Tuesday, December 02, 2008   
  Search   
 
Register  Login  
Forums  
     Minimize  

Welcome to MeraWindows forums.

Thank you for being at the Microsoft Windows Community Site. You may have to register before posting in forums. It's absolutely free. After registering, you can get all the benefits available to our registered members, you can access our Downloads section, you can participate in contests, etc. You can post in forums in English as well as in Hindi, in fact we encourage you to use Hindi in your posts. If you have any problem with registration or login, please contact us.

     
  


 
  Microsoft Windows Forums  Security Center  Windows Updates  Microsoft Security Bulletin Summary for February, 2007
Previous Previous
 
Next Next
New Post 2/14/2007 9:43 AM
User is offline Ankur Mittal
3789 posts
ankurmittal.com
Distinguished Member




Microsoft Security Bulletin Summary for February, 2007 

CRITICAL

Bulletin Identifier Microsoft Security Bulletin MS07-008

Bulletin Title

Vulnerability in HTML Help ActiveX Control Could Allow Remote Code Execution (928843)

Executive Summary

This update resolves a vulnerability in HTML Help that could allow remote code execution.

Maximum Severity Rating

Critical

Impact of Vulnerability

Remote Code Execution

Affected Software

Windows. For more information, see the Affected Software and Download Locations section.

 

Bulletin Identifier Microsoft Security Bulletin MS07-009

Bulletin Title

Vulnerability in Microsoft Data Access Components Could Allow Remote Code Execution(927779)

Executive Summary

This update resolves a vulnerability in Microsoft Data Access Components that could allow remote code execution.

Maximum Severity Rating

Critical

Impact of Vulnerability

Remote Code Execution

Affected Software

Windows. For more information, see the Affected Software and Download Locations section.

 

Bulletin Identifier Microsoft Security Bulletin MS07-010

Bulletin Title

Vulnerability in Microsoft Malware Protection Engine Could Allow Remote Code Execution (932135)

Executive Summary

This update resolves a vulnerability in the Microsoft Malware Protection Engine that could allow remote code execution.

Maximum Severity Rating

Critical

Impact of Vulnerability

Remote Code Execution

Affected Software

Microsoft Antivirus. For more information, see the Affected Software and Download Locations section.

 

Bulletin Identifier Microsoft Security Bulletin MS07-014

Bulletin Title

Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (929434)

Executive Summary

This update resolves vulnerabilities in Microsoft Word that could allow remote code execution.

Maximum Severity Rating

Critical

Impact of Vulnerability

Remote Code Execution

Affected Software

Office. For more information, see the Affected Software and Download Locations section.

 

Bulletin Identifier Microsoft Security Bulletin MS07-015

Bulletin Title

Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (932554)

Executive Summary

This update resolves vulnerabilities in Microsoft Office that could allow remote code execution.

Maximum Severity Rating

Critical

Impact of Vulnerability

Remote Code Execution

Affected Software

Office. For more information, see the Affected Software and Download Locations section.

 

Bulletin Identifier Microsoft Security Bulletin MS07-016

Bulletin Title

Cumulative Security Update for Internet Explorer (928090)

Executive Summary

This update resolves vulnerabilities in Internet Explorer that could allow remote code execution.

Maximum Severity Rating

Critical

Impact of Vulnerability

Remote Code Execution

Affected Software

Windows, Internet Explorer. For more information, see kthe Affected Software and Download Locations section.

IMPORTANT

Bulletin Identifier Microsoft Security Bulletin MS07-005

Bulletin Title

Vulnerability in Step-by-Step Interactive Training Could Allow Remote Code Execution (923723)

Executive Summary

This update resolves a vulnerability in Step-by-Step Interactive Training that could allow remote code execution. User interaction is required to exploit this vulnerability.

Maximum Severity Rating

Important

Impact of Vulnerability

Remote Code Execution

Affected Software

Windows, Interactive Training. For more information, see the Affected Software and Download Locations section.

 

Bulletin Identifier Microsoft Security Bulletin MS07-006

Bulletin Title

Vulnerability in Windows Shell Could Allow Elevation of Privilege (928255)

Executive Summary

This update resolves a vulnerability in Windows Shell that could allow elevation of privilege.

Maximum Severity Rating

Important

Impact of Vulnerability

Elevation of Privilege

Affected Software

Windows. For more information, see the Affected Software and Download Locations section.

