Microsoft Patch Tuesday for April 2013

This is an advance notification of security bulletins that Microsoft is intending to release on April 9, 2013.

This bulletin advance notification will be replaced with the April bulletin summary on April 9, 2013. For more information about the bulletin advance notification service, see Microsoft Security Bulletin Advance Notification.

To receive automatic notifications whenever Microsoft Security Bulletins are issued, subscribe to Microsoft Technical Security Notifications.

Microsoft will host a webcast to address customer questions on the security bulletins on April 10, 2013, at 11:00 AM Pacific Time (US & Canada). Register now for the April Security Bulletin Webcast. After this date, this webcast is available on-demand.

Microsoft also provides information to help customers prioritize monthly security updates with any non-security, high-priority updates that are being released on the same day as the monthly security updates. Please see the section, Other Information.

Bulletin Information

Executive Summaries

This advance notification provides a number as the bulletin identifier, because the official Microsoft Security Bulletin numbers are not issued until release. The bulletin summary that replaces this advance notification will have the proper Microsoft Security Bulletin numbers (in the MSyy-xxx format) as the bulletin identifier.

The following table summarizes the security bulletins for this month in order of severity.

For details on affected software, see the next section, Affected Software.

Bulletin ID Maximum Severity Rating and Vulnerability Impact Restart Requirement Affected Software
Bulletin 1 Critical
Remote Code Execution
Requires restart Microsoft Windows,
Internet Explorer
Bulletin 2 Critical
Remote Code Execution
May require restart Microsoft Windows
Bulletin 3 Important
Information Disclosure
May require restart Microsoft Office,
Microsoft Server Software
Bulletin 4 Important
Elevation of Privilege
Requires restart Microsoft Windows
Bulletin 5 Important
Denial of Service
Requires restart Microsoft Windows
Bulletin 6 Important
Elevation of Privilege
Requires restart Microsoft Windows
Bulletin 7 Important
Elevation of Privilege
Requires restart Microsoft Security Software
Bulletin 8 Important
Elevation of Privilege
May require restart Microsoft Office,
Microsoft Server Software
Bulletin 9 Important
Elevation of Privilege
Requires restart Microsoft Windows

Affected Software

This advance notification provides a number as the bulletin identifier, because the official Microsoft Security Bulletin numbers are not issued until release. The bulletin summary that replaces this advance notification will have the proper Microsoft Security Bulletin numbers (in the MSyy-xxx format) as the bulletin identifier.

The following tables list the bulletins in order of major software category and severity.

How do I use these tables?

Use these tables to learn about the security updates that you may need to install. You should review each software program or component listed to see whether any security updates pertain to your installation. If a software program or component is listed, then the severity rating of the security update is also listed.

Note You may have to install several security updates for a single vulnerability. Review the whole column for each bulletin identifier that is listed to verify the updates that you have to install, based on the programs or components that you have installed on your system.

Windows Operating System and Components
Windows XP
Bulletin Identifier Bulletin 1 Bulletin 2 Bulletin 4 Bulletin 5 Bulletin 6 Bulletin 9
Aggregate Severity Rating Critical Critical Important Low Important Important
Windows XP Service Pack 3 Internet Explorer 6
(Critical)

Internet Explorer 7
(Critical)

Internet Explorer 8
(Critical)

Windows XP Service Pack 3
(Critical)
Windows XP Service Pack 3
(Important)
Windows XP Service Pack 3
(Low)
Windows XP Service Pack 3
(Moderate)
Windows XP Service Pack 3
(Important)
Windows XP Professional x64 Edition Service Pack 2 Internet Explorer 6
(Critical)

Internet Explorer 7
(Critical)

Internet Explorer 8
(Critical)

Windows XP Professional x64 Edition Service Pack 2
(Critical)
Windows XP Professional x64 Edition Service Pack 2
(Important)
Windows XP Professional x64 Edition Service Pack 2
(Low)
Windows XP Professional x64 Edition Service Pack 2
(Important)
Windows XP Professional x64 Edition Service Pack 2
(Important)
Windows Server 2003
Bulletin Identifier Bulletin 1 Bulletin 2 Bulletin 4 Bulletin 5 Bulletin 6 Bulletin 9
Aggregate Severity Rating Moderate Moderate Important Important Important Important
Windows Server 2003 Service Pack 2 Internet Explorer 6
(Moderate)

