MS15-120: Security update for IPsec to address denial of service: November 10, 2015

Summary
This security update resolves a denial of service vulnerability in Microsoft Windows. An attacker who successfully exploited the vulnerability could cause the system to become unresponsive. To exploit the vulnerability, an attacker must have valid credentials.

To learn more about the vulnerability, see Microsoft Security Bulletin MS15-120.
More information
Important
  • If you manually install this security update, we recommend that you install the update on your server-based systems first and then install the update on the client-based systems. Or, install the update on the server-based and client-based systems at the same time.

    Depending on your IPsec implementation, deploying this update to client systems only may result in a loss of network connectivity.
  • All future security and nonsecurity updates for Windows RT 8.1, Windows 8.1, and Windows Server 2012 R2 require update 2919355 to be installed. We recommend that you install update 2919355 on your Windows RT 8.1-based, Windows 8.1-based, or Windows Server 2012 R2-based computer so that you receive future updates.
  • If you install a language pack after you install this update, you must reinstall this update. Therefore, we recommend that you install any language packs that you need before you install this update. For more information, see Add language packs to Windows.
How to obtain and install the update

Method 1: Windows Update

This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, seeGet security updates automatically.

Note For Windows RT and Windows RT 8.1, this update is available through Windows Update only.

Method 2: Microsoft Download Center

You can obtain the stand-alone update package through the Microsoft Download Center. Follow the installation instructions on the download page to install the update.

Click the download link in Microsoft Security Bulletin MS15-120 that corresponds to the version of Windows that you are running.
More information

Security update deployment information

To Windows 8 and Windows 8.1 (all editions)

Reference Table

The following table contains the security update information for this software.
Security update file nameFor all supported 32-bit editions of Windows 8:
Windows8-RT-KB3102939-x86.msu

For all supported x64-based editions of Windows 8:
Windows8-RT-KB3102939-x64.msu

For all supported 32-bit editions of Windows 8.1:
Windows8.1-KB3102939-x86.msu

For all supported x64-based editions of Windows 8.1:
Windows8.1-KB3102939-x64.msu
Installation switchesSee Microsoft Knowledge Base Article 934307
Restart requirementIn some cases, this update does not require a system restart. If the required files are being used, this update will require a system restart. If this behavior occurs, you receive a message that advises you to restart your system.
Removal informationTo uninstall an update that is installed by WUSA, use the /Uninstall setup switch. Or, click Control Panel, click System and Security, and then click Windows Update. Under See also, click Installed updates, and then select from the list of updates.
File informationSee the file information section.
Registry key verificationNote A registry key does not exist to validate the presence of this update.

Windows Server 2012 and Windows Server 2012 R2 (all editions)

Reference Table

The following table contains the security update information for this software.
Security update file nameFor all supported editions of Windows Server 2012:
Windows8-RT-KB3102939-x64.msu

For all supported editions of Windows Server 2012 R2:
Windows8.1-KB3102939-x64.msu
Installation switchesSee Microsoft Knowledge Base Article 934307
Restart requirementIn some cases, this update does not require a system restart. If the required files are being used, this update will require a system restart. If this behavior occurs, you receive a message that advises you to restart your system.
Removal informationTo uninstall an update that is installed by WUSA, use the /Uninstall setup switch. Or, click Control Panel, click System and Security, and then click Windows Update. Under See also, click Installed updates, and then select from the list of updates.
File informationSee the file information section.
Registry key verificationNote A registry key does not exist to validate the presence of this update.

Windows RT and Windows RT 8.1 (all editions)

Reference Table

The following table contains the security update information for this software.
DeploymentThese updates are available through Windows Update only.
Restart requirementYes, you must restart your system after you apply this security update.
Removal informationClick Control Panel, click System and Security, and then click Windows Update. Under See also, click Installed updates, and then select from the list of updates.
File informationSee the file information section.

