VPNの脆弱性に関する不安が広がっています。ZPAの60日間無料トライアルを利用して、VPNからの移行のメリットをお確かめください。

ゼットスケーラーのセキュリティアドバイザリ

セキュリティ アドバイザリー - 10月 13, 2015

Zscaler Protects against Multiple Security Vulnerabilities in Internet Explorer, Windows kernel and Microsoft edge.

Zscaler, working with Microsoft through their MAPP program, has proactively deployed protections for the following 13 vulnerabilities included in the October 2015 Microsoft security bulletins. Zscaler will continue to monitor exploits associated with all vulnerabilities in the October release and deploy additional protections as necessary.

MS15-111 - Security Update for Windows Kernel to Address Elevation of Privilege

Severity: Important
Affected Software

  • Windows Vista
  • Windows Server 2008
  • Windows 7
  • Windows Server 2008 R2
  • Windows 8 and Windows 8.1
  • Windows Server 2012 and Windows Server 2012 R2
  • Windows RT and Windows RT 8.1
  • Windows 10

CVE-2015-2549 - Windows Kernel Memory Corruption Vulnerability

CVE-2015-2550 - Windows Elevation of Privilege Vulnerability

Description: This security update resolves vulnerabilities in Microsoft Windows. The more severe of the vulnerabilities could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application

MS15-109 Security Update for Windows Shell to Address Remote Code Execution

Severity: Critical
Affected Software:

  • Windows Vista
  • Windows Server 2008
  • Windows 7
  • Windows Server 2008 R2
  • Windows 8 and Windows 8.1
  • Windows Server 2012 and Windows Server 2012 R2
  • Windows RT and Windows RT 8.1
  • Windows 10

CVE-2015-2515 - Toolbar Use After Free Vulnerability

CVE-2015-2548 - Microsoft Tablet Input Band Use After Free Vulnerability

Description: This security update resolves vulnerabilities in Microsoft Windows. The vulnerabilities could allow remote code execution if a user opens a specially crafted toolbar object in Windows or an attacker convinces a user to view specially crafted content online.

MS15-107 – Cumulative Security Update for Microsoft Edge

Severity: Important
Affected Software:

  • Microsoft Edge

CVE-2015-6058 - XSS Filter Bypass in Microsoft Edge

Description: This security update resolves vulnerabilities in Microsoft Edge. The most severe of the vulnerabilities could allow information disclosure if a user views a specially crafted webpage using Microsoft Edge. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. Customers whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

MS15-106 – Cumulative Security Update for Internet Explorer

Severity: Critical
Affected Software:

  • Internet Explorer 7-11

CVE-2015-6059 - Information Disclosure Vulnerability

CVE-2015-6055 - Scripting Engine Memory Corruption Vulnerability

CVE-2015-6050 - Memory Corruption Vulnerability

CVE-2015-6049 - Memory Corruption Vulnerability

CVE-2015-6048 - Memory Corruption Vulnerability

CVE-2015-6047 - Elevation of Privilege Vulnerability

CVE-2015-6042 - Memory Corruption Vulnerability

CVE-2015-2482 - Scripting Engine Memory Corruption Vulnerability

Description: This security update resolves vulnerabilities in Internet Explorer. The most severe of the vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. Customers whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

MS15-107 – Cumulative Security Update for Microsoft Edge

Severity: Important
Affected Software:

  • Microsoft Edge

CVE-2015-6058 - XSS Filter Bypass in Microsoft Edge

Description: This security update resolves vulnerabilities in Microsoft Edge. The most severe of the vulnerabilities could allow information disclosure if a user views a specially crafted webpage using Microsoft Edge. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. Customers whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

MS15-106 – Cumulative Security Update for Internet Explorer

Severity: Critical
Affected Software:

  • Internet Explorer 7-11

CVE-2015-6059 - Information Disclosure Vulnerability

CVE-2015-6055 - Scripting Engine Memory Corruption Vulnerability

CVE-2015-6050 - Memory Corruption Vulnerability

CVE-2015-6049 - Memory Corruption Vulnerability

CVE-2015-6048 - Memory Corruption Vulnerability

CVE-2015-6047 - Elevation of Privilege Vulnerability

CVE-2015-6042 - Memory Corruption Vulnerability

CVE-2015-2482 - Scripting Engine Memory Corruption Vulnerability

Description: This security update resolves vulnerabilities in Internet Explorer. The most severe of the vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. Customers whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.