Overview of the July 2007 Microsoft patches and their status.
| # | Affected | Contra Indications | Known Exploits | Microsoft rating | ISC rating(*) | |
|---|---|---|---|---|---|---|
| clients | servers | |||||
| MS07-036 | Multiple vulnerabilities allow remote code execution with the rights of the logged on user. Replaces MS07-023 |
|||||
| Office CVE-2007-1756 CVE-2007-3029 CVE-2007-3030 |
KB 936542 | No known exploits | Critical | Critical | Important | |
| MS07-037 | Input validation failure allows remote code execution with the rights of the logged on user | |||||
| Publisher 2007 CVE-2007-1754 |
KB 936548 |
No known exploits | Important | Critical(***) | Important | |
| MS07-038 | Teredo interfaces bypass certain firewall rules leading to exposure of the system's interfaces and bypass of the perimeter defenses due to the tunneling. | |||||
| Vista CVE-2007-3038 |
KB 935807 |
No known exploits | Moderate | Critical | Critical(**) | |
| MS07-039 | Multiple input validation failures allow remote code execution and DoS. | |||||
| Active Directory Servers CVE-2007-3028 CVE-2007-0040 |
KB 926122 | No known exploits | Critical | Important(**) | Critical | |
| MS07-040 | Multiple vulnerabilities allow remote code execution on clients and information disclosure on servers. Replaces MS05-004 |
|||||
| .NET framework CVE-2007-0041 CVE-2007-0042 CVE-2007-0043 |
Please read the KB and those it references below, readers are reporting various issues. |
No known exploits | Critical | Critical | Critical | |
| MS07-041 | Buffer overflow allows remote code execution with system level privileges. | |||||
| IIS 5.1 (Web server on windows XP) CVE-2005-4360 |
KB 939373 |
DoS exploit public since 2005 | Important | Critical(***) | Critical(***) | |
(**): in the event Vista based machines are used as a server, or in the unlikely event Active Directory Services are running on machines used as clients.
(***):If installed.
--
Swa Frantzen -- NET2S
Login here to post a comment. Diary Archive