Microsoft curates Vista, Office 2007 and IE7
Redmond (USA) – Microsoft has released seven new security bulletins, all classified as “critical”, which address 19 security vulnerabilities in Windows, Internet Explorer, Office, Exchange, Cryptographic API Component Object Model (CAPICOM) and BizTalk.
The bulletin MS07-029 fixes a zero-day flaw in the RPC interface of the Windows 2000 Server and Windows Server 2003 DNS service. first worm capable of exploiting it. For details on the vulnerability, see the news published last month.
There are seven security bugs fixed in Office in all, and they are described in three different bulletins. L’ MS07-023 it concerns three flaws in Excel 2000, 2002, 2003 (including Viewer), 2007 and 2004 for Mac, considered “critical” in Office 2000 and “important” in the other editions of the suite. In all three cases, an attacker could exploit them to create files that, when opened with a vulnerable version of Excel, execute code with the same privileges as the local user.
L’ MS07-024 instead it concerns three flaws in Word 2000, 2002, 2003 (including Viewer), 2004 for Mac, and Works Suite 2004/2005/2006. Also in this case the problem is considered of the greatest seriousness in Office 2000 and “important” in the other cases: immune to any Word 2007 problem. A cracker could create malformed documents which, once opened, cause the execution of malicious code.
The latest Office bulletin is the MS07-025 , which fixes a vulnerability contained in the 2000, 2002, 2003 and 2007 versions of Excel, FrontPage, Publisher, Office SharePoint Designer 2007 and Expression Web. The problem is due to the incorrect handling of a malformed graphic object which, if inserted into the inside a malicious file, it can cause code execution. The vulnerability is considered “critical” in Office 2000 and “important” in other software affected by the problem.
The bulletin MS07-027 , which according to BigM “fixes several recently discovered vulnerabilities and reported both publicly and privately to Microsoft,” fixes five Internet flaws 5.x, 6, and 7 (including the version built into Windows Vista). Depending on the version of the browser and the version of Windows, the severity is more or less serious: in particular, Windows Server 2003 is the platform considered by Microsoft to be more difficult to “pierce”. All vulnerabilities can be exploited to execute code remotely.
Four other flaws were sealed by Microsoft in the 2000, 2003 and 2007 versions of Exchange, and except one, which was considered “critical”, were classified as “important”. In two cases the problems could be exploited to launch denial of service attacks, in one case to intercept personal information and in the latter case to execute code remotely.
The last “critical” vulnerability, described in MS07-028 bulletin, concerns CAPICOM, GDI + redistributable component of Microsoft Platform SDK CAPICOM and BizTalk Server 2004.
Microsoft has posted a summary of the vulnerabilities here, while the Internet Storm Center provides its usual summary table here.
Microsoft has also made it available a new update for Windows Vista related to the known compatibility issue between the Safely Remove Hardware feature of Vista and iPod. The update, which Microsoft’s Nick White qualifies as “definitive” (a first update had already been released at the end of March), can be downloaded immediately from here or, starting May 22, through Windows Update.
- Microsoft: Linux violates a sea of patents In an interview that appeared yesterday on CNNMoney.com, two executives from Microsoft’s legal department stated that some of the most…
- Tom Hanrahan is now a Microsoft man Redmond – It seems now confirmed the news, passed so far in silence, according to which Tom Hanrahan, already known…
- Microsoft’s August isn’t unpatched Redmond (USA) – Microsoft’s security team didn’t take vacation even in the hottest month. In mid-August, the Redmond big company…
- Microsoft fixes 15 vulnerabilities Redmond (USA) – Yesterday evening, Microsoft published six security bulletins, four of which rated with the highest degree of danger,…
- Novell continues to defend itself over the deal with Microsoft The Novell-Microsoft telenovela, which began last November with the controversial agreement between two companies who lived in the antithetical and…
- Microsoft fires on Vista Frankenstein Redmond (USA) – A few weeks after its new operating system debuted on the mass market, Microsoft launched the first…
- Turbolinux also joins forces with Microsoft Redmond (USA) – Microsoft continues to weave collaborative and cross-licensing relationships with companies that distribute Linux or that, in any…
- Microsoft announced the new Office Live Meeting Orlando (USA) – The new release of Office Live Meeting was announced by Microsoft in recent days at the Tech…
- WinHEC / Microsoft looks beyond the PC Los Angeles (USA) – Microsoft’s challenge is to bring computing into every aspect of daily life, while improving the ways…
- Microsoft retires Digital Image Suite Redmond (USA) – Microsoft has decided to stop developing its Digital Image Suite (DIS), a software that rivaled, at least…
- GPL3, Microsoft raises its shields Redmond (USA) – Microsoft has never officially spoken out on GPL3, but its reaction to the recent approval of the…
- UK, Microsoft launches an online petition London – The great battle conducted by Microsoft to have its Open XML standard, the backbone of Office and already…
- Microsoft will carry Digg advertising A few days ago the diabolical Microsoft signed an exclusive advertising agreement with the angelic platform Digg.com. The announcement exploded,…
- Google and Googleplex seen by Microsoft Take a former Microsoft employee who, after a fling with his startup, acquired by Google, decides to return to Redmond,…
