MS15-025: Description of the security update for Windows kernel: March 10, 2015

Applies to: Windows Server 2012 R2 DatacenterWindows Server 2012 R2 StandardWindows Server 2012 R2 Essentials


This security update resolves privately reported vulnerabilities in Windows. The most severe effect of the vulnerabilities is elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application. An attacker who has successfully exploited the vulnerabilities could run arbitrary code in the security context of the account of another user who is logged on to the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts that have full user rights. To learn more about the vulnerabilities, see Microsoft Security Bulletin MS15-025.

Known issues

For Windows 7 and Windows Server 2008 R2, the security update 3035131 shares affected binaries with the security update that is described in Security Advisory 3033929. This overlap in affected binaries causes one update to supersede the other. In this case, security advisory update 3033929 supersedes security update 3035131. 

If you have automatic updating enabled, you should experience no unusual installation behavior. Both updates should install automatically and both updates appear in the list of installed updates.

However, if you download and install updates manually, you have to install security update 3035131 before you install security advisory update 3033929. Otherwise, when you install security update 3035131, you may receive a message that states that update 3035131 is already installed, and security update 3035131 is not added to the list of installed updates. 

How to obtain and install the update

Method 1: Windows Update

This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, see Get security updates automatically.

Note For Windows RT and Windows RT 8.1, this update is available through Windows Update only.

More Information