Fixlet Site - EnterpriseSecurity Current Version: 849 Published: Wed, 11 Apr 2007 01:04:48 GMT *************************************************************** Title: MS07-018: Vulnerabilities in Microsoft Content Management Server Could Allow Remote Code Execution - MCMS 2001 SP1 - Windows 2000 Severity: Critical Fixlet ID: 701801 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/ms07-018.mspx Fixlet Description: Microsoft has released an update resolving two newly discovered, privately reported vulnerabilities. An attacker who successfully exploited these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. After downloading and installing this update, affected computers will no longer be susceptible to these vulnerabilities. Important Note: This Fixlet Message will become relevant if any Microsoft Content Management Server 2001 component has been upgraded to Service Pack 1. This Fixlet Message may fail if other components have not been upgraded to Service Pack 1. In this event, upgrade all components to Service Pack 1 using the relevant Fixlet Message and reapply this Fixlet Message. *************************************************************** Title: MS07-018: Vulnerabilities in Microsoft Content Management Server Could Allow Remote Code Execution - MCMS 2002 SP2 Severity: Critical Fixlet ID: 701803 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/ms07-018.mspx Fixlet Description: Microsoft has released an update resolving two newly discovered, privately reported vulnerabilities. An attacker who successfully exploited these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. After downloading and installing this update, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-018: Vulnerabilities in Microsoft Content Management Server Could Allow Remote Code Execution - MCMS 2001 SP1 - Windows XP/2003 Severity: Critical Fixlet ID: 701805 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/ms07-018.mspx Fixlet Description: Microsoft has released an update resolving two newly discovered, privately reported vulnerabilities. An attacker who successfully exploited these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. After downloading and installing this update, affected computers will no longer be susceptible to these vulnerabilities. Important Note: On Windows XP and 2003 Server operating systems, the patch may fail to install. Please deploy the update manually if the client reports "failed" for the action. Important Note: This Fixlet Message will become relevant if any Microsoft Content Management Server 2001 component has been upgraded to Service Pack 1. This Fixlet Message may fail if other components have not been upgraded to Service Pack 1. In this event, upgrade all components to Service Pack 1 using the relevant Fixlet Message and reapply this Fixlet Message. *************************************************************** Title: MS07-019: Vulnerability in Universal Plug and Play Could Allow Remote Code Execution - Windows XP (x64) Severity: Critical Fixlet ID: 701901 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-019.mspx Fixlet Description: Microsoft has released a patch resolving a newly discovered, privately reported vulnerability. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of the affected workstation. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-019: CORRUPT PATCH - Windows XP (x64) Severity: Critical Fixlet ID: 701902 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-019.mspx *************************************************************** Title: MS07-019: Vulnerability in Universal Plug and Play Could Allow Remote Code Execution - Windows XP SP2 Severity: Critical Fixlet ID: 701903 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-019.mspx Fixlet Description: Microsoft has released a patch resolving a newly discovered, privately reported vulnerability. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of the affected workstation. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-019: CORRUPT PATCH - Windows XP SP2 Severity: Critical Fixlet ID: 701904 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-019.mspx *************************************************************** Title: MS07-020: Vulnerability in Microsoft Agent Could Allow Remote Code Execution - Windows XP/2003 (x64) Severity: Critical Fixlet ID: 702001 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-020.mspx Fixlet Description: Microsoft has released a patch resolving a newly discovered, privately reported vulnerability. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of the affected workstation. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. After downloading and installing this patch, affected computers will no longer be susceptible to this vulnerability. *************************************************************** Title: MS07-020: CORRUPT PATCH - Windows XP/2003 (x64) Severity: Critical Fixlet ID: 702002 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-020.mspx *************************************************************** Title: MS07-020: Vulnerability in Microsoft Agent Could Allow Remote Code Execution - Windows 2000 SP4 Severity: Critical Fixlet ID: 702003 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-020.mspx Fixlet Description: Microsoft has released a patch resolving a newly discovered, privately reported vulnerability. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of the affected workstation. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. After downloading and installing this patch, affected computers will no longer be susceptible to this vulnerability. *************************************************************** Title: MS07-020: CORRUPT PATCH - Windows 2000 SP4 Severity: Critical Fixlet ID: 702004 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-020.mspx *************************************************************** Title: MS07-020: Vulnerability in Microsoft Agent Could Allow Remote Code Execution - Windows XP SP2 Severity: Critical Fixlet ID: 702005 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-020.mspx Fixlet Description: Microsoft has released a patch resolving a newly discovered, privately reported vulnerability. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of the affected workstation. