MS07-039 - Critical: Vulnerability in Windows Active Directory Could Allow Remote Code Execution (926122)

Bulletin Severity Rating:Critical - This critical security update resolves a privately reported vulnerability in implementations of Active Directory on Windows 2000 Server and Windows Server 2003 that could allow remote code execution or a denial of service condition. Attacks attempting to exploit this vulnerability would most likely result in a denial of service condition. However remote code execution could be possible. On Windows Server 2003 an attacker must have valid logon credentials to exploit this vulnerability. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts. This is a critical security update for supported editions of Windows 2000 and an important security update for supported editions of Windows Server 2003. For more information, see the subsection, Affected and Non-Affected Software, in this section. This security update addresses the vulnerability by validating the number of convertible attributes in the client LDAP request.

Posted under Microsoft Security Alerts

This post was written by Microsoft Security Bulletins on July 10, 2007

MS07-040 - Critical: Vulnerabilities in .NET Framework Could Allow Remote Code Execution (931212)

Bulletin Severity Rating:Critical - This update resolves three privately reported vulnerabilities. Two of these vulnerabilities could allow remote code execution on client systems with .NET Framework installed, and one could allow information disclosure on Web servers running ASP.NET.

Posted under Microsoft Security Alerts

This post was written by Microsoft Security Bulletins on July 10, 2007

MS07-041 - Important: Vulnerability in Microsoft Internet Information Services Could Allow Remote Code Execution (939373)

Bulletin Severity Rating:Important - This important security update resolves a privately reported vulnerability. This vulnerability could allow remote code execution if an attacker sent specially crafted URL requests to a Web page hosted by Internet Information Services (IIS) 5.1 on Windows XP Professional Service Pack 2. IIS 5.1 is not part of a default install of Windows XP Professional Service Pack 2. An attacker who successfully exploited this vulnerability could take complete control of the affected system.

Posted under Microsoft Security Alerts

This post was written by Microsoft Security Bulletins on July 10, 2007