Qualys Vulnerability R&D Lab has released new vulnerability checks in the Enterprise TruRisk Platform to protect organizations against 21 vulnerabilities that were fixed in 12 bulletins announced today by Microsoft. Customers can immediately audit their networks for these and other new vulnerabilities by accessing their Qualys subscription. Visit Qualys Security Blog to prioritize remediation.
Non-Qualys customers can audit their network for these and other vulnerabilities by signing up for a Qualys Free Trial, or by trying Qualys Community Edition.
Microsoft has released 12 security bulletins to fix newly discovered flaws in their software. Qualys has released the following checks for these new vulnerabilities:
Windows XP Embedded Systems:- For additional information regarding security updates for embedded systems, refer to the following MSDN blog(s):
February 2007 Windows XP Embedded Updates Now Available on the ECE (KB926436)
Microsoft Windows 2000 Service Pack 4 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=7b1a81d5-1072-49d9-a24a-0e2630f62d8c
Microsoft Windows XP Service Pack 2 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=e9b84661-25e3-4d38-95b1-8d3e7af565aa
Microsoft Windows XP Professional x64 Edition :
http://www.microsoft.com/downloads/details.aspx?FamilyId=57c1b19f-3242-457c-bedf-d35a8efe525c
Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=eaed6f59-801e-45d7-9518-469d0de13cad
Microsoft Windows Server 2003 for Itanium based Systems and Microsoft Windows Server 2003 with SP1 for Itanium based Systems :
http://www.microsoft.com/downloads/details.aspx?FamilyId=cd1b18ae-bc8d-4d73-847f-4fa7ca672c88
Microsoft Windows Server 2003 x64 Edition :
http://www.microsoft.com/downloads/details.aspx?FamilyId=11f4f8f6-b8ce-4a5f-b7ed-8389ccc56473
Refer to Micrsoft Security Bulletin MS07-011 for further details.
Microsoft has rated this issue as Important.
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS07-005 Step by Step Interactive Training when installed on Microsoft Windows 2000 Service Pack 4
MS07-005 Step by Step Interactive Training when installed on Microsoft Windows Server 2003 for Itanium based Systems, Microsoft Windows Server 2003 with SP1 for Itanium based Systems, and Microsoft Windows Server 2003 with SP2 for Itanium based Systems
MS07-005 Step by Step Interactive Training when installed on Microsoft Windows Server 2003 x64 Edition and Microsoft Windows Server 2003 x64 Edition Service Pack 2
MS07-005 Step by Step Interactive Training when installed on Microsoft Windows Server 2003, Microsoft Windows Server 2003 Service Pack 1, and Microsoft Windows Server 2003 Service Pack 2
MS07-005 Step by Step Interactive Training when installed on Microsoft Windows XP Professional x64 Edition and Microsoft Windows XP Professional x64 Edition Service Pack 2
MS07-005 Step by Step Interactive Training when installed on Microsoft Windows XP Service Pack 2 and Microsoft Windows XP Service Pack 3
Windows XP Embedded Systems:- For additional information regarding security updates for embedded systems, refer to the following MSDN blog(s):
February 2007 Windows XP Embedded Updates Now Available on the ECE (KB928255)
Microsoft Windows XP Service Pack 2 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=f821b3a0-4e5a-4737-b9bf-1249f6683f4d
Microsoft Windows XP Professional x64 Edition :
http://www.microsoft.com/downloads/details.aspx?FamilyId=75abff9b-c2b5-4151-b366-4be652882944
Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=418acc52-0ebd-4623-81a7-5eacc21c3965
Microsoft Windows Server 2003 for Itanium based Systems and Microsoft Windows Server 2003 with SP1 for Itanium based Systems :
http://www.microsoft.com/downloads/details.aspx?FamilyId=dc33a2fc-2d01-4577-b133-017493d1f278
Microsoft Windows Server 2003 x64 Edition :
http://www.microsoft.com/downloads/details.aspx?FamilyId=c3e55066-b34e-485d-ac04-179f8e3a407a
Refer to Micrsoft Security Bulletin MS07-006 for further details.
Windows Image Acquisition (WIA) enables imaging programs to communicate with imaging devices such as digital cameras and scanners.
