About this tag
The tag 'privately reported' refers to security vulnerabilities in Microsoft Windows and related software that were disclosed to Microsoft by external researchers or organizations before public announcement. These vulnerabilities are addressed through Microsoft Security Bulletins (MS) and cumulative updates. Topics covered include elevation of privilege in Windows Task Scheduler, FAT32 driver, and CSRSS; remote code execution in Unicode Scripts Processor, OpenType CFF driver, and Internet Explorer; and security feature bypass in SSL/TLS. The tag is used in discussions about security updates, patch management, and vulnerability disclosure practices for Windows systems.
  1. News

    MS15-028 - Important: Vulnerability in Windows Task Scheduler Could Allow Security Feature...

    Severity Rating: Important Revision Note: V1.0 (March 10, 2015): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow Security Feature Bypass if a user runs a specially crafted application that is...
  2. News

    MS14-063 - Important: Vulnerability in FAT32 Disk Partition Driver Could Allow Elevation of...

    Severity Rating: Important Revision Note: V1.0 (October 14, 2014): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. An elevation of privilege vulnerability exists in the way the Windows FASTFAT system driver interacts with FAT32...
  3. News

    MS13-060 - Critical : Vulnerability in Unicode Scripts Processor Could Allow Remote Code...

    Severity Rating: Critical Revision Note: V1.0 (August 13, 2013): Bulletin published. Summary: This security update resolves a privately reported vulnerability in the Unicode Scripts Processor included in Microsoft Windows. The vulnerability could allow remote code execution if a user viewed a...
  4. News

    MS13-033 - Important : Vulnerability in Windows Client/Server Run-time Subsystem (CSRSS) Could Allow

    Severity Rating: Important Revision Note: V1.0 (April 9, 2013): Bulletin published. Summary: This security update resolves a privately reported vulnerability in all supported editions of Windows XP, Windows Vista, Windows Server 2003, and Windows Server 2008. The...
  5. News

    MS13-005 - Important : Vulnerability in Windows Kernel-Mode Driver Could Allow Elevation of Privileg

    Severity Rating: Important Revision Note: V1.1 (January 9, 2013): Corrected detection and deployment summary tables. This is an informational change only. Customers who have already successfully updated their systems do not need to take any action. Summary: This security...
  6. News

    MS12-052 - Critical : Cumulative Security Update for Internet Explorer (2722913) - Version: 1.1

    Severity Rating: Critical Revision Note: V1.1 (August 15, 2012): Removed erroneous FAQ for Windows 8 Release Preview and Windows Server 2012 Release Candidate releases. The Windows 8 Release Preview and Windows Server 2012 Release Candidate releases are not affected by the...
  7. News

    MS12-038 - Critical : Vulnerability in .NET Framework Could Allow Remote Code Execution (2706726) -

    Severity Rating: Critical Revision Note: V1.0 (June 12): Bulletin published. Summary: This security update resolves one privately reported vulnerability in the Microsoft .NET Framework. The vulnerability could allow remote code execution on a client system if a user views a...
  8. News

    MS11-100 - Critical : Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (2638420)

    Severity Rating: Critical Revision Note: V1.3 (February 1, 2012): Corrected registry keys and installation switches in the deployment tables for Windows Server 2003 and Windows Server 2008, and installation switches in the deployment table for Windows Vista. This is an informational...
  9. News

    MS11-049 - Important : Vulnerability in the Microsoft XML Editor Could Allow Information Disclosure

    Severity Rating: Important Revision Note: V2.0 (August 9, 2011): Bulletin rereleased to announce a detection change to the update for Microsoft Visual Studio 2005 Service Pack 1 (KB2251481) to add detection for related software listed in the update FAQ. There were no changes to the...
  10. News

    MS11-021 - Important: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2489279)

    Bulletin Severity Rating:Important - This security update resolves nine privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited any of these...
  11. News

    MS10-080 - Important: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2293211)

    Severity Rating: Important - Revision Note: V1.0 (October 12, 2010): Bulletin published.Summary: This security update resolves thirteen privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file or...
  12. News

    MS10-080 - Important: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2293211)

    Bulletin Severity Rating:Important - This security update resolves thirteen privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file or a specially crafted Lotus 1-2-3 file. An attacker who...