Internet Explorer 7
(Moderate)

Internet Explorer 8
(Moderate)

Windows Server 2003 Service Pack 2
(Moderate)
Windows Server 2003 Service Pack 2
(Important)
Windows Server 2003 Service Pack 2
(Important)
Windows Server 2003 Service Pack 2
(Important)
Windows Server 2003 Service Pack 2
(Important)
Windows Server 2003 x64 Edition Service Pack 2 Internet Explorer 6
(Moderate)

Internet Explorer 7
(Moderate)

Internet Explorer 8
(Moderate)

Windows Server 2003 x64 Edition Service Pack 2
(Moderate)
Windows Server 2003 x64 Edition Service Pack 2
(Important)
Windows Server 2003 x64 Edition Service Pack 2
(Important)
Windows Server 2003 x64 Edition Service Pack 2
(Important)
Windows Server 2003 x64 Edition Service Pack 2
(Important)
Windows Server 2003 with SP2 for Itanium-based Systems Internet Explorer 6
(Moderate)

Internet Explorer 7
(Moderate)

Not applicable Windows Server 2003 with SP2 for Itanium-based Systems
(Important)
Windows Server 2003 with SP2 for Itanium-based Systems
(Important)
Windows Server 2003 with SP2 for Itanium-based Systems
(Important)
Windows Server 2003 with SP2 for Itanium-based Systems
(Important)
Windows Vista
Bulletin Identifier Bulletin 1 Bulletin 2 Bulletin 4 Bulletin 5 Bulletin 6 Bulletin 9
Aggregate Severity Rating Critical Critical Important Low Moderate Important
Windows Vista Service Pack 2 Internet Explorer 7
(Critical)

Internet Explorer 8
(Critical)

Internet Explorer 9
(Critical)

Windows Vista Service Pack 2
(Critical)
Windows Vista Service Pack 2
(Important)
Windows Vista Service Pack 2
(Low)
Windows Vista Service Pack 2
(Moderate)
Windows Vista Service Pack 2
(Important)
Windows Vista x64 Edition Service Pack 2 Internet Explorer 7
(Critical)

Internet Explorer 8
(Critical)

Internet Explorer 9
(Critical)

Windows Vista x64 Edition Service Pack 2
(Critical)
Windows Vista x64 Edition Service Pack 2
(Important)
Windows Vista x64 Edition Service Pack 2
(Low)
Windows Vista x64 Edition Service Pack 2
(Moderate)
Windows Vista x64 Edition Service Pack 2
(Important)
Windows Server 2008
Bulletin Identifier Bulletin 1 Bulletin 2 Bulletin 4 Bulletin 5 Bulletin 6 Bulletin 9
Aggregate Severity Rating Moderate Moderate Important Important Moderate Important
Windows Server 2008 for 32-bit Systems Service Pack 2 Internet Explorer 7
(Moderate)

Internet Explorer 8
(Moderate)

Internet Explorer 9
(Moderate)

Windows Server 2008 for 32-bit Systems Service Pack 2
(Moderate)
Windows Server 2008 for 32-bit Systems Service Pack 2
(Important)
Windows Server 2008 for 32-bit Systems Service Pack 2
(Important)
Windows Server 2008 for 32-bit Systems Service Pack 2
(Moderate)
Windows Server 2008 for 32-bit Systems Service Pack 2
(Important)
Windows Server 2008 for x64-based Systems Service Pack 2 Internet Explorer 7
(Moderate)

Internet Explorer 8
(Moderate)

Internet Explorer 9
(Moderate)

Windows Server 2008 for x64-based Systems Service Pack 2
(Moderate)
Windows Server 2008 for x64-based Systems Service Pack 2
(Important)
Windows Server 2008 for x64-based Systems Service Pack 2
(Important)
Windows Server 2008 for x64-based Systems Service Pack 2
(Moderate)
Windows Server 2008 for x64-based Systems Service Pack 2
(Important)
Windows Server 2008 for Itanium-based Systems Service Pack 2 Internet Explorer 7
(Moderate)
Windows Server 2008 for Itanium-based Systems Service Pack 2
(Moderate)
Windows Server 2008 for Itanium-based Systems Service Pack 2
(Important)
Not applicable Windows Server 2008 for Itanium-based Systems Service Pack 2
(Moderate)
Windows Server 2008 for Itanium-based Systems Service Pack 2
(Important)
Windows 7
Bulletin Identifier Bulletin 1 Bulletin 2 Bulletin 4 Bulletin 5 Bulletin 6 Bulletin 9
Aggregate Severity Rating Critical Critical Important Low None Important
Windows 7 for 32-bit Systems Internet Explorer 8
(Critical)