File hash information

Package NamePackage Hash SHA 1Package Hash SHA 2
Windows8-RT-KB3102939-x86.msuE3BA8513D11160B99DE7874DC82CC87E10D285ABE6CEE790FB5410D382B9A7987532EDD8F90761EA7D753CF4FE5A9DC623C53488
Windows8-RT-KB3102939-x64.msuF56D7AD3E6F87F9B0DC35BC5723E42438E3BA187CF0F22768B869A74A781A0FDA075D1E140ADC1196F22B9BAB878153B01B2F297
Windows8.1-KB3102939-x86.msu30C8E0BF6CD91A669C9BAA7334D490027F00AA956366AA9E2C58A366D1D5D42BA86175C9C22B15D60CD42EFE35D9FEAF1280EB73
Windows8.1-KB3102939-x64.msu194894AEA47349E55B195ACEF50B56930D4540B2F2EAB3C1FF3444E6AA961D391E1D0F64075DFE5D46C4ECF484A641D9B3AB2E84
Windows8-RT-KB3102939-arm.msuB90A261CE4CFA8277F6F77D8065AD68AE4D17F19184FC80EE6C844E95D3CD9A7A052A0EC805289AF9EC05AACC0116566FE008A6A
Windows8.1-KB3102939-arm.msu7CA826FACB7440A1B487EAC3EEA7319BDC5D7E525865F199E61AFE730902164AF520321CE03707A3F755831783BCE704A88CB4AA
Windows8-RT-KB3102939-x64.msuF56D7AD3E6F87F9B0DC35BC5723E42438E3BA187CF0F22768B869A74A781A0FDA075D1E140ADC1196F22B9BAB878153B01B2F297
Windows8-RT-KB3102939-x64.msuF56D7AD3E6F87F9B0DC35BC5723E42438E3BA187CF0F22768B869A74A781A0FDA075D1E140ADC1196F22B9BAB878153B01B2F297
Windows8.1-KB3102939-x64.msu194894AEA47349E55B195ACEF50B56930D4540B2F2EAB3C1FF3444E6AA961D391E1D0F64075DFE5D46C4ECF484A641D9B3AB2E84
Windows8.1-KB3102939-x64.msu194894AEA47349E55B195ACEF50B56930D4540B2F2EAB3C1FF3444E6AA961D391E1D0F64075DFE5D46C4ECF484A641D9B3AB2E84

File information

The English (United States) version of this software update installs files that have the attributes that are listed in the following tables. The dates and times for these files are listed in Coordinated Universal Time (UTC). The dates and times for these files on your local computer are displayed in your local time and with your current daylight saving time (DST) bias. Additionally, the dates and times may change when you perform certain operations on the files.

Windows 8 and Windows Server 2012 file information

  • The files that apply to a specific product, milestone (RTM,SPn), and service branch (LDR, GDR) can be identified by examining the file version numbers as shown in the following table:
    VersionProductMilestoneService branch
    6.2.920 0.17 xxxWindows 8, Windows RT, or Windows Server 2012RTMGDR
    6.2.920 0.21 xxxWindows 8, Windows RT, or Windows Server 2012RTMLDR
  • GDR service branches contain only those fixes that are widely released to address widespread, critical issues. LDR service branches contain hotfixes in addition to widely released fixes.
Note The MANIFEST files (.manifest) and MUM files (.mum) that are installed are not listed.

For all supported x86-based versions of Windows 8

File nameFile versionFile sizeDateTimePlatform
Bfe.dll6.2.9200.17539473,60011-Oct-201506:52x86
Fwpuclnt.dll6.2.9200.16634245,24810-Jun-201319:10x86
Ikeext.dll6.2.9200.17539684,03211-Oct-201506:52x86
Nshwfp.dll6.2.9200.17218702,46418-Dec-201406:20x86
Bfe.dll6.2.9200.21656473,60012-Oct-201515:00x86
Fwpuclnt.dll6.2.9200.21656245,24812-Oct-201515:00x86
Ikeext.dll6.2.9200.21656684,03212-Oct-201515:00x86
Nshwfp.dll6.2.9200.21317702,46418-Dec-201400:38x86
Bfe.dll6.2.9200.17539473,60011-Oct-201506:52x86
Fwpuclnt.dll6.2.9200.16634245,24810-Jun-201319:10x86
Ikeext.dll6.2.9200.17539684,03211-Oct-201506:52x86
Networksecurity-ppdlic.xrm-msNot Applicable2,92011-Oct-201507:24Not Applicable
Nshwfp.dll6.2.9200.17218702,46418-Dec-201406:20x86
Wfplwfs.sys6.2.9200.1721838,72018-Dec-201407:02x86
Bfe.dll6.2.9200.21656473,60012-Oct-201515:00x86
Fwpuclnt.dll6.2.9200.21656245,24812-Oct-201515:00x86
Ikeext.dll6.2.9200.21656684,03212-Oct-201515:00x86
Networksecurity-ppdlic.xrm-msNot Applicable2,92012-Oct-201515:21Not Applicable
Nshwfp.dll6.2.9200.21317702,46418-Dec-201400:38x86
Wfplwfs.sys6.2.9200.2131738,72018-Dec-201401:29x86

