Fixlet Site - PatchesforWindows(Japanese) Current Version: 187 Published: Thu, 12 Jul 2007 23:19:26 GMT *************************************************************** Title: MS06-078: Vulnerability in Windows Media Format Could Allow Remote Code Execution - Windows XP SP2 (re-released 7/10/2007) (Japanese) Severity: Critical Fixlet ID: 607814 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS06-078.mspx Fixlet Description: Microsoft has released a patch that resolves two newly discovered vulnerabilities. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Microsoft recommends that customers apply the update immediately. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. Important Note: This patch was re-released on July 10, 2007 to address issues with error messages appearing while installing the patch on Windows XP Service Pack 2. The action below deploys the revised version of the patch. The changes made to the patch do not effect previous deployments therefore, re-deploying this patch is not neccesary. Important Note: There are several known issues associated with the installation of this patch. See the Caveats section of the security bulletin for more information. *************************************************************** Title: MS06-078: Vulnerability in Windows Media Format Could Allow Remote Code Execution - Windows Media Player 6.4 (re-released 7/10/2007) (Japanese) Severity: Critical Fixlet ID: 607816 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS06-078.mspx Fixlet Description: Microsoft has released a patch that resolves two newly discovered vulnerabilities. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Microsoft recommends that customers apply the update immediately. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. Important Note: This patch was re-released on July 10, 2007 to address issues with installing the patch on Windows 2003 Service Pack 2. The action below deploys the revised version of the patch. The changes made to the patch do not effect previous deployments therefore, re-deploying this patch is not neccesary. Important Note: There are several known issues associated with the installation of this patch. See the Caveats section of the security bulletin for more information. *************************************************************** Title: MS06-078: CORRUPT PATCH - Windows XP SP2 (re-released 7/10/2007) (Japanese) Severity: Critical Fixlet ID: 607820 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS06-078.mspx *************************************************************** Title: MS06-078: CORRUPT PATCH - Windows Media Player 6.4 (re-released 7/10/2007) (Japanese) Severity: Critical Fixlet ID: 607821 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS06-078.mspx *************************************************************** Title: MS07-036: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution - Excel 2003 (Local Install) (Japanese) Severity: Important Fixlet ID: 703604 Fixlet Link: http://www.microsoft.com/technet/security/Bulletin/MS07-036.mspx Fixlet Link: http://support.bigfix.com/cgi-bin/kbdirect.pl?id=129 Fixlet Description: Microsoft has released a security patch for Excel 2003. This critical update resolves one publicly disclosed vulnerability and two privately reported vulnerabilities in addition to other security issues identified during the course of the investigation. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-036: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution - Excel 2003 - Windows NT/2000/XP/2003 (Administrative Install) (Japanese) Severity: Important Fixlet ID: 703605 Fixlet Link: http://www.microsoft.com/technet/security/Bulletin/MS07-036.mspx Fixlet Link: http://support.bigfix.com/cgi-bin/kbdirect.pl?id=129 Fixlet Description: Microsoft has released a security patch for Excel 2003. This critical update resolves one publicly disclosed vulnerability and two privately reported vulnerabilities in addition to other security issues identified during the course of the investigation. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-036: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution - Excel 2003 (Network Install) (Japanese) Severity: Important Fixlet ID: 703606 Fixlet Link: http://www.microsoft.com/technet/security/Bulletin/MS07-036.mspx Fixlet Link: http://support.bigfix.com/cgi-bin/kbdirect.pl?id=129 Fixlet Description: Microsoft has released a security patch for Excel 2003. This critical update resolves one publicly disclosed vulnerability and two privately reported vulnerabilities in addition to other security issues identified during the course of the investigation. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-036: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution - Excel 2002 (Network/Local Install) (Japanese) Severity: Important Fixlet ID: 703607 Fixlet Link: http://www.microsoft.com/technet/security/Bulletin/MS07-036.mspx Fixlet Link: http://support.bigfix.com/cgi-bin/kbdirect.pl?id=129 Fixlet Description: Microsoft has released a security patch for Excel 2002. This update resolves several newly-discovered, privately and publicly reported vulnerabilities. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-036: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution - Excel 2002 - Windows NT/2000/XP/2003 (Administrative Install) (Japanese) Severity: Important Fixlet ID: 703609 Fixlet Link: http://www.microsoft.com/technet/security/Bulletin/MS07-036.mspx Fixlet Link: http://support.bigfix.com/cgi-bin/kbdirect.pl?id=129 Fixlet Description: Microsoft has released a security patch for Excel 2002. This update resolves several newly-discovered, privately and publicly reported vulnerabilities. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-036: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution - Excel 2007 (Japanese) Severity: Important Fixlet ID: 703611 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-036.mspx Fixlet Description: Microsoft has released a security patch for Excel 2007. This update resolves several newly-discovered, privately and publicly reported vulnerabilities. