Microsoft Updates for Multiple Vulnerabilities
http://jvnrss.ise.chuo-u.ac.jp/jtg/trn/en/TRTA07-128A.html
JVNRSS based Status Tracking Notes: Microsoft has released updates that address critical vulnerabilities in Microsoft Windows, Internet Explorer, Office, Exchange, Cryptographic API Component Object Model (CAPICOM), and BizTalk. Exploitation of these vulnerabilities could allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial of service on a vulnerable system.JVNRSS Feasibility Study Teamjvn@jvn.jpTRTA07-128A2007-05-13T08:02+00:002007-05-10T09:33+00:002007-05-13T08:02+00:00MS07-027 mdsauth.dll NMSA Session Description Object SaveAs control, arbitrary file modification
http://www.securityfocus.com/bid
Arbitrary File Rewrite Vulnerability Proof Of Concept (CVE-2007-2221, MS07-027)
#Cid: 23827.html
Bugtraqhttp://www.microsoft.com/technet/security/bulletin/ms07-027.mspx2007-05-102007-05-102007-05-10ThreatCON (2) => (1)
https://tms.symantec.com/
Symantechttp://www.uscert.gov/cas/techalerts/TA07-128A.htmlhttp://www.microsoft.com/technet/security/bulletin/ms07-023.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-024.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-025.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-026.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-027.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-028.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-029.mspx2007-05-10T03:21+09:002007-05-10T03:21+09:002007-05-10T03:21+09:00May 2007 Microsoft Security Bulletin (seven critical patches)
http://www.jpcert.or.jp/at/2007/at070012.txt
JPCERT/CCJPCERT-AT-2007-0012http://www.uscert.gov/cas/techalerts/TA07-128A.htmlhttp://www.microsoft.com/technet/security/bulletin/ms07-023.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-024.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-025.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-026.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-027.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-028.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-029.mspx2007-05-09T01:04+00:002007-05-09T01:04+00:002007-05-09T01:04+00:00Microsoft Updates for Multiple Vulnerabilities
http://www.us-cert.gov/cas/techalerts/TA07-128A.html
Via US-CERT Mailing List
US-CERTTA07-128Ahttp://www.uscert.gov/cas/techalerts/TA07-128A.htmlhttp://www.microsoft.com/technet/security/bulletin/ms07-023.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-024.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-025.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-026.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-027.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-028.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-029.mspx2007-05-08T16:20-04:002007-05-08T16:20-04:002007-05-08T16:20-04:00Vulnerability in Windows DNS RPC Interface Could Allow Remote Code Execution (935966)
http://www.microsoft.com/technet/security/Bulletin/MS07-029.mspx
Security Bulletin published.
MicrosoftMicrosoft Security Bulletin MS07-029http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-17482007-05-08T12:42-07:002007-05-08T12:42-07:002007-05-08T12:42-07:00Microsoft Releases May Security Bulletin
http://www.us-cert.gov/current/archive/2007/05/08/archive.html#microsoft_releases_may_security_bulletin
Microsoft has released updates to address vulnerabilities in Microsoft Windows, Internet Explorer, Windows DNS RPC Interface, Office, Exchange, CAPICOM, and BizTalk as part of the Microsoft Security Bulletin Summary for May 2007.
US-CERThttp://www.uscert.gov/cas/techalerts/TA07-128A.html2007-05-08T14:20-04:002007-05-08T14:20-04:002007-05-08T14:20-04:00ThreatCON (1) => (2)
https://tms.symantec.com/
Symantechttp://www.uscert.gov/cas/techalerts/TA07-128A.htmlhttp://www.microsoft.com/technet/security/bulletin/ms07-023.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-024.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-025.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-026.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-027.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-028.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-029.mspx2007-05-09T03:00+09:002007-05-09T03:00+09:002007-05-09T03:00+09:00Microsoft Exchange MIME base64 code execution
http://www.iss.net/threats/262.html
Microsoft Exchange could allow a remote attacker to execute arbitrary code on the system, caused by improper decoding of MIME base64-encoded content.
Internet Security Systemshttp://xforce.iss.net/xforce/xfdb/33889http://www.microsoft.com/technet/security/Bulletin/MS07-026.mspx2007-05-082007-05-082007-05-08Microsoft Internet Explorer Msauth.dll Code Execution
http://www.iss.net/threats/263.html
Microsoft Internet Explorer could allow a remote attacker to execute arbitrary code on the system, caused by a vulnerability in the mdsauth.dll control in Windows Media Server.
Internet Security Systemshttp://xforce.iss.net/xforce/xfdb/33355http://www.microsoft.com/technet/security/Bulletin/MS07-027.mspx2007-05-082007-05-082007-05-08Microsoft Security Bulletin Summary for May 2007
http://www.microsoft.com/technet/security/bulletin/ms07-may.mspx
Included in this advisory are updates for newly discovered vulnerabilities.
MicrosoftMS07-MAYhttp://www.microsoft.com/technet/security/bulletin/ms07-023.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-024.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-025.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-026.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-027.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-028.mspxhttp://www.microsoft.com/technet/security/bulletin/ms07-029.mspx2007-05-082007-05-082007-05-08Vulnerability in RPC on Windows DNS Server Could Allow Remote Code Execution
http://www.microsoft.com/technet/security/advisory/935964.mspx
DNS RPC Management Vulnerability(CVE-2007-1748)
Advisory published.
