ID: 3378
Date: 12 September 2007 11:27
Title: 3378 - Microsoft Security Bulletin Summary for September 2007
Abstract: This bulletin summary lists security bulletins released for September 2007
Vendors affected:Microsoft
Applications affected:Agent (Windows 2000), Crystal reports redistributed with visual studio, Windows services for UNIX, Messenger
Availability of fix: Available
Type of fix: Patch
Source: Microsoft Corporation
Reliability of source: Trusted
Source URL: http://www.microsoft.com/technet/security/bulletin/ms07-sep.mspx
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
********************************************************************
Microsoft Security Bulletin Summary for September 2007
Issued: September 11, 2007
********************************************************************
This bulletin summary lists security bulletins released for September 2007.
The full version of the Microsoft Security Bulletin Summary for September 2007 can be found at http://www.microsoft.com/technet/security/bulletin/ms07-sep.mspx.
With the release of the bulletins for September 2007, this bulletin summary replaces the bulletin advance notification originally issued on September 6, 2007 and updated on September 7, 2007. For more information about the bulletin advance notification service, see http://www.microsoft.com/technet/security/Bulletin/advance.mspx.
To receive automatic notifications whenever Microsoft Security Bulletins are issued, subscribe to Microsoft Technical Security Notifications on http://www.microsoft.com/technet/security/bulletin/notify.mspx.
Microsoft is hosting a webcast to address customer questions on these bulletins on Wednesday, September 12, 2007, at 11:00 AM Pacific Time (US & Canada). Register for the September Security Bulletin Webcast at http://www.microsoft.com/technet/security/bulletin/summary.mspx.
Microsoft also provides information to help customers prioritize monthly security updates with any non-security, high-priority updates that are being released on the same day as the monthly security updates. Please see the section, Other Information.
Bulletin Information
====================
The security bulletins for this month are as follows, in order of
severity:
Critical Security Bulletins
===========================
MS07-051 - Vulnerability in Microsoft Agent Could Allow Remote Code Execution (938827)
- Affected Software:
- Microsoft Windows 2000 Service Pack 4
- Impact: Remote Code Execution
- Version Number: 1.0
Important Security Bulletins
============================
MS07-052 - Vulnerability in Crystal Reports for Visual Studio Could Allow Remote Code Execution (941522)
- Affected Software:
- Visual Studio .NET 2002 Service Pack 1 (KB937057)
- Visual Studio .NET 2003(KB937058)
- Visual Studio .NET 2003 Service Pack 1 (KB937059)
- Visual Studio 2005 (KB937060)
- Visual Studio 2005 Service Pack 1 (KB937061)
- Impact: Remote Code Execution
- Version Number: 1.0
MS07-053 - Vulnerability in Windows Services for UNIX Could Allow Elevation of Privilege (939778)
- Affected Software:
- Windows Services for UNIX 3.0 on Windows 2000 Service Pack 4
- Windows Services for UNIX 3.5 on Windows 2000 Service Pack 4
- Windows Services for UNIX 3.0 on Windows XP Service Pack 2
- Windows Services for UNIX 3.5 on Windows XP Service Pack 2
- Windows Services for UNIX 3.0 on Windows Server 2003 Service
Pack 1 and Windows Server 2003 Service Pack 2
- Windows Services for UNIX 3.5 on Windows Server 2003 Service
Pack 1 and Windows Server 2003 Service Pack 2
- Subsystem for UNIX-based Applications on Windows Server 2003
Service Pack 1 and Windows Server 2003 Service Pack 2
- Subsystem for UNIX-based Applications on Windows Server 2003
x64 Edition and Windows Server 2003 x64 Edition Service Pack 2
- Subsystem for UNIX-based Applications on Windows Vista
- Subsystem for UNIX-based Applications on Windows Vista x64
Edition
- Impact: Elevation of Privilege
- Version Number: 1.0
MS07-054 - Vulnerability in MSN Messenger and Windows Live Messenger Could Allow Remote Code Execution (942099)
- Affected Software:
- MSN Messenger 6.2
- MSN Messenger 7.0
- MSN Messenger 7.5
- Windows Live Messenger 8.0
- Impact: Remote Code Execution
- Version Number: 1.0
Other Information
=================
Microsoft Windows Malicious Software Removal Tool:
==================================================
Microsoft has released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.
