July 2007
Microsoft Security Bulletin Summary for July 2007
ID: 157
Ref: 102/2007
Date: 11 July 2007:09:26:18
Version: 1
Title: Microsoft Security Bulletin Summary for July 2007
Abstract: This bulletin summary lists security bulletins released for July 2007. The full version of the Microsoft Security Bulletin Summary for July 2007 can be found at http://www.microsoft.com/technet/security/bulletin/MS07-jul.mspx
Vendors affected: Microsoft
Operating systems affected: Microsoft
Applications affected: Microsoft
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
********************************************************************
Title: Microsoft Security Bulletin Summary for July 2007
Issued: July 10, 2007
Version Number: 1.0
********************************************************************
This bulletin summary lists security bulletins released for July 2007.
The full version of the Microsoft Security Bulletin Summary for July
2007 can be found at
http://www.microsoft.com/technet/security/bulletin/MS07-jul.mspx
With the release of the bulletins for July 2007, this bulletin summary
replaces the bulletin advance notification originally issued July 5, 2007. For
more information about the bulletin advance notification service, see
http://www.microsoft.com/technet/security/Bulletin/advance.mspx.
To receive automatic notifications whenever Microsoft Security Bulletins are
issued, subscribe to Microsoft Technical Security Notifications on
http://www.microsoft.com/technet/security/bulletin/notify.mspx.
Microsoft is hosting a webcast to address customer questions on these
bulletins on Wednesday, July 11, 2007, at 11:00 AM Pacific Time (US & Canada).
Register for the July Security Bulletin Webcast at
http://www.microsoft.com/technet/security/bulletin/summary.mspx.
After this date, this webcast is available on-demand.
Microsoft also provides information to help customers prioritize monthly
security updates with any non-security, high-priority updates that are being
released on the same day as the monthly security updates. Please see the
section, Other Information.
Bulletin Information
====================
The security bulletins for this month are as follows, in order of
severity:
Critical Security Bulletins
===========================
MS07-036 - Vulnerabilities in Microsoft Excel Could Allow Remote Code
Execution (936542)
Affected Software:
- Excel 2000 Service Pack 3
- Excel 2003 Service Pack 2
- Excel 2003 Viewer
- Excel 2007
- Office Compatibility Pack for Word, Excel,
and PowerPoint 2007 File Formats
- Impact: Remote Code Execution
- Version Number: 1.0
MS07-039 - Vulnerability in Windows Active Directory Could Allow Remote Code
Execution (926122)
Affected Software:
- Windows 2000 Server Service Pack 4
- Windows Server 2003 Service Pack 1
- Windows Server 2003 Service Pack 2
- Windows Server 2003 with SP1 for Itanium-based Systems
- Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Server 2003 x64 Edition
- Windows Server 2003 x64 Edition Service Pack 2
- Impact: Remote Code Execution
- Version Number: 1.0
MS07-040 - Vulnerabilities in .NET Framework Could Allow Remote Code Execution
(931212)
Affected Software:
- Windows 2000 Service Pack 4
- Windows XP Service Pack 2
- Windows XP Professional x64 Edition
- Windows XP Professional x64 Edition Service Pack 2
- Windows Server 2003 Service Pack 1
- Windows Server 2003 Service Pack 2
- Windows Server 2003 x64 Edition
- Windows Server 2003 x64 Edition Service Pack 2
- Windows Server 2003 with SP1 for Itanium-based Systems
- Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Vista
- Windows Vista x64
- Impact: Remote Code Execution
- Version Number: 1.0
Important Security Bulletins
============================
MS07-037 - Vulnerability in Microsoft Office Publisher Could Allow Remote Code
Execution (936548)
Affected Software:
- Publisher 2007
- Impact: Remote Code Execution
- Version Number: 1.0
MS07-041 - Vulnerability in Microsoft Internet Information Services Could
Allow Remote Code Execution (939373)
Affected Software:
- Windows XP Professional Service Pack 2
- Impact: Remote Code Execution
- Version Number: 1.0
Moderate Security Bulletins
===========================
MS07-038 - Vulnerability in Windows Vista Firewall Could Allow Information
Disclosure (935807)
Affected Software:
- Windows Vista
- Windows Vista x64 Edition
- Impact: Information Disclosure
- Version Number: 1.0
Other Information
=================
Microsoft Windows Malicious Software Removal Tool:
==================================================
Microsoft has released an updated version of the Microsoft Windows Malicious
Software Removal Tool on Windows Update, Microsoft Update, Windows Server
Update Services, and the Download Center.
Note that this tool is not distributed using Software Update Services (SUS).
