MS16-003: Cumulative security update for JScript and VBScript to address remote code execution: January 12, 2016

Summary

This security update resolves a vulnerability in the VBScript scripting engine in Microsoft Windows. The vulnerability could allow remote code execution if a user visits a specially crafted website. An attacker who successfully exploits this vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploits this vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 

To learn more about the vulnerability, see Microsoft Security Bulletin MS16-003.

Additional information about this security update


The following articles contain additional information about this security update as it relates to individual product versions. The articles may contain known issue information.
  • 3124625 MS16-003: Description of the security update for JScript 5.8 and VBScript 5.8: January 12, 2016
  • 3124624 MS16-003: Description of the security update for JScript 5.7 and VBScript 5.7: January 12, 2016

How to obtain and install the update

Method 1: Windows Update

This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, see
Get security updates automatically.

Method 2: Microsoft Download Center

More Information

Security update deployment information
How to obtain help and support for this security update
Właściwości

Identyfikator artykułu: 3125540 — ostatni przegląd: 12.01.2016 — zmiana: 1

Opinia