Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft

January 10th, 2007, 08:41 GMT · By

Microsoft Debuts the 2007 Patching Season

SHARE:

Adjust text size:


It has been a light patch debut in 2007 for Microsoft. The Redmond Company initially planned a total of eight security bulletins in January, but the original Microsoft Security Bulletin Advanced
Notification was adapted just one day after its release to list only four patches. "Included among the delayed releases are fixes for various Word issues. The updates for January that did make the cut cover 10 distinct vulnerabilities, which were primarily file-based, client-side issues in the Office suite," revealed Ben Greenbaum the manager of the DeepSight threat analysis team at Symantec.

Here are Microsoft's Security Bulletins for January, as presented by Christopher Budd, a Security Program Manager at Microsoft:

Microsoft Office (MS07-001)
- maximum severity rating of Important
- vulnerabilities could allow an attacker to run code in the context of the logged on user.
Microsoft Office (MS07-002)
- maximum severity rating of Critical
- vulnerabilities could allow an attacker to run code in the context of the logged on user.
Microsoft Office (MS07-003)
- maximum severity rating of Critical
- vulnerabilities could allow an attacker to to run code in the context of the logged on user.
Microsoft Windows (MS07-004)
- maximum severity rating of Critical
- vulnerabilities could allow an attacker to run code in the context of the logged on user.

These patches are designed to address a total of 10 vulnerabilities. One affects the Brazilian Grammar Checker in Office 2003. Five impact Microsoft Excel, providing fixes for Excel Malformed Record, Excel IMDATA Record, Excel Malformed Column Record, Excel Malformed String Remote and Excel Malformed Palette. Microsoft also delivered a fix for the Windows Vector Markup Language Buffer Overrun Vulnerability and three patches for flaws in Outlook.

However, the Redmond Company has failed to provide a patch for the highly publicized Windows Vista vulnerability. In fact, Microsoft is keeping quiet in relation to all four patches that it has pulled from the January security bulletins list. But as vista is scheduled for availability on January 29, 2007, Microsoft will have to publish an out of band release of the remaining patches.

TELL US WHAT YOU THINK:

1,525 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


133 Critical and Important Microsoft Vulnerabilities

Internet Explorer 7 - Zero Vulnerabilities

Inspect OS and Software Security

Seven December 2006 Security Bulletins

The Third Exploit for Microsoft Word Vulnerability

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM