August 14, 2007Microsoft released the August Security Update on August 14, 2007. Nine bulletins were released that address 14 individual vulnerabilities. Microsoft rated six bulletins as Critical. These bulletins address vulnerabilities in XML Core Services, OLE Automation, Excel, Internet Explorer, GDI, and the Vector Markup Language. Each of these vulnerabilities could allow a remote attacker to execute arbitrary code, but each exploit also requires some form of user interaction. Microsoft also released three Important bulletins to correct vulnerabilities in Windows Gadgets, Windows Media Player, Virtual PC, and Virtual Server that may also allow for code execution. Although the Windows Media Player vulnerabilities were rated Important, they also allow for remote code execution with user interaction. The vulnerabilities in Windows Gadgets only affect Windows Vista systems; therefore, controls in the operating system may mitigate the impact of exploit attempts. The Virtual PC and Virtual Server vulnerabilities could allow a local attacker to gain elevated privileges.
|
