KB # |
Exploit Type
Product |
Principle type of systems exposed |
Exploit details public? / Being exploited? |
Comprehensive, practical workaround available? |
MS severity rating |
Vulnerable
Windows or
Office versions |
Notes |
Randy’s recommendation |
2000 |
XP |
2003 |
Vista/ 2007 |
MS07-031 - 935840 |
Arbitrary code
Windows |
Workstations & Terminal Servers |
No/No |
No |
Critical |
Denial of Service only |
YES |
Denial of Service only |
No |
Mostly likely even on XP to cause denial of service instead of arbitrary code execution |
Patch after testing |
MS07-033 -
933566 |
Arbitrary code
Internet Explorer |
Workstations & Terminal Servers |
Yes/No |
No |
Critical |
Yes |
Yes |
Yes |
Yes |
6 different vulnerabilities
Only one is public and risk is limited to spoofed web pages |
Patch after testing |
MS07-034 -
929123 |
Arbitrary code
Outlook Express and Windows Mail |
Workstations & Terminal Servers |
Yes/No |
Mixed |
Critical |
No |
Yes - Important |
Yes - Moderate |
Yes – Critical |
4 different vulnerabilities with varying severity depending on OS |
Patch after testing or prevent users from using Windows Mail and Outlook Express |
MS07-035 -
935839 |
Arbitrary code
Windows |
Workstations & Terminal Servers |
No/No |
Yes |
Critical |
Yes |
Yes |
Yes |
No |
|
Patch after testing unless exploit details become public, then patch ASAP |
MS07-030 -
927051 |
Arbitrary code
Visio |
Workstations & Terminal Servers |
No/No |
No |
Important |
? |
Yes |
Yes |
No |
|
Patch after testing unless exploit details become public, then patch ASAP or block Visio files at perimeter |
MS07-032 -
931213 |
Information Disclosure
Windows Vista |
Workstations |
No/No |
No |
Moderate |
No |
No |
No |
Yes |
Mostly an issue for shared workstations or environments where end-users lack administrator authority on their workstations |
Patch after testing if an issue for your environment |