MS15-098 - Vulnerabilities in Windows Journal Could Allow Remote Code Execution

Bulletin ID: 

MS15-098

Severity: 

Critical

Description: 

Severity Rating: Critical
Revision Note: V1.1 (September 23, 2015): Bulletin revised to correct the severity and impact for CVE-2015-2514. This is an informational change only. Customers who have already successfully installed the update do not need to take any action.
Summary: This security update resolves vulnerabilities in Microsoft Windows. The more severe of the vulnerabilities could allow remote code execution if a user opens a specially crafted Journal file. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Security advisory: 

Related content