On TV.com: TOP 10 Shows CANCELED Too Soon
BNET Business Network:
BNET
TechRepublic
ZDNet

February 13th, 2007

MS Patch Tuesday: 12 bulletins, 6 critical, 20 vulnerabilities

Posted by Ryan Naraine @ 10:45 am

Categories: Botnets, Browsers, Data theft, Exploit code, Hackers, Microsoft, Patch Watch, Uncategorized, Viruses and Worms, Vulnerability research, Zero-day attacks

Tags: Microsoft Office, Vulnerability, Microsoft Internet Explorer, Microsoft Corp., Microsoft Data Access Components, Ryan Naraine

Microsoft’s Patch Tuesday train rumbled into security central with a full load today: 12 bulletins with patches for at least 20 vulnerabilities in a wide range of widely used software products.

Six of the 12 bulletins are rated “critical,” Redmond’s highest severity rating.

As expected, there are fixes for gaping holes in the Microsoft Office desktop productivity suite but it is not immediately clear if all the flaws exploited in the recent zero-day attacks are covered.

The biggest batch is contained in MS07-014, which covers six different vulnerabilities in Microsoft Word. The Information and Communication Security Technology Center in Taiwan is credited with reporting two of the six Word bugs to Microsoft, suggesting that a government agency or business in Taiwan might have been the target of the attacks.

Four of the 12 bulletins deal with holes in Office applications — Access, Excel, FrontPage, Outlook, PowerPoint, Publisher and Word. A separate update (MS07-015) covers two different bugs in Excel and PowerPoint.

There’s also a “critical” fix (MS07-016) for the dominant Internet Explorer browser to cover a trio of PC takeover flaws if a user simply browses to a malicious Web page. Uberhacker HD Moore of BreakingPoint Systems is credited with reporting five class identifiers documented in one of IE vulnerabilities.

Another critical update, MS07-009, is also flagged as a high-priority issue because public proof-of-concept exploits are already available. This patch covers a bug in MDAC (Microsoft Data Access Components) that could be exploited via Internet Explorer. “The ADODB.Connection ActiveX control included in MDAC could, if passed unexpected data, cause Internet Explorer to fail in a way that could allow code execution,” according to the alert.

The critical MS07-010 update is also a big black eye for Microsoft. It covers a remote code execution hole that affects all the security products that use the Malware Protection Engine. Affected software include Windows Live OneCare, Microsoft Antigen 9.x, Microsoft Windows Defender, Microsoft ForeFront Security for Microsoft Exchange Server 1.x, and Microsoft ForeFront Security for SharePoint Server 1.x.

A successful exploit will completely compromise the affected computer.

Home users can download the patches from the Automatic Updates mechanism built into Windows. Patches also also be downloaded from Microsoft Update or Windows Update.

Security and reliability fixes for Microsoft Office can be downloaded from the Microsoft Office site.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 26 Talkback(s)
annoying instabilities
Well, the kindest thing I can think of to say is that none of the app crashes has yet directly crashed WinXP. I've observed quite a variety. After one login, WinXP MC2005 claimed the Paging file was e... (Read the rest)
Posted by: AlterGeek Posted on: 02/18/07 You are currently: a Guest | | Terms of Use
Oh what a tangled web we weave......  Shelendrea | 02/13/07
Be lucky  klumper | 02/13/07
Lucky eh, hate to take you to the race track  intrepi@... | 02/13/07
Just waiting for the Vista patches to start flowing out...  B.O.F.H. | 02/13/07
The last isn't Vista?  dlmeyer@... | 02/13/07
Windows 7 is what Vista should have been.  B.O.F.H. | 02/13/07
lol - as if  shraven | 02/14/07
more patches now that silly Bill Gates taunted  hirez | 02/13/07
Patch Brought Local Net To Knees...  KTHernandez | 02/13/07
Or your ISP might want to start installing some transparent caches  georgeou | 02/13/07
hmm  xiaodre | 02/13/07
Patch Stories Should Say which Version of Windows is being patched  Jeff Hayes | 02/13/07
Info on patches and versions  misceng | 02/14/07
Kudos to all the workers  TripleII | 02/13/07
And the saga continues ,,,  Intellihence | 02/13/07
Wasn't it broken to begin with ?  Intellihence | 02/13/07
Whatever the case this is rubbish ,,,  Intellihence | 02/13/07
Same tired bashers... Boring  No_Ax_to_Grind | 02/13/07
Same Old Rabble From A Senile Old Man  itanalyst | 02/13/07
To the Unix people  s_gamgee | 02/14/07
Nail hit on head  whisperycat | 02/14/07
EXACTAMUNDO!!! Good Post!!!  itanalyst | 02/14/07
IF I WERE A BANKER I WOULD BE EXTREMELY UPSET  BALTHOR | 02/14/07
For the nonprogrammers to understand  miyojim | 02/15/07
what a pain  cmegkp@... | 02/16/07
annoying instabilities  AlterGeek | 02/18/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline