Patch Tuesday Analysis for January 2007
2 months doesn’t make a trend but it looks like *something* is different about the code base of Vista, IE7 and Office 2007. For 2 months they haven’t inherited the vulnerabilities discovered in their predecessors.
Few of you out there are Vista and Office 2007 though so at least 2 of this month’s 4 vulnerabilities need your immediate attention. The VML content vulnerability (just like MS06-055) for sure. If your users don’t get email via POP, IMAP or HTTP (are you sure?) relax on the Outlook front. That leaves Excel and Portuguese/MUI versions of Office products. Oh, and Mac users weren’t left out as you’ll see.
| Bulletin | Exploit Types /Technologies Affected | System Types Affected | Exploit details public? / Being exploited? | Comprehensive, practical workaround available? | MS severity rating | Products Affected | Notes | Randy's recommendation | MS07-001
921585 | Arbitrary code
/ Office | Workstations Terminal Servers
| Yes/No | No | Important | Office 2003 Visio 2003 Frontpage 2003
| Portuguese and MUI editions only | Patch ASAP | MS07-003
925938 | Arbitrary code Denial of service
/ Outlook | Workstations Terminal Servers
| Yes/No | No | Critical | Office 2000 Office XP Office 2003
| Outlook receiving .iCal calendar | Patch any Outlook clients that use POP/IMAP/HTTP | MS07-002
927198 | Arbitrary code
/ Windows | Workstations Terminal Servers
| No/No | No | Critical | Office 2000 Office XP Office 2003 Office 2004 for Mac Works 2005 Works 2004 Works 2006
| Excel – Mac and Windows. Most versions | Patch after thorough testing | MS07-004
929969 | Arbitrary code
/ Windows | Workstations Terminal Servers
| Yes/Yes | Yes | Critical | Win2000 XP Server 2003
| Vector Markup Language content | Patch ASAP or implement one or more workarounds |
Receive Randy's same-day, independent analysis each Patch Tuesday
Email:
We will not share your address. Unsubscribe anytime.
|
"Thank you. I am very glad I subscribed to this newsletter.
Relevant content clearly and concisely. Finally!!!"
- John K.
"I really like the Fast Facts on this Month's Microsoft
Security Bulletins. Do you keep old copies? If yes, please let me know how I can
access them?"
-Susan D.
"Thanks, Randy. Your regular updates have streamlined my
monthly patching. Much appreciated,"
- Steve T.
"Really appreciate your patch observor. In the corporate
IT world, anything we can get our hands on that speeds the process of analyzing
threats and how they may or may not apply to our environments is a God-send.
Thanks so much for your efforts."
- Tess G.
"Many thanks for this Randy"
- Roger G.
"The chart is a REAAALLY good idea :)"
- Phil J.
"I like the table. Your insight is very valuable. "
Tom C.
"I liked your high level overview of patches in the
table. There are so many sources of patch information which can be very specific
or surrounded by other stuff that it’s refreshing to get everything summarised
like this. The “Randy’s Recommendation” comment is useful starting point too.
Please keep up the good work."
- David A.
"Your Patch Tuesday Observer is a very good tool in
making the decision whether to patch or not to patch. And also to patch asap or
to wait a while before patching. Also I do think the use of the table is realy
improving the readability of the provided information."
- Gerard T.
|