MS15-087: Description of the security update for UDDI services in Windows: August 11, 2015

Summary
This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker engineered a cross-site scripting (XSS) scenario by inserting a malicious script into a webpage search parameter. A user would have to visit a specially crafted webpage where the malicious script would then be executed.

To learn more about the vulnerability, see Microsoft Security Bulletin MS15-087.
More information
Important
  • If you install a language pack after you install this update, you must reinstall this update. Therefore, we recommend that you install any language packs that you need before you install this update. For more information, see Add language packs to Windows.
How to obtain and install the update

Method 1: Windows Update

This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, see Get security updates automatically.

Method 2: Microsoft Download Center

You can obtain the stand-alone update package through the Microsoft Download Center. Follow the installation instructions on the download page to install the update.

Click the download link in Microsoft Security Bulletin MS15-087 that corresponds to the version of Windows that you are running.
More information

File information

The English (United States) version of this software update installs files that have the attributes that are listed in the following tables. The dates and times for these files are listed in Coordinated Universal Time (UTC). The dates and times for these files on your local computer are displayed in your local time and with your current daylight saving time (DST) bias. Additionally, the dates and times may change when you perform certain operations on the files.

Windows Server 2008 file information

  • The files that apply to a specific product, milestone (SPn), and service branch (LDR, GDR) can be identified by examining the file version numbers as shown in the following table:
    VersionProductMilestoneService branch
    6.0.6002.18xxxWindows Vista SP2 and Windows Server 2008 SP2SP2GDR
    6.0.6002.23xxxWindows Vista SP2 and Windows Server 2008 SP2SP2LDR
  • GDR service branches contain only those fixes that are widely released to address widespread, critical issues. LDR service branches contain hotfixes in addition to widely released fixes.
Note The MANIFEST files (.manifest) and MUM files (.mum) that are installed are not listed.

For all supported x86-based versions of Windows Vista and Windows Server 2008

File nameFile versionFile sizeDateTimePlatform
Default.aspxNot Applicable1,12316-Apr-200800:40Not Applicable
Frames.aspxNot Applicable2,61920-Jun-201513:13Not Applicable
Help.aspxNot Applicable1,13516-Apr-200800:40Not Applicable
Results.aspxNot Applicable12,90916-Apr-200800:40Not Applicable
Search.aspxNot Applicable17,52116-Apr-200800:40Not Applicable
Default.aspxNot Applicable1,12307-May-201423:45Not Applicable
Frames.aspxNot Applicable2,61920-Jun-201513:14Not Applicable
Help.aspxNot Applicable1,13507-May-201423:45Not Applicable
Results.aspxNot Applicable12,90907-May-201423:45Not Applicable
Search.aspxNot Applicable17,52107-May-201423:45Not Applicable

For all supported x64-based versions of Windows Vista and Windows Server 2008

File nameFile versionFile sizeDateTimePlatform
Default.aspxNot Applicable1,12303-Sep-200818:50Not Applicable
Frames.aspxNot Applicable2,61920-Jun-201513:13Not Applicable
Help.aspxNot Applicable1,13503-Sep-200818:50Not Applicable
Results.aspxNot Applicable12,90903-Sep-200818:50Not Applicable
Search.aspxNot Applicable17,52103-Sep-200818:50Not Applicable
Default.aspxNot Applicable1,12307-May-201423:45Not Applicable
Frames.aspxNot Applicable2,61920-Jun-201513:14Not Applicable
Help.aspxNot Applicable1,13507-May-201423:45Not Applicable
Results.aspxNot Applicable12,90907-May-201423:45Not Applicable
Search.aspxNot Applicable17,52107-May-201423:45Not Applicable

How to obtain help and support for this security update

Help for installing updates: Support for Microsoft Update

Security solutions for IT professionals: TechNet Security Troubleshooting and Support

Help for protecting your Windows-based computer from viruses and malware: Virus Solution and Security Center

Local support according to your country: International Support
malicious attacker exploit
Properties

Article ID: 3073893 - Last Review: 08/11/2015 17:23:00 - Revision: 1.0

Windows Server 2008 Service Pack 2

  • atdownload kbbug kbexpertiseinter kbfix kbsecbulletin kbsecurity kbsecvulnerability KB3073893
Feedback