July 2007
Microsoft Security Bulletin Advance Notification for July 2007
ID: 152
Ref: 97/2007
Date: 09 July 2007:16:28:27
Version: 1
Title: Microsoft Security Bulletin Advance Notification for July 2007
Abstract: Advance notification of six security bulletins that Microsoft is intending to release on July 10, 2007.
Vendors affected: Microsoft
Operating systems affected: Microsoft
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
********************************************************************
Microsoft Security Bulletin Advance Notification for July 2007
Issued: July 5, 2007
********************************************************************
This is an advance notification of six security bulletins that Microsoft is
intending to release on July 10, 2007.
The full version of the Microsoft Security Bulletin Advance Notification for
June 2007 can be found at
http://www.microsoft.com/technet/security/bulletin/ms07-jul.mspx.
This bulletin advance notification will be replaced with the July bulletin
summary on July 10, 2007. For more information about the bulletin advance
notification service, see
http://www.microsoft.com/technet/security/Bulletin/advance.mspx.
To receive automatic notifications whenever Microsoft Security Bulletins are
issued, subscribe to Microsoft Technical Security Notifications on
http://www.microsoft.com/technet/security/bulletin/notify.mspx.
Microsoft will host a webcast to address customer questions on these bulletins
on Wednesday, July 11, 2007, at 11:00 AM Pacific Time (US & Canada). Register
for the June Security Bulletin Webcast at
http://www.microsoft.com/technet/security/bulletin/summary.mspx.
Microsoft also provides information to help customers prioritize monthly
security updates with any non-security, high-priority updates that are being
released on the same day as the monthly security updates. Please see the
section, Other Information.
Critical Security Bulletins
===========================
Microsoft Security Bulletin 1
- Affected Software:
- Excel 2000 Service Pack 3
- Excel 2003 Service Pack 2
- Excel 2003 Viewer
- Excel 2007
- Office Compatibility Pack for Word, Excel,
and PowerPoint 2007 File Formats
- Impact: Remote Code Execution
- Version Number: 1.0
Microsoft Security Bulletin 5
- Affected Software:
- Microsoft Windows 2000 Service Pack 4
- Windows XP Service Pack 2
- Windows XP Professional x64 Edition
- Windows XP Professional x64 Edition Service Pack 2
- Windows Server 2003 Service Pack 1
- Windows Server 2003 Service Pack 2
- Windows Server 2003 x64 Edition
- Windows Server 2003 x64 Edition Service Pack 2
- Windows Server 2003 with SP1 for Itanium-based Systems
- Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Vista
- Windows Vista x64
- Impact: Remote Code Execution
- Version Number: 1.0
Microsoft Security Bulletin 4
- Affected Software:
- Microsoft Windows 2000 Server Service Pack 4
- Windows Server 2003 Service Pack 1
- Windows Server 2003 Service Pack 2
- Windows Server 2003 with SP1 for Itanium-based Systems
- Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Server 2003 x64 Edition
- Windows Server 2003 x64 Edition Service Pack 2
- Impact: Remote Code Execution
- Version Number: 1.0
Important Security Bulletins
============================
Microsoft Security Bulletin 2
- Affected Software:
- Publisher 2007
- Impact: Remote Code Execution
- Version Number: 1.0
Microsoft Security Bulletin 6
- Affected Software:
- Windows XP Professional Service Pack 2
- Impact: Remote Code Execution
- Version Number: 1.0
Moderate Security Bulletins
===========================
Microsoft Security Bulletin 3
- Affected Software:
- Windows Vista
- Windows Vista x64 Edition
- Impact: Information Disclosure
- Version Number: 1.0
Other Information
=================
Microsoft Windows Malicious Software Removal Tool:
==================================================
Microsoft will release an updated version of the Microsoft Windows Malicious
Software Removal Tool on Windows Update, Microsoft Update, Windows Server
Update Services, and the Download Center.
Note that this tool will not be distributed using Software Update Services (SUS).
Non-Security, High-Priority Updates on MU, WU, WSUS and SUS:
============================================================
For this month:
* Microsoft is planning to release four non-security,
high-priority updates on Microsoft Update (MU) and
Windows Server Update Services (WSUS).
* Microsoft is planning to release one non-security,
high-priority update for Windows on Windows Update (WU) and
Software Update Services (SUS).