- Microsoft UK, a video documents the defacement Last week the Microsoft.co.uk website was attacked by an unknown cracker who replaced a page with a photo of a…
- Microsoft tries to stem Brussels Brussels – Microsoft does not intend to stand by while every other day even some high poppies of the European…
- New CEO for Microsoft Italy Milan – “Mario Derba, in Microsoft Italy since July 2005 as Director of the Enterprise & Partner Group (EPG) Division…
- Microsoft is heading towards VoIP Orlando – It is VoiceCon Spring 2007, the forum on IP telephony organized this week in Orlando, the occasion chosen…
- Microsoft cancels Vista hack A few days ago Microsoft requested and obtained the cancellation of a hack for Windows Vista whose purpose was to…
- Microsoft, open source experiments Redmond (USA) – In recent years Microsoft has tried to make its own, by re-adapting them, certain principles underlying the…
- Microsoft joins the OpenAjax Alliance New York (USA) – OpenAjax Alliance, which aims to standardize components and development techniques AJAX (Asynchronous JavaScript and XML), can…
- Microsoft brings old PCs to Africa Africa as a privileged target in the fight against the Digital Divide, this is the message that Microsoft wants to…
- Microsoft blocks the expansion of its YouTube It was supposed to be Microsoft’s answer to Youtube and since it first appeared in September last year, it had…
- Samsung and Microsoft present the i600 Hong Kong – The new SGH-i600 Ultra Mobile Messaging, the first HSDPA terminal launched on the Asian market by the…
- Microsoft VoIP, not just software There is not only the software front: Microsoft’s objectives in the field of Internet telephony are expanding: the Redmond giant…
- Microsoft’s anti-PDF standard soon? Geneva – After Open XML, ECMA is preparing to standardize another native format of Office 2007: XML Paper Specification (XPS),…
- BlackBerry meets Microsoft.NET Waterloo (Canada) – To make life easier for mobile application developers, and increase interest in their BlackBerry platform, Research In…
- Microsoft, discoveries on spam and new hope Redmond (USA) – Microsoft researchers have carried out a study that aims to be an examination of the current state…
- Computer center at Microsoft Research in Trento Trento – In the coming months, a large cluster of computers for parallel computing will be installed in Trentino, mainly…
- Microsoft: ready to compete with Google In recent months, Microsoft’s head of software design, Ray Ozzie, had framed Google as a stimulus to launch the Redmond…
- Wikipedia, Wales excommunicates Microsoft Microsoft’s new initiative, designed to counter the broad support for the OpenDocument (ODF) open format, rather than its Office Open…
- Piedmont Region-Microsoft partnership signed Turin – As expected yesterday in Turin Microsoft, the Piedmont Region, the Turin Polytechnic and the University of Turin (School…
- Microsoft brings RFID to Biztalk Redmond (USA) – Microsoft has released an updated version of BizTalk Server 2006, R2, which introduces targeted support for RFID…
- Develop robots? With Microsoft it’s free Redmond (USA) – Presented for the first time to the public last June, Microsoft Robotics Studio is the first attempt…
- Anti-Microsoft gang licensed to scam Redmond – Microsoft sued a group of scammers who illegally – and at bargain prices – sold copies of Windows…
- Microsoft puts the Windows kernel on a diet Champaign-Urbana (USA) – The technological heart of the next major release of Windows will be compact enough to run on…
- Microsoft will save the UK archives London – Libraries and dusty archives have preserved cultural heritage and documents for centuries: the issues to be addressed were…
- Microsoft saws pieces from Viridian Redmond (USA) – To limit the development time of Viridian, code name of the virtualization technology that will be paired…
- Microsoft sinks Get the Facts Microsoft’s comparative advertising towards open software and the open code development model, so far embodied by the aggressive and low-impact…
- Microsoft at iPhone school? It is called Extensible Filtered Lists for Mobile Device User Interface and is the new user interface that Microsoft registered…
- All in the Microsoft Alliance Barcelona – The Spanish Microsoft TechEd IT Forum has baptized the new Redmond credo: “interoperability”. In fact, the Interoperability Vendor…
- Microsoft, mega fine for MP3 patent infringement The news of the megafin imposed by the San Diego federal jury on BigM for infringing the patents owned by…
- A Microsoft study attacks the GPL3 Alan MacCormack, a professor at Harvard Business School, has written, on commission from Microsoft, a study on the GPL3 that…
- Firefox crashes, Microsoft offers help It is quite rare for Firefox to crash, but when it does, and you are using Windows, Microsoft is ready…
- Microsoft fixes a dozen flaws Redmond (USA) – Yesterday evening Microsoft released six security bulletins, three of which were classified as critical, two as important…
- India, anti-Microsoft general strike Surat (India) – It’s bandh, or a general strike by Indian IT retailers in the state of Gujarat: Microsoft’s anti-piracy…
- Microsoft finds millions of infected Windows There are four million PCs that Microsoft’s Windows Malicious Software Removal Tool has identified in the first six months of…
- Microsoft launches a whole new Hotmail Milan – One day after the US debut, today the new Windows Live Hotmail becomes accessible also in Italy. Microsoft…
- I have a Microsoft in the gulliver! The idea will thrill some and will certainly send a chill on the back for many others. Microsoft has registered…
- Microsoft for the conversion of the guerrillas Bogotà – Microsoft’s money and know-how are reaching the Colombian government in recent weeks, which will use them to try…