Welcome to another Black Tuesday this time for August 2007
We have 6xCritical, 3xImportant patches for our entertainment, all are detected via Microsoft Baseline Security Analyzer. A restart will be required.
| Bulletin |
KB number |
Description |
Severity |
Impact |
Software |
| MS07-042 |
936227 |
Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution |
Remote Code Execution |
Critical |
Windows, XML Core Services. |
| MS07-043 |
921503 |
Vulnerability in OLE Automation Could Allow Remote Code Execution |
Remote Code Execution |
Critical |
Windows, Visual Basic, Office for Mac |
| MS07-044 |
940965 |
Vulnerability in Microsoft Excel Could Allow Remote Code Execution |
Remote Code Execution |
Critical |
Office |
| MS07-045 |
937143 |
Cumulative Security Update for Internet Explorer |
Remote Code Execution |
Critical |
Windows, Internet Explorer |
| MS07-046 |
938829 |
Vulnerability in GDI Could Allow Remote Code Execution |
Remote Code Execution |
Critical |
Windows |
| MS07-050 |
938127 |
Vulnerability in Vector Markup Language Could Allow Remote Code Execution |
Remote Code Execution |
Critical |
Windows, Internet Explorer. |
| MS07-047 |
936782 |
Vulnerability in Windows Media Player Could Allow Remote Code Execution |
Remote Code Execution |
Important |
Windows |
| MS07-048 |
938123 |
Vulnerabilities in Windows Gadgets Could Allow Remote Code Execution |
Remote Code Execution |
Important |
Windows Vista |
| MS07-049 |
937986 |
Vulnerability in Virtual PC and Virtual Server Could Allow Elevation of Privilege |
Elevation of Privilege |
Important |
Virtual PC, Virtual Server |
| MS07-038 |
935807 |
Vulnerability in Windows Vista Firewall could allow information disclosure |
information disclosure |
Re-release |
Windows Vista |
Out of nine patches this month, eight patches patched vulnerabilities that were able to be exploited over the Internet to execute arbitrary code. [5]
PATCH NOW:
MS07-042, MS07-043, MS07-044, MS07-045, MS07-046,, MS07-047, MS07-048, MS07-049, MS07-050
Just as a reminder, support for Software Update Services (SUS) 1.0 ended last month on Tuesday, July 10, 2007. As support and update content availability for SUS 1.0 is no longer available, we encourage our customers to utilize Windows Server Update Services (WSUS) 2.0 or 3.0 as it supports updating a broader set of Microsoft products. [6]
LINKS:
[1.] Microsoft Security Bulletin Advance Notification [MS]
[2.] August ‘Black Tuesday’ overview [SANS]
[3.] Microsoft Security Bulletin Summary for August 2007 [MS]
[4.] Microsoft security updates for August 2007 [MS]
[5.] Microsoft Patch Disclosure – August 2007 [eEye]
[6.] August 2007 Monthly Security Bulletin Release [MS Security Response Center Blog]