 

Bulletin Identifier Microsoft Security Bulletin MS07-007

Bulletin Title

Vulnerability in Windows Image Acquisition Service Could Allow Elevation of Privilege (927802)

Executive Summary

This update resolves a vulnerability in the Windows Image Acquisition Service that could allow elevation of privilege.

Maximum Severity Rating

Important

Impact of Vulnerability

Elevation of Privilege

Affected Software

Windows. For more information, see the Affected Software and Download Locations section.

 

Bulletin Identifier Microsoft Security Bulletin MS07-011

Bulletin Title

Vulnerability in Microsoft OLE Dialog Could Allow Remote Code Execution (926436)

Executive Summary

This update resolves a vulnerability in Microsoft OLE Dialog that could allow remote code execution. User interaction is required to exploit this vulnerability.

Maximum Severity Rating

Important

Impact of Vulnerability

Remote Code Execution

Affected Software

Windows. For more information, see the Affected Software and Download Locations section.

 

Bulletin Identifier Microsoft Security Bulletin MS07-012

Bulletin Title

Vulnerability in Microsoft MFC Could Allow Remote Code Execution (924667)

Executive Summary

This update resolves a vulnerability in Microsoft MFC that could allow remote code execution. User interaction is required to exploit this vulnerability.

Maximum Severity Rating

Important

Impact of Vulnerability

Remote Code Execution

Affected Software

Windows, Visual Studio. For more information, see the Affected Software and Download Locations section.

 

Bulletin Identifier Microsoft Security Bulletin MS07-013

Bulletin Title

Vulnerability in Microsoft RichEdit Could Allow Remote Code Execution (918118)

Executive Summary

This update resolves a vulnerability in Microsoft RichEdit that could allow remote code execution. User interaction is required to exploit this vulnerability.

Maximum Severity Rating

Important

Impact of Vulnerability

Remote Code Execution

Affected Software

Windows, Office. For more information, see the Affected Software and Download Locations section.


 News Source: www.microsoft.com

Tech Today
 
New Post 2/15/2007 7:25 AM
User is offline Srinath Sadda
1230 posts
www.meraTechExplorer.com
MW Addict




Re: Microsoft Security Bulletin Summary for February, 2007 

Important vs. Critical

Many of the other patches fix problems that could give a remote attacker control of the computer, Randy Abrams, director of technical education at ESET, told TechNewsWorld. "They are very serious vulnerabilities."

Microsoft users should download all of the patches no matter how they are rated by Microsoft, he advised.

"Generally, an 'important' rating on a Microsoft bulletin means that the vulnerability won't exploit itself -- a user has to interact in the manner they normally would," he said. "There are some exceptions, but in most cases important updates should be treated as critical updates. Typically, the difference is in Microsoft PR and not in a significant real-world impact."

Some of the vulnerabilities were zero-day exploits, noted Gary Morse, president of Razorpoint Security Technologies. "Usually a vulnerability will get announced, and by the time the exploit code starts making the rounds, a fix is also available,"

"Zero-day exploits leave customers particularly vulnerable because there are no official patches yet available from the manufacturer," he added.


 
New Post 2/15/2007 7:27 AM
User is offline Srinath Sadda
1230 posts
www.meraTechExplorer.com
MW Addict




Re: Microsoft Security Bulletin Summary for February, 2007 

Whither Vista?

Windows Vista is not directly affected by any of the vulnerabilities, but the Internet security community jumped on the fact that Windows Defender is used with the new OS.

"The fact that Windows Defender is installed on Vista by default means that Microsoft's security software has put Vista users at risk," ESET's Abrams asserted.

Vista has the potential to offer better security than XP, but that does not mean it will not have vulnerabilities, he continued. "Vista should have fewer vulnerabilities than XP due to a better design process; however, vulnerabilities in Vista are to be expected, just as with any operating system."

A full evaluation of Vista's security won't be practical until more users have deployed the system, however.

"Malware for Vista won't start showing up until more people are using it," David Perry, Trend Micro's (Nasdaq: TMIC) Latest News about Trend Micro global director of education, told TechNewsWorld. "Right now, Mac OS X has a larger user base than Vista."

Source: Techtree.com, technologynews.com & Microsoft Security Team 


 
Previous Previous
 
Next Next
  Microsoft Windows Forums  Security Center  Windows Updates  Microsoft Security Bulletin Summary for February, 2007


   Get Your Own E-Mail Account @MeraWindows.com Minimize  
New Page 1 New Page 1
Show your cool quotient with @merawindows.com email account