SecPod

Learn Search

Search across all Learn content

← Back to Security Research

Patch Tuesday: Microsoft Security Bulletin Summary for July 2015

Microsoft Patch Tuesday July 2015 bring 14 security bulletins which address 58 CVE’s using their vulnerability scanning solution. This month has 3 high priority bulletins, MS15-065 for Internet Explorer, MS15-070 for Microsoft Office, and MS15-077 for Windows. 4 bulletins are rated as Critical , MS1

Jul 16, 20153 min read
PT-July-2015-image
PT-July-2015-image

Microsoft Patch Tuesday July 2015 bring 14 security bulletins which address 58 CVE’s using their vulnerability scanning solution. This month has 3 high priority bulletins, MS15-065 for Internet Explorer, MS15-070 for Microsoft Office, and MS15-077 for Windows.

4 bulletins are rated as Critical , MS15-065 for Internet Explorer 6 through 11 addressing 29 vulnerabilities, MS15-066 for VBScript engine in Windows Server 2003, Windows Server 2008 and Windows Vista, MS15-067 for Remote Desktop Protocol (RDP) in Windows 7 and Windows 8, and MS15-068 for Windows Hyper-V on Windows Server 2008, Windows Server 2008 R2, Windows 8,  Windows Server 2012, Windows 8.1 and Windows Server 2012 R2. However, a patch management tool can patch these critical vulnerabilities.

Microsoft security bulletin summary for July 2015 in order of severity

MS15-058 : Vulnerabilities in SQL Server Could Allow Remote Code Execution (3065718)
Severity Rating: Important
Affected Software: Microsoft SQL Server
Impact: Remote Code Execution

MS15-065 : Security Update for Internet Explorer (3076321)
Severity Rating: Critical
Impact: Remote Code Execution
Affected Software: Microsoft Windows, Internet Explorer

MS15-066 : Vulnerability in VBScript Scripting Engine Could Allow Remote Code Execution (3072604)
Severity Rating: Critical
Impact: Remote Code Execution
Affected Software: Microsoft Windows

MS15-067 : Vulnerability in RDP Could Allow Remote Code Execution (3073094)
Severity Rating: Critical
Impact: Remote Code Execution
Affected Software: Microsoft Windows

More Microsoft security bulletin summary

MS15-068 : Vulnerabilities in Windows Hyper-V Could Allow Remote Code Execution (3072000)
Severity Rating: Critical
Impact: Remote Code Execution
Affected Software: Microsoft Windows

MS15-069 : Vulnerabilities in Windows Could Allow Remote Code Execution (3072631)
Severity Rating: Important
Impact: Remote Code Execution
Affected Software: Microsoft Windows
MS15-070 : Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3072620)
Severity Rating: Important
Impact: Remote Code Execution
Affected Software: Microsoft Office

MS15-071 : Vulnerability in Netlogon Could Allow Elevation of Privilege (3068457)
Severity Rating: Important
Impact: Elevation of Privilege
Affected Software: Microsoft Windows

MS15-072 : Vulnerability in Windows Graphics Component Could Allow Elevation of Privilege (3069392)
Severity Rating: Important
Impact: Elevation of Privilege
Affected Software: Microsoft Windows
MS15-073 : Vulnerability in Windows Kernel-Mode Driver Could Allow Elevation of Privilege (3070102)
Severity Rating: Important
Impact: Elevation of Privilege
Affected Software: Microsoft Windows

MS15-074 : Vulnerability in Windows Installer Service Could Allow Elevation of Privilege (3072630)
Severity Rating: Important
Impact: Elevation of Privilege
Affected Software: Microsoft Windows

MS15-075 : Vulnerabilities in OLE Could Allow Elevation of Privilege (3072633)
Severity Rating: Important
Impact: Elevation of Privilege
Affected Software: Microsoft Windows

MS15-076 : Vulnerability in Windows Remote Procedure Call Could Allow Elevation of Privilege (3067505)
Severity Rating: Important
Impact: Elevation of Privilege
Affected Software: Microsoft Windows

MS15-077 : Vulnerability in ATM Font Driver Could Allow Elevation of Privilege (3077657)
Severity Rating: Important
Impact: Elevation of Privilege
Affected Software: Microsoft Windows

SecPod Saner detects these vulnerabilities and automatically fixes by applying security updates. Download Saner now and keep your systems updated and secure.

  • Deependra Bapna

Featured Posts

Open WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels
WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

CVE Research

WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

Oct 1, 2026

Open OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure
OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

CVE Research

OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

Two critical vulnerabilities added to CISA KEV on September 24, 2026 reveal sharply different exploitation timelines. CVE-2026-71362 saw publicly documented exploitation roughly one day after Adobe's patch release, while CVE-2026-5430 had a 133-day vendor-remediation-to-observed-exploitation interval.

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026
Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

CVE Research

Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

Three Linux kernel vulnerabilities entered CISA’s KEV catalog on September 18, 2026, although their Linux 6.12 fixes were available 91–386 days earlier. This analysis separates patch availability, CVE publication, and known-exploitation status without treating KEV dates as first-attack dates.

Sep 28, 2026