Microsoft Black Tuesday - April 2007 - Michael Sutton's Blog -
Microsoft Black Tuesday - April 2007

The month of April started off with a bang, when Microsoft released MS07-017, a rare out of cycle patch but ended with a fizzle, with 8 additional vulnerabilities. While four critical vulnerabilities were addressed, that is down significantly from the 13 critical vulnerabilities that were patched in February 2007, the last full patch cycle (March was skipped). While it may at first appear encouraging to see the number of patches diminishing, don't be fooled. Take a quick look at upcoming advisories for 3Com's Zero Day Initiative or eEye Research and you'll see that they collectively have more than a dozen unpatched Microsoft vulnerabilities.

The February patch release was relatively small when compared to recent months. We ended up with 8 vulnerabilities in 5 bulletins having the following overall severity rankings.

  • 4 Critical
  • 3 Important
  • 1 Moderate

This month's bulletins included patches for one public vulnerability, beyond MS07-017 which was patched last week. The following publicly known issue received a patch:

  • MS07-021 (CVE-2006-6696) MsgBox (CSRSS) Remote Code Execution Vulnerability

Below is a cheat sheet for all 8 vulnerabilities.

Enjoy!

- michael

 

Bulletin  

Title

MS07-018  




CMS Memory Corruption Vulnerability
CVE-2007-0938
Critical
Public: No
Exploited: No

MS07-018  




CMS Cross-Site Scripting and Spoofing Vulnerability
CVE-2007-0939
Important
Discovered By: Martyn Tovey of Netcraft
Public: No
Exploited: No

MS07-019




UPnP Memory Corruption Vulnerability
CVE-2007-1204
Critical
Discovered By: Greg MacManus of iDefense Labs
Public: No
Exploited: No
Advisory: iDefense

MS07-020





Microsoft Agent URL Parsing Vulnerability
CVE-2007-1205
Critical
Discovered By: JJ Reyes and Carsten Eiram of Secunia
Public: No
Exploited: No
Advisory: Secunia

MS07-021




MsgBox (CSRSS) Remote Code Execution Vulnerability
CVE-2006-6696
Critical
Discovered By: Tim Garnett of Determina Security Research
Public: Yes
Exploited: No

MS07-021





CSRSS Local Elevation of Privilege Vulnerability
CVE-2007-1209
Important
Discovered By: eEye
Public: No
Exploited: No
Advisory: eEye

MS07-021



CSRSS DoS Vulnerability
CVE-2006-6797
Moderate
Public: No
Exploited: No

MS07-022





Kernel Local Elevation of Privilege Vulnerability
CVE-2007-1206
Important
Discovered By: eEye
Public: No
Exploited: No
Advisory: eEye

 


Posted 04-10-2007 4:56 PM by erik.peterson

Comments

Best Posts from around the Web » Microsoft Black Tuesday - April 2007 wrote Best Posts from around the Web » Microsoft Black Tuesday - April 2007
on 04-10-2007 6:04 PM