Overview of the May 2007 Microsoft patches and their status.
| # | Affected | Contra Indications | Known Exploits | Microsoft rating | ISC rating(*) | |
|---|---|---|---|---|---|---|
| clients | servers | |||||
| MS07-023 |
Multiple vulnerabilities allow remote code execution, replaces MS07-002 | |||||
| Excel CVE-2007-0215 CVE-2007-1203 CVE-2007-1214 |
KB 934233 | No known exploits | Critical | Critical | Important |
|
| MS07-024 | Multiple vulnerabilities allow remote code execution, replaces MS07-014 | |||||
| Word CVE-2007-0035 CVE-2007-0870 CVE-2007-1202 |
KB 934232 | Actively exploited |
Critical | PATCH NOW | Important |
|
| MS07-025 | Lack of input validation in MSO.DLL allows remote code execution, replaces MS07-015 | |||||
| Office CVE-2007-1747 |
KB 934873 |
No known exploits | Critical | Critical | Important |
|
| MS07-026 | Multiple vulnerabilities allow remote code execution, information leaks and DoS replaces MS06-019 and MS06-029 | |||||
| Exchange CVE-2007-0220 CVE-2007-0039 CVE-2007-0213 CVE-2007-0221 |
KB 931832 |
No known exploits | Critical | Important(**) | Critical | |
| MS07-027 | Cumulative Internet Explorer update, replaces MS07-016 |
|||||
| MSIE CVE-2007-0942 CVE-2007-0944 CVE-2007-0945 CVE-2007-0946 CVE-2007-0947 CVE-2007-2221 |
KB 931768 |
Publicly disclosed (some) |
Critical | PATCH NOW | Important | |
| MS07-028 | Input handling vulnerability in the handling of certificates leading to remote code execution |
|||||
| CAPICOM and BizTalk server CVE-2007-0940 |
KB 931906 | No known exploits | Critical | Critical | Critical | |
| MS07-029 | RPC vulnerability allows remote code execution | |||||
| DNS CVE-2007-1748 |
KB 935966 | Actively exploited Microsoft Security Advisory (935964) |
Critical | Important(**) | PATCH NOW | |
--
Swa Frantzen -- NET2S
Login here to post a comment. Diary Archive