Internet Explorer 9
(Critical)

Windows 7 for 32-bit Systems
(Critical)
Windows 7 for 32-bit Systems
(Important)
Windows 7 for 32-bit Systems
(Low)
Not applicable Windows 7 for 32-bit Systems
(Important)
Windows 7 for 32-bit Systems Service Pack 1 Internet Explorer 8
(Critical)

Internet Explorer 9
(Critical)

Internet Explorer 10
(Critical)

Windows 7 for 32-bit Systems Service Pack 1
(Critical)
Windows 7 for 32-bit Systems Service Pack 1
(Important)
Windows 7 for 32-bit Systems Service Pack 1
(Low)
Not applicable Windows 7 for 32-bit Systems Service Pack 1
(Important)
Windows 7 for x64-based Systems Internet Explorer 8
(Critical)

Internet Explorer 9
(Critical)

Windows 7 for x64-based Systems
(Critical)
Windows 7 for x64-based Systems
(Important)
Windows 7 for x64-based Systems
(Low)
Not applicable Windows 7 for x64-based Systems
(Important)
Windows 7 for x64-based Systems Service Pack 1 Internet Explorer 8
(Critical)

Internet Explorer 9
(Critical)

Internet Explorer 10
(Critical)

Windows 7 for x64-based Systems Service Pack 1
(Critical)
Windows 7 for x64-based Systems Service Pack 1
(Important)
Windows 7 for x64-based Systems Service Pack 1
(Low)
Not applicable Windows 7 for x64-based Systems Service Pack 1
(Important)
Windows Server 2008 R2
Bulletin Identifier Bulletin 1 Bulletin 2 Bulletin 4 Bulletin 5 Bulletin 6 Bulletin 9
Aggregate Severity Rating Moderate Moderate Important Important None Important
Windows Server 2008 R2 for x64-based Systems Internet Explorer 8
(Moderate)

Internet Explorer 9
(Moderate)

Windows Server 2008 R2 for x64-based Systems
(Moderate)
Windows Server 2008 R2 for x64-based Systems
(Important)
Windows Server 2008 R2 for x64-based Systems
(Important)
Not applicable Windows Server 2008 R2 for x64-based Systems
(Important)
Windows Server 2008 R2 for x64-based Systems Service Pack 1 Internet Explorer 8
(Moderate)

Internet Explorer 9
(Moderate)

Internet Explorer 10
(Moderate)

