On CBS MoneyWatch: 6 things NOT to do on Twitter, Facebook
BNET Business Network:
BNET
TechRepublic
ZDNet

June 12th, 2007

'Critical' Vista, IE 7 patches highlight MS security updates

Posted by Ryan Naraine @ 10:54 am

Categories: Botnets, Browsers, Data theft, Digital rights management, Exploit code, Hackers, Metasploit, Microsoft, Passwords, Patch Watch, Pen testing, Responsible disclosure, Vulnerability research, Windows Vista, Zero-day attacks

Tags: Security, Vulnerability, Microsoft Internet Explorer 7, Patch Management, Microsoft Windows Vista, Microsoft Windows, Microsoft Internet Explorer, Microsoft Corp., Bulletin, Ryan Naraine

This month’s batch of patches from Microsoft includes six bulletins covering at least 15 vulnerabilities, including several critical code execution holes in Windows Vista and Internet Explorer 7.

In all, Redmond pushed out four critical bulletins with fixes for flaws that could put Windows users at risk of complete PC takeover attacks.

http://content.zdnet.com/2346-12691_22-87874.htmlThe most serious is a cumulative Internet Explorer update (MS07-033) that affects all versions of the dominant browser — IE 5.01 on Windows 2000 through IE 7 on Windows Vista.

The mega IE update addresses a total of six flaws, including one that was publicly discussed prior to Patch Tuesday. Interestingly, all six IE bugs are rated “critical” across the board, except for some versions of Windows Server 2003.

(NOTE: Click on image at right for step-by-step instructions on some key configuration changes you can make to run/use IE securely)

Another high-priority update to pay special attention to is MS07-035, which touches a “critical” vulnerability in the way that the Win32 API validates parameters. This bug does not affect Windows Vista.

Microsoft provides a dire warning:

An attacker could exploit the vulnerability by constructing a specially crafted Web page that could potentially allow remote code execution if a user viewed the Web page. An attacker who successfully exploited this vulnerability could take complete control of an affected system.

Windows Vista is also immune to MS07-031, a “critical” bulletin that covers a flaw in the Secure Channel (Schannel) security package in Windows. “This vulnerability could allow remote code execution if a user viewed a specially crafted Web page using an Internet Web browser or used an application that makes use of SSL/TLS,” according to the bulletin. Affected software includes Windows 2000, Windows XP and Windows Server 2003.

However, the built-in Windows Mail client in Vista didn’t escape unscathed. The MS07-034 update contains fixes for four vulnerabilities (two publicly discussed before today) that could lead to code execution attacks. This update also affects Outlook Express.

The gaping hole that dings Windows Vista comes with this warning:

A remote code execution vulnerability results from the way local or UNC navigation requests are handled in Windows Mail. An attacker could exploit the vulnerability by constructing a specially crafted e-mail message that could potentially allow execution of code from a local file or UNC path if a user clicked on a link in the e-mail message. An attacker who successfully exploited this vulnerability could take complete control of an affected system.

Windows Vista users will also see an automatic update for MS07-032, a “moderate” bulletin that fixes an information disclosure issue. The bug “could allow non-privileged users to access local user information data stores including administrative passwords contained within the registry and local file system,” Microsoft warned.