For all supported x64-based versions of Windows 8 and Windows Server 2012

File nameFile versionFile sizeDateTimePlatform
Bfe.dll6.2.9200.17539723,96811-Oct-201506:45x64
Fwpuclnt.dll6.2.9200.16634381,95210-Jun-201319:15x64
Ikeext.dll6.2.9200.175391,160,19211-Oct-201506:45x64
Nshwfp.dll6.2.9200.17218889,34418-Dec-201406:52x64
Bfe.dll6.2.9200.21656718,84812-Oct-201514:33x64
Fwpuclnt.dll6.2.9200.21656378,88012-Oct-201514:33x64
Ikeext.dll6.2.9200.216561,074,68812-Oct-201514:33x64
Nshwfp.dll6.2.9200.21317889,34418-Dec-201400:46x64
Bfe.dll6.2.9200.17539723,96811-Oct-201506:45x64
Fwpuclnt.dll6.2.9200.16634381,95210-Jun-201319:15x64
Ikeext.dll6.2.9200.175391,160,19211-Oct-201506:45x64
Networksecurity-ppdlic.xrm-msNot Applicable2,92011-Oct-201508:33Not Applicable
Nshwfp.dll6.2.9200.17218889,34418-Dec-201406:52x64
Wfplwfs.sys6.2.9200.1721896,57618-Dec-201408:51x64
Bfe.dll6.2.9200.21656718,84812-Oct-201514:33x64
Fwpuclnt.dll6.2.9200.21656378,88012-Oct-201514:33x64
Ikeext.dll6.2.9200.216561,074,68812-Oct-201514:33x64
Networksecurity-ppdlic.xrm-msNot Applicable2,92012-Oct-201514:44Not Applicable
Nshwfp.dll6.2.9200.21317889,34418-Dec-201400:46x64
Wfplwfs.sys6.2.9200.2131796,57618-Dec-201402:58x64
Fwpuclnt.dll6.2.9200.16634245,24810-Jun-201319:10x86
Nshwfp.dll6.2.9200.17218702,46418-Dec-201406:20x86
Fwpuclnt.dll6.2.9200.21656245,24812-Oct-201515:00x86
Nshwfp.dll6.2.9200.21317702,46418-Dec-201400:38x86

Windows 8.1 and Windows Server 2012 R2 file information

  • The files that apply to a specific product, milestone (RTM,SPn), and service branch (LDR, GDR) can be identified by examining the file version numbers as shown in the following table:
    VersionProductMilestoneService branch
    6.3.920 0.17 xxxWindows RT 8.1, Windows 8.1, and Windows Server 2012 R2RTMGDR
  • GDR service branches contain only those fixes that are widely released to address widespread, critical issues.
Note The MANIFEST files (.manifest) and MUM files (.mum) that are installed are not listed.

For all supported x86-based versions of Windows 8.1

File nameFile versionFile sizeDateTimePlatform
Bfe.dll6.3.9600.18009570,36810-Aug-201517:01x86
Fwpuclnt.dll6.3.9600.18009272,38410-Aug-201516:56x86
Ikeext.dll6.3.9600.18086734,20808-Oct-201515:45x86
Nshwfp.dll6.3.9600.18009561,66410-Aug-201516:46x86
Bfe.dll6.3.9600.18009570,36810-Aug-201517:01x86
Fwpuclnt.dll6.3.9600.18009272,38410-Aug-201516:56x86
Ikeext.dll6.3.9600.18086734,20808-Oct-201515:45x86
Networksecurity-ppdlic.xrm-msNot Applicable3,05908-Oct-201517:55Not Applicable
Nshwfp.dll6.3.9600.18009561,66410-Aug-201516:46x86
Wfplwfs.sys6.3.9600.1748569,44010-Nov-201417:47x86

For all supported x64-based versions of Windows 8.1 and Windows Server 2012 R2

File nameFile versionFile sizeDateTimePlatform
Bfe.dll6.3.9600.18009845,31210-Aug-201518:15x64
Fwpuclnt.dll6.3.9600.18009422,40010-Aug-201518:06x64
Ikeext.dll6.3.9600.180861,083,90408-Oct-201516:08x64
Nshwfp.dll6.3.9600.18009713,21610-Aug-201517:49x64
Bfe.dll6.3.9600.18009845,31210-Aug-201518:15x64
Fwpuclnt.dll6.3.9600.18009422,40010-Aug-201518:06x64
Ikeext.dll6.3.9600.180861,083,90408-Oct-201516:08x64
Networksecurity-ppdlic.xrm-msNot Applicable3,05908-Oct-201518:46Not Applicable
Nshwfp.dll6.3.9600.18009713,21610-Aug-201517:49x64
Wfplwfs.sys6.3.9600.17485136,51210-Nov-201418:06x64
Fwpuclnt.dll6.3.9600.18009272,38410-Aug-201516:56x86
Nshwfp.dll6.3.9600.18009561,66410-Aug-201516:46x86

How to obtain help and support for this security update

Help for installing updates: Support for Microsoft Update

Security solutions for IT professionals: TechNet Security Troubleshooting and Support

Help for protecting your Windows-based computer from viruses and malware: Virus Solution and Security Center

Local support according to your country: International Support
malicious attacker exploit
Properties

Article ID: 3102939 - Last Review: 12/18/2015 20:03:00 - Revision: 3.0

Windows Server 2012 R2 Datacenter, Windows Server 2012 R2 Standard, Windows Server 2012 R2 Essentials, Windows Server 2012 R2 Foundation, Windows 8.1 Enterprise, Windows 8.1 Pro, Windows 8.1, Windows RT 8.1, Windows Server 2012 Datacenter, Windows Server 2012 Standard, Windows Server 2012 Essentials, Windows Server 2012 Foundation, Windows 8 Enterprise, Windows 8 Pro, Windows 8, Windows RT

  • atdownload kbbug kbexpertiseinter kbfix kbsecbulletin kbsecurity kbsecvulnerability KB3102939
Feedback