Windows XP Embedded Systems:- For additional information regarding security updates for embedded systems, refer to the following MSDN blog(s):
February 2007 Windows XP Embedded Updates Now Available on the ECE (KB927802)
Microsoft Windows XP Service Pack 2 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=ce695e0e-938c-4fc6-a9a2-0eb9fc3e5512
Refer to Micrsoft Security Bulletin MS07-007 for further details.
HTML Help ActiveX control methods do not perform sufficient parameter validation.
Windows XP Embedded Systems:- For additional information regarding security updates for embedded systems, refer to the following MSDN blog(s):
February 2007 Windows XP Embedded Updates Now Available on the ECE (KB928843)
Microsoft has rated this issue as Critical.
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS07-008 Microsoft Windows 2000 Service Pack 4
MS07-008 Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1
MS07-008 Microsoft Windows Server 2003 for Itanium based Systems and Microsoft Windows Server 2003 with SP1 for Itanium based Systems
MS07-008 Microsoft Windows Server 2003 x64 Edition
MS07-008 Microsoft Windows XP Professional x64 Edition
MS07-008 Microsoft Windows XP Service Pack 2
Windows XP Embedded Systems:- For additional information regarding security updates for embedded systems, refer to the following MSDN blog(s):
February 2007 Windows XP Embedded Updates Now Available on the ECE (KB927779)
Microsoft Data Access Components 2.5 Service Pack 3 on Microsoft Windows 2000 Service Pack 4 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=EF163E3E-DD3B-4429-98A4-720DA2C96464
Microsoft Data Access Components 2.8 Service Pack 1 on Microsoft Windows XP Service Pack 2 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=6B0CDB65-AEF4-489F-B917-812D9F7687BD
Microsoft Data Access Components 2.8 on Microsoft Windows Server 2003 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=34D24335-4EC0-49E7-9E3F-787F89DD7B1D
Microsoft Data Access Components 2.8 on Microsoft Windows Server 2003 for Itanium based Systems :
http://www.microsoft.com/downloads/details.aspx?FamilyId=58322D1B-A1A8-4BA6-BA1B-6649013CC324
Refer to Micrsoft Security Bulletin MS07-009 for further details.
Microsoft has rated this issue as Critical.
Patches:
The following are links for downloading patches to fix these vulnerabilities:
MS07-010 Windows
MS07-010 Windows
Windows XP Embedded Systems:- For additional information regarding security updates for embedded systems, refer to the following MSDN blog(s):
February 2007 Windows XP Embedded Updates Now Available on the ECE (KB924667)
Microsoft Windows 2000 Service Pack 4 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=d6577f1f-0d9e-4856-b1d6-7e27657a3620
Microsoft Windows XP Service Pack 2 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=84ae4c62-89ae-410a-b34b-471e3c09ce98
Microsoft Windows XP Professional x64 Edition and Microsoft Windows XP Professional x64 Edition Service Pack 2 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=54e0dc33-6bad-476c-b4cf-b833d591aaad
Microsoft Windows Server 2003, Microsoft Windows Server 2003 Service Pack 1, and Microsoft Windows Server 2003 Service Pack 2 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=934ca609-d6bc-4bf0-8233-969eb43d48bb
Microsoft Windows Server 2003 for Itanium based Systems, Microsoft Windows Server 2003 with SP1 for Itanium based Systems, and Microsoft Windows Server 2003 with SP2 for Itanium based Systems :
http://www.microsoft.com/downloads/details.aspx?FamilyId=67f52e93-cd57-4852-b838-a958ab9b23fb
Microsoft Windows Server 2003 x64 Edition and Microsoft Windows Server 2003 x64 Edition Service Pack 2 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=f2ca9de9-f69e-4e34-9aa9-0b320d670e04
Microsoft Visual Studio .NET 2002 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=711F05A8-CD67-4702-B079-3FF79A3AB4DE
Microsoft Visual Studio .NET 2002 Service Pack 1 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=124F2D2D-8CF3-47F3-A8FD-24A9FACF4FA4
Microsoft Visual Studio .NET 2003 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=A05CE727-C5B5-4022-B7A0-D8861CE99209
Microsoft Visual Studio .NET 2003 Service Pack 1 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=1DD6D8E7-390B-4E02-9F16-AB9D5EF7792E
Refer to Micrsoft Security Bulletin MS07-012 for further details.