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-036: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution - Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats (Japanese) Severity: Important Fixlet ID: 703612 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-036.mspx Fixlet Description: Microsoft has released a security patch for Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats. This update resolves several newly-discovered, privately and publicly reported vulnerabilities. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-036: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution - Excel Viewer 2003 (Japanese) Severity: Important Fixlet ID: 703613 Fixlet Link: http://www.microsoft.com/technet/security/Bulletin/MS07-036.mspx Fixlet Description: Microsoft has released a security patch for Excel Viewer 2003. This update resolves several newly discovered, privately reported vulnerabilities. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-037: Vulnerability in Microsoft Office Publisher 2007 Could Allow Remote Code Execution (Japanese) Severity: Important Fixlet ID: 703701 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-037.mspx Fixlet Description: Microsoft has released a security patch for Publisher 2007. This update resolves one publicly reported vulnerability. This vulnerability could allow remote code execution if a user viewed a specially crafted Microsoft Office Publisher file. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. User interaction is required to exploit this vulnerability. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-038: Vulnerability in Windows Vista Firewall Could Allow Information Disclosure - Windows Vista (Japanese) Severity: Moderate Fixlet ID: 703801 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-038.mspx Fixlet Description: Microsoft has released a patch that resolves a privately reported vulnerability. This vulnerability could allow incoming unsolicited network traffic to access a network interface. An attacker could potentially gather information about the affected host. This security update addresses the vulnerability by modifying the Windows Vista firewall default behavior to block unsolicited traffic communicating over the Teredo interface. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-039: Vulnerability in Windows Active Directory Could Allow Remote Code Execution - Windows 2000 SP4 (Japanese) Severity: Critical Fixlet ID: 703901 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-039.mspx Fixlet Description: Microsoft has released an update that resolves a privately reported vulnerability in implementations of Active Directory on Windows 2000 Server and Windows Server 2003 that could allow remote code execution or a denial of service condition. Attacks attempting to exploit this vulnerability would most likely result in a denial of service condition. However remote code execution could be possible. On Windows Server 2003 an attacker must have valid logon credentials to exploit this vulnerability. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-039: CORRUPT PATCH - Windows 2000 SP4 (Japanese) Severity: Critical Fixlet ID: 703902 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-039.mspx *************************************************************** Title: MS07-039: Vulnerability in Windows Active Directory Could Allow Remote Code Execution - Windows Server 2003 SP1/SP2 (Japanese) Severity: Important Fixlet ID: 703903 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-039.mspx Fixlet Description: Microsoft has released an update that resolves a privately reported vulnerability in implementations of Active Directory on Windows 2000 Server and Windows Server 2003 that could allow remote code execution or a denial of service condition. Attacks attempting to exploit this vulnerability would most likely result in a denial of service condition. However remote code execution could be possible. On Windows Server 2003 an attacker must have valid logon credentials to exploit this vulnerability. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-039: CORRUPT PATCH - Windows Server 2003 SP1/SP2 (Japanese) Severity: Important Fixlet ID: 703904 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-039.mspx *************************************************************** Title: MS07-040: Vulnerabilities in .NET Framework Could Allow Remote Code Execution - .NET Framework 1.1 SP1 - Windows 2003 SP1/SP2 (Japanese) Severity: Important Fixlet ID: 704001 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/ms07-040.mspx Fixlet Description: Microsoft has released a patch that resolves three privately reported vulnerabilities. Two of these vulnerabilities could allow remote code execution on client systems with .NET Framework installed, and one could allow information disclosure on Web servers running ASP.NET. In all remote code execution cases, users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Important Note: There are known issues associated with the installation of this patch. See the Known Issues section of the security bulletin for more information. *************************************************************** Title: MS07-040: CORRUPT PATCH - .NET Framework 1.1 SP1 - Windows 2003 SP1/SP2 (Japanese) Severity: Important Fixlet ID: 704002 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/ms07-040.mspx *************************************************************** Title: MS07-040: Vulnerabilities in .NET Framework Could Allow Remote Code Execution - .NET Framework 1.0 SP3 - Windows 2000/XP/2003/Vista (Japanese) Severity: Critical Fixlet ID: 704003 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/ms07-040.mspx Fixlet Description: Microsoft has released a patch that resolves three privately reported vulnerabilities. Two of these vulnerabilities could allow remote code execution on client systems with .NET Framework installed, and one could allow information disclosure on Web servers running ASP.NET. In all remote