To learn more about the vulnerabilities, see ADV180002.
How to obtain and install the update
Known issues in this hotfix
Report Builder does not start after you install security update for SQL Server 2012 SP4 GDR.
A supported update is available to fix this issue:
On-demand hotfix update package for SQL Server 2012 SP4
The English (United States) version of this software update installs files that have the attributes that are listed in the following tables. The dates and times for these files are listed in Coordinated Universal Time (UTC). The dates and times for these files on your local computer are displayed in your local time together with your current daylight-saving time (DST) bias. Additionally, the dates and times may change when you perform certain operations on the files.
The MANIFEST files (.manifest) and MUM files (.mum) that are installed are not listed.