• On CBS.com: Victoria Secret Model Contest -Vote Now!
October 9, 2007 10:50 AM PDT

Microsoft fixes 9 flaws in 6 patches; 4 are critical

by Robert Vamosi
  • Font size
  • Print
  • 10 comments

Microsoft today released its October 2007 security bulletin, which includes six updates: four are designated as Critical by the software giant; two are deemed Important, and one previously announced patch was dropped. On the Windows side there is a cumulative update for Internet Explorer, a patch for Outlook/Windows Mail, and one for an RPC vulnerability. On the Microsoft Office side, there is a patch for SharePoint Server and one critical patch for Microsoft Office Word, including Microsoft Office 2004 for Mac. And one patch for the Kodak Image Viewer. All Microsoft security patches for Windows and Office software are available via Microsoft Update or via the individual bulletins detailed below.

MS07-055: Critical

Entitled "Vulnerability in Kodak Image Viewer Could Allow Remote Code Execution (923810)," this bulletin affects users of Microsoft Windows 2000, Windows XP SP2, and Windows Server 2003 x64 and Itanium-based users, or Windows Vista, and addresses the vulnerability detailed in CVE-2007-2217. A vulnerability exists in the way that the Kodak Image Viewer, formerly known as Wang Image Viewer, handles specially crafted images files. Successful exploitation could allow remote code execution.

MS07-056: Critical

Entitled "Security Update for Outlook Express and Windows Mail (941202)," this bulletin affects users of Outlook Express 5.5, 6, and Windows Mail running on Windows 2000, Windows XP, and Windows Server 2003, and Windows Vista, and addresses the vulnerability detailed in CVE-2007-3897. Successful exploitation due to an incorrectly handled malformed NNTP response could allow remote code execution.

MS07-057: Critical

Entitled "Cumulative Security Update for Internet Explorer (939653)," this bulletin affects users of Internet Explorer 5.01, 6, and 7 running on Windows 2000, Windows XP, and Windows Server 2003, and Windows Vista, and addresses the four vulnerabilities detailed in CVE-2007-3892, CVE-2007-3893, CVE-2007-1091 and CVE-2007-3826. Successful exploitation due could allow remote code execution.

MS07-058: Important

Entitled "Vulnerability in RPC Could Allow Denial of Service (933729)," this bulletin affects users of Windows 2000, Windows Server 2003, Windows XP, and Windows Vista, and addresses the vulnerability detailed in CVE-2007-2228. Successful exploitation could lead to a denial-of-service vulnerability.

MS07-059: Important

Entitled "Vulnerability in Windows SharePoint Services 3.0 and Office SharePoint Server 2007 Could Result in Elevation of Privilege Within the SharePoint Site (942017)," this bulletin affects users of Microsoft Windows Server 2003 SP1 running SharePoint Services 3.0 and Microsoft Office SharePoint Server 2007, and addresses the vulnerability detailed in CVE-2007-2581. Successful exploitation could allow an attacker to run arbitrary script to modify a user's cache, resulting in information disclosure at the workstation.

MS07-060: Critical

Entitled "Vulnerability in Microsoft Word Could Allow Remote Code Execution (942695)," this bulletin affects users of Microsoft Office 2000 Service Pack 3, Microsoft Office XP Service Pack 3, and Microsoft Office 2004 for Mac, and does not affect Microsoft Office 2003 Service Pack 2 and 3 and 2007 Microsoft Office system, and addresses the vulnerability detailed in CVE-2007-3899. Successful exploitation if a user opens a specially crafted Word file with a malformed string could allow remote code execution.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from News Blog
Nvidia puts NForce chipset development on hold
Opera 10 browser is here
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
Add a Comment (Log in or register) (10 Comments)
  • prev
  • 1
  • next
Can't they get anything right?
by drukenhard October 9, 2007 12:08 PM PDT
thank god I'm free from windows now!
Reply to this comment
10.4.11?
by close5828 October 9, 2007 1:13 PM PDT
Yeah, 10.4.11 is indicative of Apple's perfection.

RSD, Overheating, Whine, etc. Yeah, a lot to envy in that camp.
View reply
in a word
by The_happy_switcher October 9, 2007 2:25 PM PDT
NO!
lulz mode
by igmuska October 9, 2007 2:19 PM PDT
hahahahahahaha

heard rumor that Microsoft is changing its name to MacroHard
Reply to this comment
patch me
by The_happy_switcher October 9, 2007 2:20 PM PDT
Is it Tuesday already? Why are you running Windows still? They should shut down Microsoft and return all the money to the stock holders.
Reply to this comment
Beware of patches
by dbrandon October 9, 2007 5:12 PM PDT
I just updated both of my computers and upon reboot I received an error message that windows service had determined my copy of Vista was not a genuine copy. After shutting down to reboot, other patches were applied and reboot was successful. Hope this doesn't happen to others.
Reply to this comment
A patch patch?
by Rick Cavaretti October 10, 2007 7:42 AM PDT
Flaws in existing patches? So they issued a patch to patch a patch.
I dare you to say that five times really fast by the way. Does
anyone proof their codes up there anymore? Or did that
department get outsourced?
Reply to this comment
LOL
by The_Decider October 14, 2007 9:15 AM PDT
An exploit that can lead to elevation of privileges is not rated critical?

Only in the nightmare known as Microsoft.
Reply to this comment
doesnt install
by yomyman October 14, 2007 11:25 AM PDT
stupid updates dont install.
Reply to this comment
(10 Comments)
  • prev
  • 1
  • next
advertisement

S.F. hacker space: Heaven for the DIY set?

The Noisebridge hacker space offers sewing and Mandarin classes, soldering workshops, Internet-controlled front door access, and a server room with no door.
• Photos: Circuits, code, community

The browser battles go on and on

roundup From Firefox to IE and from Chrome to Opera and Safari, there's no sitting still for browser makers looking to keep their products fresh and competitive.

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement
Click Here

Inside CNET News

Scroll Left Scroll Right