This security update resolves vulnerabilities in Windows, the Microsoft .NET Framework, Microsoft Office, Microsoft Lync, and Microsoft Silverlight. The more severe of these vulnerabilities could allow for one of the following scenarios:
- Remote code execution if a user opens a specially crafted document or goes to an untrusted webpage that contains embedded TrueType fonts.
- Elevation of privilege if an attacker logs on locally and runs arbitrary code in kernel mode. An attacker could then take the following actions:
- Install programs
- View, change, or delete data
- Create new accounts that have full user rights