Windows XP Embedded Systems:- For additional information regarding security updates for embedded systems, refer to the following MSDN blog(s):
February 2007 Windows XP Embedded Updates Now Available on the ECE (KB918118)
Microsoft Windows Server 2003 x64 Edition :
http://www.microsoft.com/downloads/details.aspx?FamilyId=3b6ee258-b636-455b-8833-74dea6269e24
Microsoft Office 2000 Service Pack 3 :
http://www.microsoft.com/downloads/details.aspx?FamilyID=2FF67E78-2A08-45C9-A7AC-09678D060439
Microsoft Office XP Service Pack 3 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=85C5162C-FC35-40B4-AD04-ADD247950423
Microsoft Office 2003 Service Pack 2 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=6C3BCAB8-0C99-4BE6-8DE7-71D463473A4A
Microsoft Windows 2000 Service Pack 4 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=0b0b13d3-b2fb-4cf4-8ee1-51871d39eecd
Microsoft Windows XP Service Pack 2 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=3159428d-7212-4bf0-9699-3dbae5db6ca1
Microsoft Windows XP Professional x64 Edition :
http://www.microsoft.com/downloads/details.aspx?FamilyId=daf2f7ac-20b4-4ec9-9467-2ddd4fc493d6
Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=2e8d2355-d5c5-406d-9322-5fe1b2134d2f
Microsoft Windows Server 2003 for Itanium based Systems and Microsoft Windows Server 2003 with SP1 for Itanium based Systems :
http://www.microsoft.com/downloads/details.aspx?FamilyId=ed6dd20f-4c0b-48f7-a1f9-613265506835
Microsoft Project 2000 Service Release 1 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=019B11FC-00B8-451C-AB3C-772780D4C46A
Microsoft Office 2000 Multilanguage Packs :
http://www.microsoft.com/downloads/details.aspx?FamilyID=B5A087F8-74D2-4184-9986-23AB3C4EF7F2
Microsoft Project 2002 Service Pack 1 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=D162C366-C5E7-4850-B773-1FE669FAEEAF
For a complete list of patch download links, please refer to Micrsoft Security Bulletin MS07-013.
The following specific issues were reported. A remote code execution vulnerability exists:
- When Microsoft Word handles Word files with a specially crafted string or specially crafted data structure.
- When Microsoft Word parses a file and processes an unchecked count, a malformed drawing object or a malformed function.
Previously this was a Zero Day vulnerability.
Microsoft Office 2000 Service Pack 3 (Microsoft Word 2000 ):
http://www.microsoft.com/downloads/details.aspx?FamilyId=F1E61E6A-BE3D-4536-AF76-A11D5CE67199
Microsoft Office XP Service Pack 3 (Microsoft Word 2002 ):
http://www.microsoft.com/downloads/details.aspx?FamilyId=A1CA8DD7-0622-4D66-A85F-A6586545EF9D
Microsoft Office 2003 Service Pack 2 (Microsoft Word 2003 ):
http://www.microsoft.com/downloads/details.aspx?FamilyID=882F8503-DA72-43C9-B556-A002EC58F289
Microsoft Office 2003 Service Pack 2 (Microsoft Word Viewer 2003 ):
http://www.microsoft.com/downloads/details.aspx?FamilyId=FB59798B-AFE2-4103-9991-CBDD7686F9AD
Microsoft Works Suites (Microsoft Works Suite 2004 ):
http://www.microsoft.com/downloads/details.aspx?FamilyId=A1CA8DD7-0622-4D66-A85F-A6586545EF9D
Microsoft Works Suites (Microsoft Works Suite 2005 ):
http://www.microsoft.com/downloads/details.aspx?FamilyId=A1CA8DD7-0622-4D66-A85F-A6586545EF9D
Microsoft Works Suites (Microsoft Works Suite 2006 ):
http://www.microsoft.com/downloads/details.aspx?FamilyId=A1CA8DD7-0622-4D66-A85F-A6586545EF9D
Microsoft Office 2004 for Mac :
http://www.microsoft.com/mac/
Refer to Micrsoft Security Bulletin MS07-014 for further details.
This issue occurs when the application processes maliciously crafted files.
