Cisco Event Response: Microsoft Security Bulletin Release for September 2007

September 11, 2007

Microsoft released the September Security Update on September 11, 2007. Four bulletins were released that address four individual vulnerabilities. Microsoft rated one bulletin, which addresses Microsoft Agent, as Critical. This vulnerability could allow a remote attacker to execute arbitrary code, but an exploit requires some form of user interaction. Microsoft also released three Important bulletins to correct vulnerabilities in Windows Services for Unix, MSN Messenger, and Crystal Reports that may also allow for code execution with user interaction.


Cisco Applied Mitigation Bulletin

Cisco Applied Mitigation Bulletins provide identification and mitigation techniques that administrators can deploy on Cisco network devices. When applicable, Cisco IOS access control lists, Cisco Intrusion Prevention System (IPS) signatures, Control Plane Policing, Cisco Security Agent endpoint protection, and firewall rules are among the techniques discussed in the bulletins.

Cisco Applied Mitigation Bulletin: Microsoft Security Bulletin for September 2007


Cisco Security IntelliShield Alert Manager and Cisco IPS

The following table identifies Cisco Security IntelliShield Alert Manager alerts and Cisco IPS signatures associated with this Microsoft update:

Microsoft Security Bulletin Affected Product Cisco IntelliShield Alert CVE Name
Search CVEs
Cisco IPS Signature CVSS
Base Score
CVSS Q&A

Microsoft Security Bulletin MS07-051

Vulnerability in Microsoft Agent Could Allow Remote Code Execution

Microsoft Windows 2000 Microsoft Agent URL Memory Corruption Vulnerability CVE-2007-3040
5898-0 5856-1 5477-2
9.3

Microsoft Security Bulletin MS07-052

Vulnerability in Crystal Reports for Visual Studio Could Allow Remote Code Execution

Microsoft Visual Studio .NET

Microsoft Visual Studio 2005

Business Objects Crystal Reports Professional RPT File Buffer Overflow Vulnerability CVE-2006-6133
5435-0
9.3

Microsoft Security Bulletin MS07-053

Vulnerability in Windows Services for UNIX Could Allow Elevation of Privilege

Microsoft Windows Services for UNIX

Microsoft Subsystem for UNIX-based Applications

Microsoft Windows Services for UNIX Privilege Escalation Vulnerability CVE-2007-3036
6.8

Microsoft Security Bulletin MS07-054

Vulnerability in MSN Messenger and Windows Live Messenger Could Allow Remote Code Execution

Microsoft MSN Messenger

Microsoft Windows Live Messenger

Microsoft Windows Live Messenger Video Conversation Handling Buffer Overflow Vulnerability CVE-2007-2931
5899-0
9.3

 

Return to Cisco Security Center