The break that we were given in April when only 8 vulnerabilities were delivered is now a long lost memory. While May was not a record month, it was big with 18 overall vulnerabilities in seven advisories. More importantly, the vulnerabilities were strongly skewed toward critical with 14 of 18 reports receiving the top severity ranking. As always, while it's refreshing to get such a large bundle out of the way, don't relax just yet. Instead, take a quick look at upcoming advisories for 3Com's Zero Day Initiative or eEye Research and you'll see that they still collectively have more than a dozen unpatched Microsoft vulnerabilities despite the fact that two TippingPoint issues were addressed this month.
The 18 total vulnerabilities had the following overall severity rankings.
This month's bulletins included patches for three public vulnerabilities.
- MS07-024 (CVE-2007-0870) Word Document Stream Vulnerability
- MS07-027 (CVE-2007-0942) COM Object Instantiation Memory Corruption Vulnerability
- MS07-029 (CVE-2007-1748) DNS RPC Management Vulnerability
Most importantly, the zero-day Windows DNS RPC vulnerability was addressed. This was important as Microsoft had acknowledged targeted exploitation of this issue nearly a month ago.
Below is a cheat sheet for all 18 vulnerabilities.
Enjoy!
- michael
Posted
05-09-2007 1:05 AM
by
erik.peterson