SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Patch Tuesday: Microsoft Security Bulletin Summary For August 2016

Patch Tuesday: Microsoft Security Bulletin Summary For August 2016

Microsoft August 2016 Patch Tuesday brings 9 Security Bulletins addressing a total of 34 vulnerabilities. Five Security Bulletins are rated as Critical and remaining Four are rated as Important.

Aug 10, 2016By Tushar K2 min read
aug_patch1
aug_patch1

Microsoft August 2016 Patch Tuesday brings 9 Security Bulletins addressing a total of 34 vulnerabilities. Five Security Bulletins are rated as Critical and remaining Four are rated as Important.

This month high priority fixes are for Internet Explorer, Microsoft Edge, Microsoft Graphics Component, Microsoft Office, and Microsoft Windows PDF Library which addresses 28 vulnerabilities out of 34 vulnerabilities.

This month Five bulletins are rated as Critical: MS16-095  for Internet Explorer cover 9 CVE’s, MS16-096 for Microsoft Edge cover 8 CVE’s, MS16-097 for Graphics Component cover 3 CVE’s, MS16-099 for Microsoft Office cover 5 CVE’s, and MS16-102 for PDF Library cover 1 CVE.

These Critical vulnerabilities allow Remote code execution. And other bulletins which are marked as important allow Security feature bypass, Elevation of privilege and Information disclosure.

Microsoft security bulletin summary for August 2016 in the order of severity:

MS16-095: Vulnerabilities in Internet Explorer (3177356)
Severity Rating: Critical
Affected Software: Internet Explorer
Impact: Remote Code Execution

MS16-096: Vulnerabilities in Microsoft Edge (3177358)
Severity Rating: Critical
Affected Software: Microsoft Edge
Impact: Remote Code Execution

MS16-097: Vulnerabilities in Microsoft Graphics Component (3177393)
Severity Rating: Critical
Affected Software: Microsoft Graphics Component
Impact: Remote Code Execution

MS16-098: Vulnerabilities in Windows Kernel-Mode Drivers (3178466)
Severity Rating: Important
Affected Software: Windows Kernel-Mode Drivers
Impact: Elevation of Privilege

MS16-099: Vulnerabilities in Microsoft Office (3177451)
Severity Rating: Critical
Affected Software: Microsoft Office
Impact: Remote Code Execution

MS16-100: Vulnerability in Secure Boot (3179577)
Severity Rating: Important
Affected Software: Secure Boot
Impact: Security Feature Bypass

MS16-101: Vulnerabilities in Windows Authentication Methods (3178465)
Severity Rating: Important
Affected Software: Windows Authentication Methods
Impact: Elevation of Privilege

MS16-102: Vulnerability in Microsoft Windows PDF Library (3182248)
Severity Rating: Critical
Affected Software: Microsoft Windows PDF Library
Impact: Remote Code Execution

MS16-103: Vulnerability in ActiveSyncProvider (3182332)
Severity Rating: Important
Affected Software: ActiveSyncProvider
Impact: Information Disclosure

SecPod Saner detects these vulnerabilities and automatically fixes it by applying security updates. Download Saner and keep your systems updated and secure.

Featured Posts

Open CVE-2026-31431: From 732 Bytes to Root - Anatomy of a Modern Linux Privilege Escalation

CVE-2026-31431: From 732 Bytes to Root - Anatomy of a Modern Linux Privilege Escalation

CVE Research

CVE-2026-31431: From 732 Bytes to Root - Anatomy of a Modern Linux Privilege Escalation

Jun 24, 2026

Open CVE-2026-31431: The Nine-Year Kernel Bug Hiding in Plain Sight

CVE-2026-31431: The Nine-Year Kernel Bug Hiding in Plain Sight

CVE Research

CVE-2026-31431: The Nine-Year Kernel Bug Hiding in Plain Sight

Jun 23, 2026

Open Squidbleed: A 29-Year-Old Squid Proxy Flaw That Leaks Cleartext HTTP Requests
Squidbleed: A 29-Year-Old Squid Proxy Flaw That Leaks Cleartext HTTP Requests

CVE Research

Squidbleed: A 29-Year-Old Squid Proxy Flaw That Leaks Cleartext HTTP Requests

Jun 23, 2026

Open AryStinger Malware Leverages 4,300+ Legacy Routers to Establish Persistent Spy Infrastructure
AryStinger Malware Leverages 4,300+ Legacy Routers to Establish Persistent Spy Infrastructure

CVE Research

AryStinger Malware Leverages 4,300+ Legacy Routers to Establish Persistent Spy Infrastructure

AryStinger represents a calculated shift in IoT threat methodology, abandoning noisy, destructive payloads in favor of silent, long-term reconnaissance infrastructure. By exploiting unpatched, end-of-life routers and NAS devices through decade-old vulnerabilities, the threat operator has assembled a distributed fleet of over 4,300 Executor nodes capable of conducting parallelized DNS enumeration, port scanning, and service fingerprinting at scale, all while masking origin behind residential IP addresses. With active development ongoing and a potential operational timeline stretching back to 2024, AryStinger underscores a growing and underappreciated risk: forgotten edge hardware is not merely a compliance gap but exploitable infrastructure.

Jun 23, 2026

Patch Tuesday: Microsoft Security Bulletin Summary For August 2016 | SecPod