Overview of the December 2007 Microsoft patches and their status.
| # | Affected | Contra Indications | Known Exploits | Microsoft rating | ISC rating(*) | |
|---|---|---|---|---|---|---|
| clients | servers | |||||
| MS07-063 | An unspecified vulnerability in the implementation of the SMBv2 signing allows attackers to recompute signatures. | |||||
| Vista's SMBv2 CVE-2007-5351 |
KB 942624 | No publicly known exploits | Important | Important | Important | |
| MS07-064 | Input validation failures in DirectShow allows code execution through common file types. Replaces MS05-050 |
|||||
| Direct X CVE-2007-3901 CVE-2007-3895 |
KB 941568 | No publicly known exploits | Critical | Critical | Important | |
| MS07-065 | A buffer overflow allows code execution with system privileges. Replaces MS05-017 |
|||||
| Message queuing (MSMQ) CVE-2007-3039 |
KB 937894 | Exploit available in for pay program | Important | Important | Important | |
| MS07-066 | The advanced local procedure call (ALPC) allows allows escalation of privileges. | |||||
| Vista's kernel CVE-2007-5350 |
KB 943078 | No publicly known exploits | Important | Important | Important | |
| MS07-067 | Macrovision's secdrv.sys (part of SafeDisk, a copyright enforcing scheme using a driver to allow original disks of games to run) allows privilege escalation. | |||||
| secdrv.sys CVE-2007-5587 |
KB 944653 | Actively exploited | Important | Critical | Important | |
| MS07-068 | ASF, WMV, WMA input validation failures allow code execution. Replaces MS06-078 |
|||||
| Windows Media Format CVE-2007-0064 |
KB 941569 KB 944275 |
No publicly known exploits | Critical | Critical | Important | |
| MS07-069 | Multiple vulnerabilities in Internet Explorer allow remote code execution. Replaces MS07-057 |
|||||
| MSIE CVE-2007-3902 CVE-2007-3903 CVE-2007-5344 CVE-2007-5347 |
KB 942615 | Actively exploited | Critical | PATCH NOW | Important | |
--
Swa Frantzen -- Gorilla Security
Login here to post a comment. Diary Archive