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. After downloading and installing this patch, affected computers will no longer be susceptible to this vulnerability. *************************************************************** Title: MS07-020: CORRUPT PATCH - Windows XP SP2 Severity: Critical Fixlet ID: 702006 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-020.mspx *************************************************************** Title: MS07-020: Vulnerability in Microsoft Agent Could Allow Remote Code Execution - Windows Server 2003 Severity: Moderate Fixlet ID: 702007 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-020.mspx Fixlet Description: Microsoft has released a patch resolving a newly discovered, privately reported vulnerability. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of the affected workstation. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. After downloading and installing this patch, affected computers will no longer be susceptible to this vulnerability. *************************************************************** Title: MS07-020: CORRUPT PATCH - Windows Server 2003 Severity: Moderate Fixlet ID: 702008 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-020.mspx *************************************************************** Title: MS07-021: Vulnerabilities in CSRSS Could Allow Remote Code Execution - Windows XP/2003 (x64) Severity: Critical Fixlet ID: 702101 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-021.mspx Fixlet Description: Microsoft has released an update that resolves several newly discovered, privately and publicly disclosed vulnerabilities. An attacker who successfully exploited the most severe of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-021: CORRUPT PATCH - Windows XP/2003 (x64) Severity: Critical Fixlet ID: 702102 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-021.mspx *************************************************************** Title: MS07-021: Vulnerabilities in CSRSS Could Allow Remote Code Execution - Windows 2000 SP4 Severity: Critical Fixlet ID: 702103 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-021.mspx Fixlet Description: Microsoft has released an update that resolves several newly discovered, privately and publicly disclosed vulnerabilities. An attacker who successfully exploited the most severe of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-021: CORRUPT PATCH - Windows 2000 SP4 Severity: Critical Fixlet ID: 702104 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-021.mspx *************************************************************** Title: MS07-021: Vulnerabilities in CSRSS Could Allow Remote Code Execution - Windows XP SP2 Severity: Critical Fixlet ID: 702105 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-021.mspx Fixlet Description: Microsoft has released an update that resolves several newly discovered, privately and publicly disclosed vulnerabilities. An attacker who successfully exploited the most severe of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-021: CORRUPT PATCH - Windows XP SP2 Severity: Critical Fixlet ID: 702106 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-021.mspx *************************************************************** Title: MS07-021: Vulnerabilities in CSRSS Could Allow Remote Code Execution - Windows Server 2003 Severity: Critical Fixlet ID: 702107 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-021.mspx Fixlet Description: Microsoft has released an update that resolves several newly discovered, privately and publicly disclosed vulnerabilities. An attacker who successfully exploited the most severe of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-021: CORRUPT PATCH - Windows Server 2003 Severity: Critical Fixlet ID: 702108 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-021.mspx *************************************************************** Title: MS07-021: Vulnerabilities in CSRSS Could Allow Remote Code Execution - Windows Vista Severity: Critical Fixlet ID: 702109 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-021.mspx Fixlet Description: Microsoft has released an update that resolves several newly discovered, privately and publicly disclosed vulnerabilities. An attacker who successfully exploited the most severe of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-021: Vulnerabilities in CSRSS Could Allow Remote Code Execution - Windows Vista (x64) Severity: Critical Fixlet ID: 702111 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-021.mspx Fixlet Description: Microsoft has released an update that resolves several newly discovered, privately and publicly disclosed vulnerabilities. An attacker who successfully exploited the most severe of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-022: Vulnerability in Windows Kernel Could Allow Elevation of Privilege - Windows Server 2003 Severity: Important Fixlet ID: 702201 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-022.mspx Fixlet Description: Microsoft has released a patch that resolves a newly discovered, privately reported vulnerability. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Microsoft recommends that customers apply the update at the earliest opportunity. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-022: CORRUPT PATCH - Windows Server 2003 Severity: Important Fixlet ID: 702202 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-022.mspx *************************************************************** Title: MS07-022: Vulnerability in Windows Kernel Could Allow Elevation of Privilege - Windows 2000 SP4 Severity: Important Fixlet ID: 702203 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-022.mspx Fixlet Description: Microsoft has released a patch that resolves a newly discovered, privately reported vulnerability. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Microsoft recommends that customers apply the update at the earliest opportunity. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-022: CORRUPT PATCH - Windows 2000 SP4 Severity: Important Fixlet ID: 702204 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-022.mspx *************************************************************** Title: MS07-022: Vulnerability in Windows Kernel Could Allow Elevation of Privilege - Windows XP SP2 Severity: Important Fixlet ID: 702205 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-022.mspx Fixlet Description: Microsoft has released a patch that resolves a newly discovered, privately reported vulnerability. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Microsoft recommends that customers apply the update at the earliest opportunity. After downloading and installing this patch, affected computers will no longer be susceptible to these vulnerabilities. *************************************************************** Title: MS07-022: CORRUPT PATCH - Windows XP SP2 Severity: Important Fixlet ID: 702206 Fixlet Link: http://www.microsoft.com/technet/security/bulletin/MS07-022.mspx