MicrosoftMicrosoft Security Advisory (935964)http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1748http://www.microsoft.com/technet/security/bulletin/ms07-029.mspx2007-04-122007-04-122007-04-12Microsoft Excel BIFF File Format Named Graph Record Parsing Stack Overflow Vulnerability
http://www.zerodayinitiative.com/advisories/ZDI-07-026.html
Excel BIFF Record Vulnerability(MS07-023, CVE-2007-0215)
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office Excel. Exploitation requires that the attacker coerce the target into opening a malicious .XLS file.
Vulnerability Reported
Zero Day Initiative (ZDI)ZDI-07-026http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0215http://www.microsoft.com/technet/security/bulletin/MS07-023.mspx2006-11-162006-11-162006-11-16Microsoft Internet Explorer Table Column Deletion Memory Corruption Vulnerability
http://www.zerodayinitiative.com/advisories/ZDI-07-027.html
Uninitialized Memory Corruption Vulnerability(MS07-027, CVE-2007-0944)
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page.
Vulnerability Reported
Zero Day Initiative (ZDI)ZDI-07-027http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0944http://www.microsoft.com/technet/security/bulletin/ms07-027.mspx2006-10-032006-10-032006-10-03P2I4ElH3RZ5mSjG9nat8ocx5ffk=KnYbngJO3Ck5zRGjMq8OBizUC8o=ke5xgyViY0M4FtzQzDqRkz3Cam6eHBxA4cCaYLfRaLRgG6acfWydhwRfNoUsAxKf5bQGuMJVNDJU12lNZNUpF1ti6kxhRXDE/lQ+yC66VAf/DnazXKmOjTdLyVk62uVlQGh8PcdoKB4Sqbm6eOWC/pgMZRmB1VpTaKX5wpf2fZo=MIIEJTCCA46gAwIBAgIQH8+x187tRT6w02OJfpsddzANBgkqhkiG9w0BAQUFADCBzDEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xHzAdBgNVBAsTFlZlcmlTaWduIFRydXN0IE5ldHdvcmsxRjBEBgNVBAsTPXd3dy52ZXJpc2lnbi5jb20vcmVwb3NpdG9yeS9SUEEgSW5jb3JwLiBCeSBSZWYuLExJQUIuTFREKGMpOTgxSDBGBgNVBAMTP1ZlcmlTaWduIENsYXNzIDEgQ0EgSW5kaXZpZHVhbCBTdWJzY3JpYmVyLVBlcnNvbmEgTm90IFZhbGlkYXRlZDAeFw0wNjA2MTMwMDAwMDBaFw0wNzA2MTMyMzU5NTlaMIIBGzEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xHzAdBgNVBAsTFlZlcmlTaWduIFRydXN0IE5ldHdvcmsxRjBEBgNVBAsTPXd3dy52ZXJpc2lnbi5jb20vcmVwb3NpdG9yeS9SUEEgSW5jb3JwLiBieSBSZWYuLExJQUIuTFREKGMpOTgxHjAcBgNVBAsTFVBlcnNvbmEgTm90IFZhbGlkYXRlZDE0MDIGA1UECxMrRGlnaXRhbCBJRCBDbGFzcyAxIC0gTWljcm9zb2Z0IEZ1bGwgU2VydmljZTEgMB4GA1UEAxQXSlZOUlNTIFJlc2VhcmNoIFByb2plY3QxHzAdBgkqhkiG9w0BCQEWEGp2bnJzc0BpcGEuZ28uanAwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBANV6POygjjKOFc1uAG/YV5VpW07NCJpI3BGisMqVW8gkbU3Dk6gBCc4owM7r/JDIjJ0XmGUCMTsRCnijdbNnn9VR5tIgMhWC6p0+MeOzNQ0XOXEewfLV0nhd+7K3TgjwXNcWI02xqhv+NtD1BHzcDrkdCkGoxn/g1FgUnyhJ4Ob9AgMBAAGjgbUwgbIwCQYDVR0TBAIwADBEBgNVHSAEPTA7MDkGC2CGSAGG+EUBBxcDMCowKAYIKwYBBQUHAgEWHGh0dHBzOi8vd3d3LnZlcmlzaWduLmNvbS9ycGEwCwYDVR0PBAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMEBggrBgEFBQcDAjAzBgNVHR8ELDAqMCigJqAkhiJodHRwOi8vY3JsLnZlcmlzaWduLmNvbS9jbGFzczEuY3JsMA0GCSqGSIb3DQEBBQUAA4GBAHv9wR3h5rhh1JXN/2GBxPnBDfHUi9Jn5sfxDXvu88rNJnd4kMOhxNctZVk18/oegHdhHoxsjaNJ6v1xxpF2/u5ARoWT8TwaKnvYWwefupiTS326EY/52RVXwPtep9M02v+S2CwgF3aIKXuF5EuoR2NndxqCRUzns9AJt0qQIwmY