MS15-097: Vulnerabilities in the Microsoft graphics component could allow remote code execution: September 8, 2015

Summary

This security update resolves vulnerabilities in Windows, Microsoft Office, and Microsoft Lync. The most severe of the vulnerabilities could allow remote code execution if a user opens a specially crafted document or goes to an untrusted webpage that contains embedded OpenType fonts.

To learn more about the vulnerability, see Microsoft Security Bulletin MS15-097.

More Information

Important
  • All future security and nonsecurity updates for Windows RT 8.1, Windows 8.1, and Windows Server 2012 R2 require update 2919355 to be installed. We recommend that you install update 2919355 on your Windows RT 8.1-based, Windows 8.1-based, or Windows Server 2012 R2-based computer so that you receive future updates.
  • If you install a language pack after you install this update, you must reinstall this update. Therefore, we recommend that you install any language packs that you need before you install this update. For more information, see Add language packs to Windows.

Additional information about this security update


The following articles contain additional information about this security update as it relates to individual product versions. The articles may contain known issue information.
  • 2910994 MS15-097: Description of the security update for Skype for Business 2016: September 30, 2015
  • 3086255 MS15-097: Description of the security update for the graphics component in Windows: September 8, 2015
  • 3087039 MS15-097: Description of the security update for the graphics component in Windows: September 8, 2015
  • 3087135 MS15-097: Description of the security update for the graphics component in Windows Vista and Windows Server 2008: September 8, 2015
  • 3085546 MS15-097: Description of the security update for the 2007 Microsoft Office Suite: September 8, 2015
  • 3085529 MS15-097: Description of the security update for Office 2010: September 8, 2015
  • 3085500 MS15-097: Description of the security update for Microsoft Lync 2013 (Skype for Business): September 8, 2015


    Known issues in security update 3085500:
    3099414 You can't record after you install MS15-097 for Lync 2013 (Skype for Business)
  • 3081087 MS15-097: Description of the security update for Lync 2010: September 8, 2015
  • 3081088 MS15-097: Description of the security update for Lync 2010 Attendee (user-level installation): September 8, 2015
  • 3081089 MS15-097: Description of the security update for Lync 2010 Attendee (administrator-level installation): September 8, 2015
  • 3081090 MS15-097: Description of the security update for Live Meeting Console: September 8, 2015
  • 3081091 MS15-097: Description of the security update for Live Meeting Conferencing Add-in: September 8, 2015

How to obtain and install the update

Method 1: Windows Update

This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, see
Get security updates automatically.

Note For Windows RT and Windows RT 8.1, this update is available through Windows Update only.
Method 2: Microsoft Download Center

More Information

Security update deployment information
File hash information
How to obtain help and support for this security update
Properties

Article ID: 3089656 - Last Review: Sep 30, 2015 - Revision: 1

Windows 10, Windows Server 2012 R2 Datacenter, Windows Server 2012 R2 Standard, Windows Server 2012 R2 Essentials, Windows Server 2012 R2 Foundation, Windows 8.1 Enterprise, Windows 8.1 Pro, Windows 8.1, Windows RT 8.1, Windows Server 2012 Datacenter, Windows Server 2012 Datacenter, Windows Server 2012 Datacenter, Windows Server 2012 Datacenter, Windows Server 2012 Standard, Windows Server 2012 Standard, Windows Server 2012 Standard, Windows Server 2012 Standard, Windows Server 2012 Essentials, Windows Server 2012 Foundation, Windows Server 2012 Foundation, Windows Server 2012 Foundation, Windows Server 2012 Foundation, Windows 8 Enterprise, Windows 8 Pro, Windows 8, Windows RT, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Datacenter, Windows Server 2008 R2 Enterprise, Windows Server 2008 R2 Standard, Windows Web Server 2008 R2, Windows Server 2008 R2 Foundation, Windows 7 Service Pack 1, Windows 7 Ultimate, Windows 7 Enterprise, Windows 7 Professional, Windows 7 Home Premium, Windows 7 Home Basic, Windows 7 Starter, Windows Server 2008 Service Pack 2, Windows Server 2008 Datacenter, Windows Server 2008 Enterprise, Windows Server 2008 Standard, Windows Web Server 2008, Windows Server 2008 Foundation, Windows Server 2008 for Itanium-Based Systems, Windows Vista Service Pack 2, Windows Vista Ultimate, Windows Vista Enterprise, Windows Vista Business, Windows Vista Home Premium, Windows Vista Home Basic, Windows Vista Starter, Microsoft Lync 2013, Microsoft Lync 2010 Attendee, Microsoft Lync 2010, Skype for Business, Microsoft Office 2010 Service Pack 2, 2007 Microsoft Office Suite Service Pack 3, Microsoft Office Enterprise 2007, Microsoft Office Enterprise 2007 Home Use Program, Microsoft Office Professional 2007, Microsoft Office Standard 2007, Microsoft Office Home and Student 2007, Microsoft Office Small Business 2007, Microsoft Office Basic 2007, Microsoft Office Live Meeting 2007

Feedback