code execution cases, users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Important Note: There are known issues associated with the installation of this patch. See the Known Issues section of the security bulletin for more information. *************************************************************** Title: MS07-040: CORRUPT PATCH - .NET Framework 1.0 SP3 - Windows 2000/XP/2003/Vista (Japanese) Severity: Critical Fixlet ID: 704004 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/ms07-040.mspx *************************************************************** Title: MS07-040: Vulnerabilities in .NET Framework Could Allow Remote Code Execution - .NET Framework 1.1 SP1 - Windows 2000/XP (Japanese) Severity: Critical Fixlet ID: 704005 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/ms07-040.mspx Fixlet Description: Microsoft has released a patch that resolves three privately reported vulnerabilities. Two of these vulnerabilities could allow remote code execution on client systems with .NET Framework installed, and one could allow information disclosure on Web servers running ASP.NET. In all remote code execution cases, users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Important Note: There are known issues associated with the installation of this patch. See the Known Issues section of the security bulletin for more information. *************************************************************** Title: MS07-040: CORRUPT PATCH - .NET Framework 1.1 SP1 - Windows 2000/XP (Japanese) Severity: Critical Fixlet ID: 704006 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/ms07-040.mspx *************************************************************** Title: MS07-040: Vulnerabilities in .NET Framework Could Allow Remote Code Execution - .NET Framework 2.0 - Windows 2000/XP/2003 (Japanese) Severity: Critical Fixlet ID: 704009 Fixlet Link: http://www.microsoft.com/technet/security/Bulletin/MS07-040.mspx Fixlet Description: Microsoft has released a patch that resolves three privately reported vulnerabilities. Two of these vulnerabilities could allow remote code execution on client systems with .NET Framework installed, and one could allow information disclosure on Web servers running ASP.NET. In all remote code execution cases, users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Important Note: There are known issues associated with the installation of this patch. See the Known Issues section of the security bulletin for more information. *************************************************************** Title: MS07-040: CORRUPT PATCH - .NET Framework 2.0 - Windows 2000/XP/2003 (Japanese) Severity: Critical Fixlet ID: 704010 Fixlet Link: http://www.microsoft.com/technet/security/Bulletin/MS07-040.mspx *************************************************************** Title: MS07-040: Vulnerabilities in .NET Framework Could Allow Remote Code Execution - .NET Framework 2.0 - Windows Vista (Japanese) Severity: Critical Fixlet ID: 704011 Fixlet Link: http://www.microsoft.com/technet/security/Bulletin/MS07-040.mspx Fixlet Description: Microsoft has released a patch that resolves three privately reported vulnerabilities. Two of these vulnerabilities could allow remote code execution on client systems with .NET Framework installed, and one could allow information disclosure on Web servers running ASP.NET. In all remote code execution cases, users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Important Note: There are known issues associated with the installation of this patch. See the Known Issues section of the security bulletin for more information. *************************************************************** Title: MS07-040: Vulnerabilities in .NET Framework Could Allow Remote Code Execution - .NET Framework 1.1 SP1 - Windows Vista (Japanese) Severity: Important Fixlet ID: 704013 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/ms07-040.mspx Fixlet Description: Microsoft has released a patch that resolves three privately reported vulnerabilities. Two of these vulnerabilities could allow remote code execution on client systems with .NET Framework installed, and one could allow information disclosure on Web servers running ASP.NET. In all remote code execution cases, users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Important Note: After running this patch, a user logon may be required to complete patch installation. Important Note: There are known issues associated with the installation of this patch. See the Known Issues section of the security bulletin for more information. *************************************************************** Title: MS07-040: CORRUPT PATCH - .NET Framework 1.1 SP1 - Windows Vista (Japanese) Severity: Important Fixlet ID: 704014 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/ms07-040.mspx *************************************************************** Title: MS07-041: Vulnerability in Microsoft Internet Information Services Could Allow Remote Code Execution - Windows XP SP2 (Japanese) Severity: Important Fixlet ID: 704101 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-041.mspx Fixlet Description: Microsoft has released an update that resolves a privately reported vulnerability. This vulnerability could allow remote code execution if an attacker sent specially crafted URL requests to a Web page hosted by Internet Information Services (IIS) 5.1 on Windows XP Professional Service Pack 2. IIS 5.1 is not part of a default install of Windows XP Professional Service Pack 2. An attacker who successfully exploited this vulnerability could take complete control of the affected system. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. Important Note: There are several known issues associated with the installation of this patch. See the Known Issues section of the security bulletin for more information. *************************************************************** Title: MS07-041: CORRUPT PATCH - Windows XP SP2 (Japanese) Severity: Important Fixlet ID: 704102 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-041.mspx