Note that this information pertains only to non-security, high-priority
updates on Microsoft Update, Windows Update, Windows Server Update Services,
and Software Update Services released on the same day as the Security Bulletin
Summary. Information will not be provided about non-security updates released
on other days.
Recognize and avoid fraudulent e-mail to Microsoft customers:
=============================================================
If you receive an e-mail message that claims to be distributing a Microsoft
security update, it is a hoax that may contain malware or pointers to
malicious Web sites. Microsoft does not distribute security updates via
e-mail.
The Microsoft Security Response Center (MSRC) uses PGP to digitally sign all
security notifications. However, it is not required to read security
notifications, read security bulletins, or install security updates. You can
obtain the MSRC public PGP key at
https://www.microsoft.com/technet/security/bulletin/pgp.mspx.
To receive automatic notifications whenever Microsoft Security Bulletins are
issued, subscribe to Microsoft Technical Security Notifications on
http://www.microsoft.com/technet/security/bulletin/notify.mspx.
********************************************************************
THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS PROVIDED "AS IS"
WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS ALL WARRANTIES, EITHER
EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF MERCHANTABILITY AND FITNESS
FOR A PARTICULAR PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE FOR ANY
DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS
OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS
SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR
CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING LIMITATION MAY NOT APPLY.
********************************************************************
-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1
iQIVAwUBRo0px4lDklrxMhdPAQIB6xAAtAF/pWPNzjtw7kNSLlCgh+Hs+p2K68/i
hBxMeAKqjZZSAkuH+4cZi6HxOWeCjgAGKnZ7AKR7+N0yhq7iqZWYFzdYZ5vq6c1s
lyCVjh41kS8WhRP1qkIkAkcecmAGiCSnqssIBThIFSs+ZDZPjGkqVvsTORnYA1zn
32gQ2mjic8lAhCXJI2xiiHHVzotBHBM0Eon+irhDo4P/sXblHfgHBQbZOsAj0uaI
w1WrncLWWG9AxMhrb5cZs0BzrMeaHLYdPqVf59G1aTNzk/QPgIIDXzM1v5ahrCpA
tTUSho+cO9MQozX0uc4gKEtcJ/43s3zzKaEPOWQbs2Sd7mG1apqQXAJisS8PaM4r
Ency5CWEunmHVPCWcjNduMMkDbWPqHc6z1W4texkt1Q3Yt3V0XDRncLBKug0M38M
0iE29dQj1r7IamJUHofAmcgl14Eo6RxbxIe/BgFhVbWgR94bQLy6ainQnJxJcPdc
dO0ezzr1pZ2WRFECdtNJs/zyKikDI7X6PgIj3ZxC4yI69aE/MgXxrTqi6QA/4HHW
NyDFPpuu3OZIUJG/pilWrsKrBmKVCdEKw3R3iD6hQpg3yycFcJzezMa/RV8l44j5
Ugq3w+fqYtW1WZc045qrvL4x6MBgOachUTIOP74kH21ghRo3p5atz6IqZN7ksHNk
8YTDBU3D/DE=
=ZaCh
-----END PGP SIGNATURE-----
Legal Information <http://www.microsoft.com/info/legalinfo/default.mspx>.
This newsletter was sent by the Microsoft Corporation
1 Microsoft Way
Redmond, Washington, USA
98052
___________________________________________________________________________
CPNI wishes to acknowledge the contributions of Microsoft for the
information contained in this advisory.
___________________________________________________________________________
This advisory contains information released by the original author. Some
of the information may have changed since it was released. If the issue
affects you, it may be prudent to retrieve the advisory from the site of
the original source to ensure that you receive the most current
information concerning that problem.
Reference to any specific commercial product, process, or service by trade
name, trademark manufacturer, or otherwise, does not constitute or imply
its endorsement, recommendation, or favouring by CPNI. The views and
opinions of authors expressed within this notice shall not be used for
advertising or product endorsement purposes.
CPNI shall not accept responsibility for any errors or omissions
contained within this advisory. In particular, they shall not be liable
for any loss or damage whatsoever, arising from or in connection with the
usage of information contained within this advisory.
CPNI is a member of the Forum of Incident Response and Security Teams
(FIRST) and has contacts with other international Incident Response Teams
(IRTs) in order to foster cooperation and coordination in incident
prevention, to prompt rapid reaction to incidents, and to promote
information sharing amongst its members and the community at large.
___________________________________________________________________________