Microsoft Office 2000 Service Pack 3 :
http://www.microsoft.com/downloads/details.aspx?familyid=20E089E7-7DD3-44A4-ABFE-6D8C27721683
Microsoft Office XP Service Pack 3 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=C54B1FDA-1237-48F7-AD19-F0830EE0E8FF
Microsoft Office 2003 Service Pack 2 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=BB0973E7-275D-4491-9BA1-91EAEA84EEFD
Microsoft Project 2000 Service Release 1 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=3DF54B5C-CB82-4A99-9B90-EDAB38AD6310
Microsoft Project 2002 Service Pack 1 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=419191DC-01B8-4E2A-BA5B-71BF3066C169
Microsoft Visio 2002 Service Pack 2 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=F50A5111-0926-4221-96DF-18294230ED1E
Microsoft Office 2004 for Mac :
http://www.microsoft.com/mac/
Refer to Micrsoft Security Bulletin MS07-015 for further details.
Windows XP Embedded Systems:- For additional information regarding security updates for embedded systems, refer to the following MSDN blog(s):
February 2007 Windows XP Embedded Updates Now Available on the ECE (KB928090)
Microsoft Internet Explorer 5.01 Service Pack 4 on Windows 2000 Service Pack 4 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=2D83EFCE-E507-4AFF-AB9B-EAF1D0D6320D
Microsoft Internet Explorer 6 Service Pack 1 when installed on Windows 2000 Service Pack 4 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=D9E4181A-05F9-4186-BDCA-C95351983844
Microsoft Internet Explorer 6 for Windows XP Service Pack 2 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=D4038DC1-8AF6-4BEA-82B8-EACCFF4CDB28
Microsoft Internet Explorer 6 for Windows XP Professional x64 Edition :
http://www.microsoft.com/downloads/details.aspx?FamilyId=D6EEEA2C-785E-4DEF-913E-7F121556554F
Microsoft Internet Explorer 6 for Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=C6BCBE07-39C1-4705-A10D-019DA3F997E5
Microsoft Internet Explorer 6 for Windows Server 2003 for Itanium based Systems and Windows Server 2003 with SP1 for Itanium based Systems :
http://www.microsoft.com/downloads/details.aspx?FamilyId=6476A14B-0D00-4F55-A438-E140E9D26849
Microsoft Internet Explorer 6 for Windows Server 2003 x64 Edition :
http://www.microsoft.com/downloads/details.aspx?FamilyId=C18DB204-0F2C-4DD4-B29C-0938FF1BFD7B
Windows Internet Explorer 7 for Windows XP Service Pack 2 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=EE851EFD-2CAF-41CE-A423-E1827DE318DF
Windows Internet Explorer 7 for Windows XP Professional x64 Edition :
http://www.microsoft.com/downloads/details.aspx?FamilyId=AC084BBB-084D-47AC-BFDA-156E34A63817
Windows Internet Explorer 7 for Windows Server 2003 Service Pack 1 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=36DAE010-AD1F-4E77-A353-9AFA41F065EA
Windows Internet Explorer 7 for Windows Server 2003 with SP1 for Itanium based Systems :
http://www.microsoft.com/downloads/details.aspx?FamilyId=631B590D-98CE-440D-B588-88CC31BB9370
For a complete list of patch download links, please refer to Micrsoft Security Bulletin MS07-016.
These new vulnerability checks are included in Qualys vulnerability signature 1.16.77-5. Each Qualys account is automatically updated with the latest vulnerability signatures as they become available. To view the vulnerability signature version in your account, from the Qualys Help menu, select the About tab.
To perform a selective vulnerability scan, configure a scan profile to use the following options:
In addition, prior to running a scan for these new vulnerabilities, you can estimate your exposure to these new threats by running the Risk Analysis Report, available from the Qualys Vulnerability Management Reports tab.
Platforms and Platform Identification
For more information, customers may contact Qualys Technical Support.
The Enterprise TruRisk Platform and its integrated suite of security and compliance applications provides organizations of all sizes with a global view of their security and compliance solutions, while drastically reducing their total cost of ownership. Qualys solutions include: continuous monitoring, vulnerability management, policy compliance, PCI compliance, security assessment questionnaire, web application scanning, web application firewall, malware detection and SECURE Seal for security testing of web sites.