The last bulletin this month (MS07-030) fixes two “important” bugs in Microsoft Visio 2002 and Microsoft Office Visio 2003.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 125 Talkback(s)
Message has been deleted...
Bok! Bok Bakock! Sounds like a barn yard around here! (Read the rest)
Posted by: JCitizen Posted on: 06/25/07 You are currently: a Guest | | Terms of Use
More critical security updates for Vista & Internet Explorer .  Intellihence | 06/12/07
Also as a side note ,,,  Intellihence | 06/12/07
I always wonder why most ie vulns end with  Suicida| | 06/12/07
Because it is the truth  Intellihence | 06/12/07
"Beyond the Vista  John Zern | 06/13/07
RE:Also as a side note ,,,  bmore_bro69@... | 06/13/07
Message has been deleted.  Intellihence | 06/13/07
How is that different than apple?  notsofast | 06/13/07
differenet in that MS suppoorts far more hardware  rtk | 06/13/07
And Mac's who comment on every MS post...  fr0thy2. | 06/13/07
Actually that must fall to Apple as well...  fr0thy2. | 06/13/07
To All: spot "boy" Leopard is scared of Vista  fr0thy2. | 06/13/07
re: Also as a side note ,,,  M.R. Kennedy | 06/13/07
lordie...  evilkillerwhale@... | 06/15/07
Don't you ever get tired of hearing your gums flapping together??  James T. Kirk | 06/12/07
I'm sorry to say but  Intellihence | 06/12/07
back to patching?  mdemuth | 06/12/07
Oh I have teeth literally ,  Intellihence | 06/12/07
wealthy - go play with your mp3s, and shoot a video with the other slackers  fr0thy2. | 06/13/07
Petty but wealthy  Chad_z | 06/12/07
Here is hoping it drives prices down  mdemuth | 06/12/07
what you can do with all that license money  wcb42ad | 06/13/07
He thinks you're using an Apple  John Zern | 06/13/07
Yes, because  notsofast | 06/13/07
Oh forgot Safari has to patch as well...you better get busy  fr0thy2. | 06/13/07
re:I'm sorry to say but  M.R. Kennedy | 06/13/07
No one here ever seems to tire  tic swayback | 06/12/07
Say what ,,,  Intellihence | 06/12/07
But even a fox...  tic swayback | 06/12/07
Their dedication to posting either says ...  ac2_z | 06/12/07
Talk about old world thinking will you .  Intellihence | 06/12/07
Companies have replaced local sports teams  tic swayback | 06/12/07
It's a matter of interpretation  ac2_z | 06/12/07
That's the delusion  tic swayback | 06/12/07
Hear Hear!  alfred321 | 06/12/07
I see your logic but  Intellihence | 06/12/07
Nothing to do with age  tic swayback | 06/12/07
RE: Nothing to do with age  James T. Kirk | 06/12/07
Nice touch tic it almost made me cry .  Intellihence | 06/12/07
How quaint  tic swayback | 06/13/07
"wars are fought and won..."  jacarter3 | 06/13/07
I knew it - he's a stupid kid. Living on Mommy and Daddy  fr0thy2. | 06/13/07
Is that why nothing but BS come out of your mouth  John Zern | 06/13/07
Hmmm  Norwalker | 06/14/07
Here's something new  Norwalker | 06/14/07
You Know The Anmswer to That one  bmore_bro69@... | 06/13/07
Message has been deleted.  Intellihence | 06/13/07
Children usually don't  fr0thy2. | 06/13/07
Seems he says "Message deleted" a lot doesn't it!  JCitizen | 06/14/07
Yep...  BitTwiddler | 06/12/07
Don't forget the rules.  ye | 06/12/07
Same rules don't apply ye .  Intellihence | 06/12/07
No surprise there. No wonder you consider...  ye | 06/12/07
Are you JOKING?  notsofast | 06/13/07
Umm Where Have you Been  bmore_bro69@... | 06/13/07
Where have you been hiding in the woodwork with L.D. ?  Intellihence | 06/13/07
Actually Numb n****  fr0thy2. | 06/13/07
Try fall - it was posponed remember.  fr0thy2. | 06/13/07
