, and select from the list of updates.

File information

See Microsoft Knowledge Base Article 3045171

Registry key verification

Note A registry key does not exist to validate the presence of this update.

Windows Server 2008 R2 (all editions)Reference Table

The following table contains the security update information for this software.

Security update file name

For all supported x64-based editions of Windows Server 2008 R2:
Windows6.1-KB3075220-x64.msu
Windows6.1-KB3075222-x64.msu
Windows6.1-KB3075226-x86.msu


For all supported Itanium-based editions of Windows Server 2008 R2:
Windows6.1-KB3075220-ia64.msu

Installation switches

See Microsoft Knowledge Base Article 934307

Restart requirement

You must restart your system after you apply this security update.

Removal information

To uninstall an update that was installed by WUSA, use the /Uninstall setup switch or click Control Panel, click System and Security, and then under Windows Update, click View installed updates, and select from the list of updates.

File information

See Microsoft Knowledge Base Article 3045171

Registry key verification

Note A registry key does not exist to validate the presence of this update.

Windows 8 and Windows 8.1 (all editions)Reference Table

The following table contains the security update information for this software.

Security update file name

For all supported 32-bit editions of Windows 8:
Windows8-RT-KB3075220-x86.msu


For all supported x64-based editions of Windows 8:
Windows8-RT-KB3075220-x64.msu


For all supported 32-bit editions of Windows 8.1:
Windows8.1-KB3075220-x86.msu


For all supported x64-based editions of Windows 8.1:
Windows8.1-KB3075220-x64.msu

Installation switches

See Microsoft Knowledge Base Article 934307

Restart requirement

You must restart your system after you apply this security update.

Removal information

To uninstall an update that was installed by WUSA, use the /Uninstall setup switch or click Control Panel, click System and Security, click Windows Update, and then under See also, click Installed updates and select from the list of updates.

File information

See Microsoft Knowledge Base Article 3045171

Registry key verification

Note A registry key does not exist to validate the presence of this update.

Windows Server 2012 and Windows Server 2012 R2 (all editions)Reference Table

The following table contains the security update information for this software.

Security update file name

For all supported editions of Windows Server 2012:
Windows8-RT-KB3075220-x64.msu


For all supported editions of Windows Server 2012 R2:
Windows8.1-KB3075220-x64.msu

Installation switches

See Microsoft Knowledge Base Article 934307

Restart requirement

You must restart your system after you apply this security update.

Removal information

To uninstall an update that was installed by WUSA, use the /Uninstall setup switch or click Control Panel, click System and Security, click Windows Update, and then under See also, click Installed updates and select from the list of updates.

File information

See Microsoft Knowledge Base Article 3045171

Registry key verification

Note A registry key does not exist to validate the presence of this update.

Windows RT and Windows RT 8.1 (all editions)Reference Table

The following table contains the security update information for this software.

Deployment

These updates are available through Windows Update only.

Restart Requirement

You must restart your system after you apply this security update.

Removal Information

Click Control Panel, click System and Security, click Windows Update, and then under See also, click Installed updates and select from the list of updates.