Non-Security, High-Priority Updates on MU, WU, WSUS and SUS:
For this month:
* Microsoft has released four non-security,
high-priority updates on Microsoft Update (MU) and
Windows Server Update Services (WSUS).
* Microsoft has released one non-security,
high-priority update for Windows on Windows Update (WU) and
Software Update Services (SUS).
Note that this information pertains only to non-security, high- priority
updates on Microsoft Update, Windows Update, Windows Server Update Services,
and Software Update Services released on the same day as the Security Bulletin
Summary. Information is not provided about non-security updates released on
other days.
Recognize and avoid fraudulent e-mail to Microsoft customers:
=============================================================
If you receive an e-mail message that claims to be distributing a Microsoft
security update, it is a hoax that may contain malware or pointers to
malicious Web sites. Microsoft does not distribute security updates via
e-mail.
The Microsoft Security Response Center (MSRC) uses PGP to digitally sign all
security notifications. However, it is not required to read security
notifications, read security bulletins, or install security updates. You can
obtain the MSRC public PGP key at
https://www.microsoft.com/technet/security/bulletin/pgp.mspx.
To receive automatic notifications whenever Microsoft Security Bulletins are
issued, subscribe to Microsoft Technical Security Notifications on
http://www.microsoft.com/technet/security/bulletin/notify.mspx.
********************************************************************
THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS PROVIDED "AS IS"
WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS ALL WARRANTIES, EITHER
EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF MERCHANTABILITY AND FITNESS
FOR A PARTICULAR PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE FOR ANY
DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS
OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS
SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR
CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING LIMITATION MAY NOT APPLY.
********************************************************************
-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1
iQIVAwUBRpPit4lDklrxMhdPAQJEQg//QFVyYaZ+K7yqdpb9sFZEI6C2pIxb5FiJ
kag9/aRfJCwwjm4sr1ylQBWzrwu7x5J0EC/H6vcHO6cH7FhPYjL3JqW6t8yZXgDr
vVwD5yNCjKqM4x7LtAsVoSG/ehu05XCctNokokfRoSA/7jZp20UNzVr8nZ0/zJSg
PnpXMEIhpOALjP9SkAOPKCg9sXGYQ1ogfM++qgHK8QVNshCwVkMw7+eXZWWxAX8k
o+Dd9vK7lPN9F3y47OFKVK/HMck+6jm4k1fQaysHNzxe57fpihjd1b4SkQH9YmH/
xnT+zIdirjCWoUi64/1WFZ/P3/F/W21xA38juO2pQ/rOD8RwlGg8JurqSFKtTFRF
n8qWDHM9n80aOIIdUnoah5NGFrR8ekkJ9SjKc6U1+1/oGo4IpplpB32umsR7i5lO
5/fVYFU9XjMAX0rJGm2bag+G9GUjMmn5lzhHTPxBqhJTKrrWa5B1/sJekM2/NbMI
EdfQntsY4/0+K0jk1/OU1JZ/Jgq0nNwer0Bg/4MNslGyyz85MIR5loJ5GGjtgFF8
WGEtcNknn8/5r2nCdUIMcxRF3YLR+8H0iCJ3gR/KJ51x8j7CGO+MbJHPUhCuAQ/W
S5zDJB4E0na3298xTWCOUAhwHosGw5qlGD6w9Wmf6PFXXIhuOhaIaYQbcdWQWdpt
NT47A/i/mcw=
=RqmQ
-----END PGP SIGNATURE-----
Legal Information <http://www.microsoft.com/info/legalinfo/default.mspx>.
This newsletter was sent by the Microsoft Corporation
1 Microsoft Way
Redmond, Washington, USA
98052
___________________________________________________________________________
CPNI wishes to acknowledge the contributions of Microsoft Corporation
for the information contained in this advisory.
___________________________________________________________________________
This advisory contains information released by the original author. Some of
the information may have changed since it was released. If the issue affects
you, it may be prudent to retrieve the advisory from the site of the original
source to ensure that you receive the most current
information concerning that problem.
Reference to any specific commercial product, process, or service by trade
name, trademark manufacturer, or otherwise, does not constitute or imply its
endorsement, recommendation, or favouring by CPNI. The views and opinions of
authors expressed within this notice shall not be used for advertising or
product endorsement purposes.
CPNI shall not accept responsibility for any errors or omissions
contained within this advisory. In particular, they shall not be liable for
any loss or damage whatsoever, arising from or in connection with the usage of
information contained within this advisory.
CPNI is a member of the Forum of Incident Response and Security Teams (FIRST)
and has contacts with other international Incident Response Teams (IRTs) in
order to foster cooperation and coordination in incident prevention, to prompt
rapid reaction to incidents, and to promote
information sharing amongst its members and the community at large.
___________________________________________________________________________