Non-Security, High-Priority Updates on MU, WU, and WSUS:
========================================================
For this month:
* Microsoft has released zero non-security,
high-priority updates on Microsoft Update (MU) and
Windows Server Update Services (WSUS).
* Microsoft has released zero non-security,
high-priority updates for Windows on Windows Update (WU).
Note that this information pertains only to non-security, high-priority updates on Microsoft Update, Windows Update, and Windows Server Update Services released on the same day as the Security Bulletin Summary. Information is not provided about non-security updates released on other days.
Recognize and avoid fraudulent e-mail to Microsoft customers:
=============================================================
If you receive an e-mail message that claims to be distributing a Microsoft security update, it is a hoax that may contain malware or pointers to malicious Web sites. Microsoft does not distribute security updates via e-mail.
The Microsoft Security Response Center (MSRC) uses PGP to digitally sign all security notifications. However, it is not required to read security notifications, read security bulletins, or install security updates. You can obtain the MSRC public PGP key at https://www.microsoft.com/technet/security/bulletin/pgp.mspx.
To receive automatic notifications whenever Microsoft Security Bulletins are issued, subscribe to Microsoft Technical Security Notifications on http://www.microsoft.com/technet/security/bulletin/notify.mspx.
********************************************************************
THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING LIMITATION MAY NOT APPLY.
********************************************************************
-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1
iQIVAwUBRucXXYlDklrxMhdPAQLNaxAAss8u46Eu/G9z8sCN2oFaG74B8Knm2T9A
Eyu3ghBUICTGIZ2A8KEwtTY7wmPm7IQoCtrm7+lDSY8vpli6xVmbnpauaNcNV54R
dKuUJP8LPT6K/rgNpUgAY4utp4TUkj67PdsbZM+jwkwoA0qgygAz3OSsMQst4puV
1Uk6Cuh9CANOvo6RvROyuLHtX7y/16OE3Dyw6InHgoxAuldL+jk2ZGKHkJlZFysE
ajcBVhhARxsDsR0NPwr219dSGG8UVm6lNGj0BTjnJwTk11UcBwkUx+7HO+pBCwaj
h3Sadro8KDZZYdZqMIeFVi2oN9+Vt9ZBD26sgg5JS76ZmWwuKVsWRw0jhUjlWgPS
cCOEt2dt/huxMh3Obnr+EjP34MucuKHkzQZP/9wWz/rYqPNizRK18h9jdSZZlTVZ
uqxgppbbv0uIGTv/mHfKxlCr95WQEqEeU3MTPCLV7ZBbh1m9mJBkg2hx+NvNIMBB
ptzFcD2vSzkPL7muAahwYj+l9O/sa0BnqnT3ONESABgEuOH8m2F1S/8nDavmwSv5
m+/mCtLwtDt4+xF/K7X9poIm0dQ+WT1Q5+E5FKJ5YMaA1fQ8L9BLDtsQo9ZGnW03
q7mImQUEPudYY+ZKM+DLSV9i8Uh3zvmPcDok0CrR8lcEYtWXTYjDom36Cu44tWEZ
P77CUewFaXM=
=Slrs
-----END PGP SIGNATURE-----
This advisory contains information released by the original author. Some of the information may have changed since it was released. If the issue affects you, it may be prudent to retrieve the advisory from the site of the original source to ensure that you receive the most current information concerning that problem. Reference to any specific commercial product, process, or service by trade name, trademark manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favouring by CPNI.
The views and opinions of authors expressed within this notice shall not be used for advertising or product endorsement purposes. CPNI shall not accept responsibility for any errors or omissions contained within this advisory. In particular, they shall not be liable for any loss or damage whatsoever, arising from or in connection with the usage of information contained within this advisory.
CSIRTUK is a member of the Forum of Incident Response and Security Teams (FIRST) and has contacts with other international Incident Response Teams (IRTs) in order to foster cooperation and coordination in incident prevention, to prompt rapid reaction to incidents, and to promote information sharing amongst its members and the community at large.