Windows Server 2008 R2 for x64-based Systems Service Pack 1
(Moderate)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
(Important)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
(Important)
Not applicable Windows Server 2008 R2 for x64-based Systems Service Pack 1
(Important)
Windows Server 2008 R2 for Itanium-based Systems Internet Explorer 8
(Moderate)
Windows Server 2008 R2 for Itanium-based Systems
(Moderate)
Windows Server 2008 R2 for Itanium-based Systems
(Important)
Not applicable Not applicable Windows Server 2008 R2 for Itanium-based Systems
(Important)
Windows Server 2008 R2 for Itanium-based Systems Service Pack 1 Internet Explorer 8
(Moderate)
Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
(Moderate)
Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
(Important)
Not applicable Not applicable Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
(Important)
Windows 8
Bulletin Identifier Bulletin 1 Bulletin 2 Bulletin 4 Bulletin 5 Bulletin 6 Bulletin 9
Aggregate Severity Rating Critical None Important Low None Important
Windows 8 for 32-bit Systems Internet Explorer 10
(Critical)
Not applicable Windows 8 for 32-bit Systems
(Important)
Windows 8 for 32-bit Systems
(Low)
Not applicable Windows 8 for 32-bit Systems
(Important)
Windows 8 for 64-bit Systems Internet Explorer 10
(Critical)
Not applicable Windows 8 for 64-bit Systems
(Important)
Windows 8 for 64-bit Systems
(Low)
Not applicable Windows 8 for 64-bit Systems
(Important)
Windows Server 2012
Bulletin Identifier Bulletin 1 Bulletin 2 Bulletin 4 Bulletin 5 Bulletin 6 Bulletin 9
Aggregate Severity Rating Moderate None Important Important None Important
Windows Server 2012 Internet Explorer 10
(Moderate)
Not applicable Windows Server 2012
(Important)
Windows Server 2012
(Important)
Not applicable Windows Server 2012
(Important)
Windows RT
Bulletin Identifier Bulletin 1 Bulletin 2 Bulletin 4 Bulletin 5 Bulletin 6 Bulletin 9
Aggregate Severity Rating Critical None Important None None Important
Windows RT Internet Explorer 10
(Critical)
Not applicable Windows RT
(Important)
Not applicable Not applicable Windows RT
(Important)
Server Core installation option
Bulletin Identifier Bulletin 1 Bulletin 2 Bulletin 4 Bulletin 5 Bulletin 6 Bulletin 9
Aggregate Severity Rating None None Important Important Moderate Important
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) Not applicable Not applicable Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
(Important)
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
(Important)
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
(Moderate)
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
(Important)
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) Not applicable Not applicable Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
(Important)
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
(Important)
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
(Moderate)
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
(Important)
Windows Server 2008 R2 for x64-based Systems (Server Core installation) Not applicable Not applicable Windows Server 2008 R2 for x64-based Systems (Server Core installation)
(Important)
Windows Server 2008 R2 for x64-based Systems (Server Core installation)
(Important)
Not applicable Windows Server 2008 R2 for x64-based Systems (Server Core installation)
(Important)
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) Not applicable Not applicable Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
(Important)
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
(Important)
Not applicable Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
(Important)
Windows Server 2012 (Server Core installation) Not applicable Not applicable Windows Server 2012 (Server Core installation)
(Important)
Windows Server 2012 (Server Core installation)
(Important)
Not applicable Windows Server 2012 (Server Core installation)
(Important)
Microsoft Office Suites and Software
Microsoft Office Software
Bulletin Identifier Bulletin 8
Aggregate Severity Rating None
Microsoft InfoPath 2010 Service Pack 1 (32-bit editions) Microsoft InfoPath 2010 Service Pack 1 (32-bit editions)
(No severity rating)[1]
Microsoft InfoPath 2010 Service Pack 1 (64-bit editions) Microsoft InfoPath 2010 Service Pack 1 (64-bit editions)
(No severity rating)[1]

Notes for Bulletin 8

[1]Severity ratings do not apply to this update for the specified software because the known attack vectors for the vulnerability are blocked.

See also other software categories under this section, Affected Software and Download Locations, for more update files under the same bulletin identifier. This bulletin spans more than one software category.

Microsoft Server Software
Microsoft SharePoint Server
Bulletin Identifier Bulletin 3 Bulletin 8
Aggregate Severity Rating Important Important
Microsoft SharePoint Server 2010 Service Pack 1 Not applicable Microsoft SharePoint Server 2010 Service Pack 1
(Important)
Microsoft SharePoint Server 2013 Microsoft SharePoint Server 2013
(Important)
Not applicable
Microsoft Groove Server
Bulletin Identifier Bulletin 3 Bulletin 8
Aggregate Severity Rating None Important
Microsoft Groove Server 2010 Service Pack 1 Not applicable Microsoft Groove Server 2010 Service Pack 1
(Important)
Microsoft SharePoint Foundation
Bulletin Identifier Bulletin 3 Bulletin 8
Aggregate Severity Rating None Important
Microsoft SharePoint Foundation 2010 Service Pack 1 Not applicable Microsoft SharePoint Foundation 2010 Service Pack 1
(Important)

Note for Bulletin 8

See also other software categories under this section, Affected Software and Download Locations, for more update files under the same bulletin identifier. This bulletin spans more than one software category.

Microsoft Office Web Apps
Microsoft Office Software
Bulletin Identifier Bulletin 8
Aggregate Severity Rating Important
Microsoft Office Web Apps 2010 Service Pack 1 Microsoft Office Web Apps 2010 Service Pack 1
(Important)

Note for Bulletin 8

See also other software categories under this section, Affected Software and Download Locations, for more update files under the same bulletin identifier. This bulletin spans more than one software category.

Microsoft Security Software
Antimalware Software
Bulletin Identifier Bulletin 7
Aggregate Severity Rating Important
Windows Defender for Windows 8 and Windows RT Windows Defender for Windows 8 and Windows RT
(Important)