Home / vulnerabilities TA07-345A.txt
Posted on 12 December 2007
Source : packetstormsecurity.org Link
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
National Cyber Alert System
Technical Cyber Security Alert TA07-345A
Microsoft Updates for Multiple Vulnerabilities
Original release date: December 11, 2007
Last revised: --
Source: US-CERT
Systems Affected
* Microsoft Windows
* Microsoft Internet Explorer
Overview
Microsoft has released updates that address critical vulnerabilities
in Microsoft Windows and Internet Explorer. Exploitation of these
vulnerabilities could allow a remote, unauthenticated attacker to
execute arbitrary commands.
I. Description
Microsoft has released updates to address vulnerabilities that affect
Microsoft Windows and Internet Explorer as part of the Microsoft
Security Bulletin Summary for December 2007. The most severe
vulnerabilities could allow a remote, unauthenticated attacker to
execute arbitrary commands. For more information, see the US-CERT
Vulnerability Notes Database.
II. Impact
A remote, unauthenticated attacker could execute arbitrary commands on
a vulnerable system.
III. Solution
Apply updates from Microsoft
Microsoft has provided updates for these vulnerabilities in the
December 2007 security bulletins. The security bulletins describe any
known issues related to the updates. Administrators are encouraged to
note these issues and test for any potentially adverse effects.
Administrators should consider using an automated update distribution
system such as Windows Server Update Services (WSUS).
IV. References
* US-CERT Vulnerability Notes for Microsoft December 2007 updates -
<http://www.kb.cert.org/vuls/byid?searchview&query=ms07-dec>
* Microsoft Security Bulletin Summary for December 2007 -
<http://www.microsoft.com/technet/security/bulletin/ms07-dec.mspx>
* Microsoft Update - <https://www.update.microsoft.com/microsoftupdate/>
* Windows Server Update Services -
<http://www.microsoft.com/windowsserversystem/updateservices/default.mspx>
* Securing Your Web Browser - <http://www.us-cert.gov/reading_room/securing_browser/>
_________________________________________________________________
The most recent version of this document can be found at:
<http://www.us-cert.gov/cas/techalerts/TA07-345A.html>
_________________________________________________________________
Feedback can be directed to US-CERT Technical Staff. Please send
email to <cert@cert.org> with "TA07-345A Feedback VU#437393" in the
subject.
_________________________________________________________________
For instructions on subscribing to or unsubscribing from this
mailing list, visit <http://www.us-cert.gov/cas/signup.html>.
_________________________________________________________________
Produced 2007 by US-CERT, a government organization.
Terms of use:
<http://www.us-cert.gov/legal.html>
______________________________________________________________
Revision History
December 11, 2007: Initial release
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
iQEVAwUBR18Qd/RFkHkM87XOAQKmPggAizWEwWaIVeYlbdXw6zGMS/zhqNuynvo5
D5gHuhs0UL+V96A8Aa/2c5oLaLDnR6Udk3yC8dSN1tLhwavwlQfXW33kAWWHOHpA
xLzI/szcP/XRS6UgQeWC1caH6SAjdT6wbTBLh4QSa6jODGPpHFyRLbQV2x23XKC7
4ehLACrh+NRpGKSJRffZEkUHDSoFSmSpgQHpOIHHS+mHzJcqtAm8C/v7Y0i5qeRU
uWSqUBLYIhpcOaYGOjbVBOyemRGAUzrNZYbfYhHyP7mF5rYu2jMDF7LwaTwvnKG8
3Ljv6ChkQ+7OzbyFDIDmX1B2ZC/gRUphdZrPkAGqPTChAAv/JbmxkQ==
=lx4/
-----END PGP SIGNATURE-----