um...  evilkillerwhale@... | 06/15/07
get over yourself  ubaz2 | 06/12/07
Interestingly enough  Shelendrea | 06/12/07
Shelendrea my LOVE , where have you been ?  Intellihence | 06/12/07
here there and  Shelendrea | 06/12/07
Still love you girl . Keep up the hard work , you hear .  Intellihence | 06/12/07
Well I'll be  Shelendrea | 06/13/07
I seen a vision awhile ago .  Intellihence | 06/13/07
Hrmmm  Shelendrea | 06/13/07
Our Condolences...  fr0thy2. | 06/13/07
huh?  Shelendrea | 06/13/07
Sorry - to have spots be assoc. with you  fr0thy2. | 06/13/07
Patch Tuesday is a killer this month  Chad_z | 06/12/07
That's old news Chad_z  Intellihence | 06/12/07
Hehe, did you actually read the article you linked to?  NonZealot | 06/12/07
But isn't Vista suppose to be the most secure OS on the planet Mr. zealot  Intellihence | 06/12/07
By your definition, it is the most secure  mdemuth | 06/12/07
Old news indeed...  fde101 | 06/13/07
That won't help .  Intellihence | 06/13/07
Wow, the Apple zealot gets one right!!  NonZealot | 06/13/07
Zealot Mac OS X has File Vault .  Intellihence | 06/13/07
But BitLocker is better implemented  NonZealot | 06/13/07
I have yet to see you as expert in anything other then dribble  fr0thy2. | 06/13/07
Couldn't get to my machine nor my OS...sorry goof.  fr0thy2. | 06/13/07
wow  rtk | 06/13/07
I must be  anthony@... | 06/12/07
Message has been deleted.  Intellihence | 06/12/07
Message has been deleted.  Suicida| | 06/12/07
Message has been deleted.  Intellihence | 06/12/07
Message has been deleted.  bmore_bro69@... | 06/13/07
Message has been deleted.  Intellihence | 06/13/07
Message has been deleted...  JCitizen | 06/25/07
What have I been telling you?  Resuna | 06/12/07
We get screwed by this.  yupin1 | 06/12/07
Don't feel bad .  Intellihence | 06/12/07
What no games for Apple did you just admit to a flaw.  fr0thy2. | 06/13/07
Spys in me drives  deadguy69@... | 06/13/07
Mines just loads and it's fixed...  fr0thy2. | 06/13/07
Schmucks of All Stripes/Spots/Perspectives:  dshans@... | 06/12/07
Total over reaction as usual...  Mike Cox | 06/12/07
Meh. 5.0 (And who wound up doing the 'hard deploy'?)  James T. Kirk | 06/13/07
Only 1 - spot boy from the world of Mommy and Daddy  fr0thy2. | 06/13/07
Tired of hearing it!  joe6pack_z | 06/12/07
Here Here! ZDNet doesn't care about REAL News!  Narg | 06/12/07
Message has been deleted.  charles656oio@... | 06/12/07
Wait...  BlazingEagle | 06/12/07
Message has been deleted.  ballmerrules@... | 06/12/07
So much for only 31 vulnerabilities in first 6 months  Fred Fredrickson | 06/13/07
All Software  bmore_bro69@... | 06/13/07
You missed the point  Fred Fredrickson | 06/13/07
you're ignoring the point.  rtk | 06/13/07
OF Course!!! God Forbid  Aaron A Baker | 06/13/07
re:OF Course!!! God Forbid  bmore_bro69@... | 06/13/07
Message has been deleted.  Intellihence | 06/13/07
Looks like ZDNet has you pegged  No_Ax_to_Grind | 06/13/07
Amen Brother!  fr0thy2. | 06/13/07
moments away from having your connection dropped by yer ISP  rtk | 06/13/07
"Torvalds: Solaris could nudge Linux to GPL 3" leads here . . .  CobraA1 | 06/13/07
Yep  TripleII | 06/13/07
Re: Logic  Peconet Tietokoneet-21703818799325819467806990363298 | 06/13/07
Looks Like spot was booted -  fr0thy2. | 06/13/07
hopefully.  rtk | 06/13/07
reality  trm1945 | 06/13/07
Go Figure!  jackieprewitt@... | 06/13/07
Message Has Been Deleted  Linux User 147560 | 06/13/07
New Windows same problems  ihatelinux | 06/14/07
bot net sting  jnlubken@... | 06/14/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and