Tech Features

Microsoft releases security patches, and updates (Technical Overview)

By Steve Ragan Feb 14, 2007, 16:08 GMT

Microsoft recently updated Windows systems and offered protection for twelve security vulnerabilities. The largest patch release of the year, some of these twelve patches were withheld in January when the original eight patches were cut to four just before their release.

Addressing what many called critical or serious, Microsoft has released details of what was fixed, and what the patches covered. Monsters and Critics provide a brief executive overview of the MS-Bulletin Summary for February 2007, as well as updates released by Microsoft as well as the current list of known unpatched flaws. A full technical listing of related links and articles will follow.

According to the release by Microsoft, the following were reported as Critical and are in need of Urgent Attention by IT administrators, and home users. The first set of Critical patches cover MS-07-008, 009, and 010. Each one addresses security flaws allowing for remote code execution on an exploited system. The programs affected were HTML Help, Microsoft Data Access Components, and Microsoft Malware Protection Engine. The HTML Help and MDAC are ActiveX Exploits. They have existed since August 8, 2006, and April of 2006. Html Help and MDAC have exploit proof of concept code online, and are subject to targeted attack, or exploitation on unpatched systems.

The second set of Critical patches cover MS-07-014, 015, and 016. Each one addresses security flaws allowing for remote code execution on an exploited system. The programs affected were Microsoft Word, Microsoft Office, and Internet Explorer.

The Microsoft Word exploits are different form the ones covered on Microsoft office as they are targeted at Word only. The Microsoft Office exploits were general in nature and would word on a range of Office applications. The Word and Office security risks have been known to the public since October 10, 2006, and December 12,2006.

Exploitation proof of concept code has been released for both the Office and the Word vulnerabilities. The concept code for exploitation of Internet Explorer is not public. 

According to the release by Microsoft, the following were reported as Important and are in need of Attention by IT administrators, and home users.

MS07-005, 006, 007, 011, 012, and 013 include the following list of vulnerabilities.

Vulnerability in Step-by-Step Interactive Training Could Allow Remote Code Execution.
-Exploitation proof of concept code not public

Vulnerability in Windows Shell Could Allow Elevation of Privilege.
-Exploitation proof of concept code not public

Vulnerability in Windows Image Acquisition Service Could Allow Elevation of Privilege.
-Exploitation proof of concept code not public

Vulnerability in Microsoft OLE Dialog Could Allow Remote Code Execution.
-Exploit code is public

Vulnerability in Microsoft MFC Could Allow Remote Code Execution.
- Exploit code is public

Vulnerability in Microsoft RichEdit Could Allow Remote Code Execution.
- Found in Mac OS X versions of Office.
- Exploitation proof of concept code no public

After the patches offered by Microsoft are applied, there remain a number of unpatched security holes. The following are a list of unpatched security vulnerabilities on Microsoft Windows or Microsoft Office.

Microsoft Word 2000
Microsoft PowerPoint 2003
Internet Explorer msxml3
NetWkstaUserEnum() memory allocation exhaustion
MessageBox () csrss double free vulnerability
RPC in Windows 2000 SP4 UPnP and SPOOLS
Microsoft Windows NAT Helper Components

These open and unpatched bugs pose little risk. They either offer a denial-of-service or remove code execution scenario.

Technical notices and links for unpatched Windows vulnerabilities:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0870
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0099
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6723
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6696
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6296
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3644
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5614
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5296

Technical Bulletins and Notes for Critical Updates (2-13-2007)
http://www.microsoft.com/technet/security/Bulletin/MS07-008.mspx
http://www.microsoft.com/technet/security/Bulletin/MS07-009.mspx
http://www.microsoft.com/technet/security/Bulletin/MS07-010.mspx
http://www.microsoft.com/technet/security/Bulletin/MS07-014.mspx
http://www.microsoft.com/technet/security/Bulletin/MS07-015.mspx
http://www.microsoft.com/technet/security/Bulletin/MS07-016.mspx

Technical Bulletins and Notes for Important Updates (2-13-2007)
http://www.microsoft.com/technet/security/Bulletin/MS07-005.mspx
http://www.microsoft.com/technet/security/Bulletin/MS07-006.mspx
http://www.microsoft.com/technet/security/Bulletin/MS07-007.mspx
http://www.microsoft.com/technet/security/Bulletin/MS07-011.mspx
http://www.microsoft.com/technet/security/Bulletin/MS07-012.mspx
http://www.microsoft.com/technet/security/Bulletin/MS07-013.mspx

The next block of links deal with Windows vulnerabilities that were patched (2-13-2007)

Related Common Vulnerabilities and Exposures (CVE) Links:
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3448
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0211
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0210
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0214
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5559
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5270
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0026
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0025
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1311
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3877
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0671
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4697
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0219
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0217

Microsoft Word exploits and vulnerabilities
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5994
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6456
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6561
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0208
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0209
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0515



COMMENT

FROM THE WEB

Further Reading on M&C

COMMENT on Microsoft releases security patches, and updates (Technical Overview)

comments powered by Disqus

Latest Headlines in Tech

Monsters and Critics is Looking for Writers and Reviewers

Sites We Like

Site Scene
The Tech Herald

Follow Us

Follow M&C on Pinterest

Search

Custom Search

Classic Games on M&C

Crush the Castle 2

Beer Pong

Bubble Bobble

Mah Jong Connect

Donkey Kong

Also Check Out

Product spotlight: Vice Merchants Sheets bring naughty fun to the linen closet

Product spotlight: Vice Merchants Sheets bring naughty fun to the linen closet
Thanks to a company called Vice Merchants, there is a new trend in bedding… sexy sheets for the same sex couple. ... more

Dieting, Italian Style – Bravissimo!

Dieting, Italian Style – Bravissimo!
Tisanoreica’s Old World Formula Meets The Latest In Medical Science To Lay ‘Waist’ To America’s Obesity Epidemic ... more

Memorial Day Weekend: Angry Orchard enhances Barbecue recipes

Memorial Day Weekend: Angry Orchard enhances Barbecue recipes
Memorial Day Weekend is sliding up on us, and we could not be happier about this. It means a few days where time is a little bit slower, and the food and drink are savory and satisfying but not too heavy. ... more

Abercrombie & Fitch's Big Fat Problem; everyone hates them (VIDEO)

Abercrombie & Fitchs Big Fat Problem; everyone hates them (VIDEO)
Abercrombie & Fitch CEO Mike Jeffries may want to zip it. ... more

Product spotlight: Gaiam Yoga clothes beat high priced competitors

Product spotlight: Gaiam Yoga clothes beat high priced competitors
To know me is to know that I love wearing gym clothes… all the time!  ... more

On the Web

ZergNet