File Information

See Microsoft Knowledge Base Article 3045171


File name

SHA1 hash

SHA256 hash

Windows6.0-KB3075220-ia64.msu

42DE6591E1F11B7880D592DE99822D9209DA62E1

9BE293A14D44D1DF73AE91FDFEE439B4797899B4B1DA12E7737484647E1F62C6

Windows6.0-KB3075220-x64.msu

CDB63E470C817A445929AED7521C7103CC8E801E

BE962EFB24BB4853B603EDE6AF0AE94926758BFBA54FDE7F22FEFF3C1429FF7F

Windows6.0-KB3075220-x86.msu

76552E0D4166711A4AC5BEC17CD1AA0789A7FD72

00465D9266E23EA91D5F20556F4C39F69BF221FB41805E53E3004AB967B1D927

Windows6.0-KB3075221-x64.msu

5E96E9CCAD8B302BCC38A1A69C7B7D7C6941D7EA

F29664D5C30DBF769F57E26AB3257974792758F460D7C1F5B23C224CBF5B5F81

Windows6.0-KB3075221-x86.msu

970FF92B910A98E851C24A618D152853B21CABCC

30E217FE4FC6907C00CCA928BF4271B15AF3A1A24F65037E0D7ED35666B6D91E

Windows6.1-KB3075220-ia64.msu

1A84542FEAA7C7D7E5F2A3618EC1A5F43F43EC44

F479E3B6826CCAF58F20DA7BFA9160304C65C675FB06AF1993E8136CEDC76664

Windows6.1-KB3075220-x64.msu

AA1F21337A50E431E65B348C4799B5CA2E9E636F

C8D77DE57760D69BACBB5E1FD0D9422D7FF9BFD0178F310160F3A3370F95180D

Windows6.1-KB3075220-x86.msu

1E46613AED15B1BBA9FB37F2FDDD391D41FF3E49

E118CD6720416C74F72E5EA1BED299FD4EB404FF291743DAD0A03AED599B22D5

Windows6.1-KB3075222-x64.msu

A4FBEFE464E6C9D4C3924516379A570F7884E289

58FA1785C20463A226C00AFD65EA1B73369E4220EC02A0AA43ABA815D6459EFC

Windows6.1-KB3075222-x86.msu

F1EE54E30726E374D6A6673EA197FED8D39C8EF8

F03E8E1EF46DD1DF23325EF2D9869F020BD4B4FFAAC41FB066005C9769788D4A

Windows6.1-KB3075226-x64.msu

EDCAA1B72946B2894F0A3DEBF08ADB059D5A254B

F75AB96003F255EF38DFB40941A9C0751EA9BBADCB0FCF22592E3A4C438E6C9D

Windows6.1-KB3075226-x86.msu

4AC94A6FD2B0038520D9BDAB3D98D3779F557F7F

1FCDE5BC4864D14A893D6863E9934A583841C48E353DB62928C88F2C2EE80BE6

Windows8.1-KB3075220-arm.msu

80C2CE5711A98451BFBA7DD1D83CF7DF207AD737

AC38DC63EE7B16D615002934F810438AC8A456B42AE69F4B80B3B604D05E1CAE

Windows8.1-KB3075220-x64.msu

634EC20FBF0CDAF870D77136EB6E2F3AF0D76809

0EE6806DED0DFE9A040FB9499F1E915F42480A87ACFC0E85071BDA23FBD29507

Windows8.1-KB3075220-x86.msu

DE71F161F9CFC74CE8E2D2104E23528691F73264

37BD5D87BEBD08BD6A98DFF997D80C736C0E529A5F1A44A2F58F67BF96275E3B

Windows8-RT-KB3075220-arm.msu

9362755EB2067A66FDB9694491328D206D41786C

ADC2A8781593BBB266D1D24CA1357E6D0388592C9F9740F187EC12F56B97C625

Windows8-RT-KB3075220-x64.msu

2BF751DB2BD4D2A35D2571771C0DB39FB79BD409

B7A108ED9156EC99D7436A6FCA10DE84FC0B0168E602E2D5F09E93AF6DBC9F01

Windows8-RT-KB3075220-x86.msu

233D6FC97D673F8F14A22BA26B5DFC7A0778875E

AC954F83B47DA00DA7C2558A07F4B64BCC3FE94C2921F3E27C3FB667D609C3AB


Help for installing updates: Support for Microsoft Update

Security solutions for IT professionals: TechNet Security Troubleshooting and Support

Help for protecting your Windows-based computer from viruses and malware: Virus Solution and Security Center

Local support according to your country: International Support

Need more help?

Expand your skills
Explore Training
Get new features first
Join Microsoft Insiders

Was this information helpful?

What affected your experience?

Thank you for your feedback!

×