Alert Number: 092807-01
Alert Date: 09/28/07
Alert Title: Microsoft re-release of Security Bulletin MS07-042
Update-to: none
OS/Platform/Application:
Microsoft Windows Vista (all service packs and editions)**
Microsoft Windows XP (all service packs and editions)
Microsoft Windows Server 2003 (all service packs and editions)
Microsoft Windows 2000 (all service packs and editions)
Microsoft Office 2003 Service Pack 2
Microsoft Office 2007 system
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats
Microsoft Expression Web
Microsoft Office Groove Server 2007
Microsoft office SharePoint Server
Category: ALERT
Severity: HIGH
Attention: System Administrators, Desktop Support Personnel, Mozilla users
Summary: On September 27 2007 Microsoft updated its MS07-042 Security bulletin. MS07-042 was originally released on August 14 2007 as part of the monthly security program and addresses a critical vulnerability in XML Core Services that could result in remote code execution if a user views a malicious web page using Internet Explorer.
According to the vendor, the update made on September 27 "Added Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats and Microsoft Expression Web as affected products. The Bulletin has also been updated to inform customers that a potential reliability issue exists in applications that have installed Microsoft XML Core Services 4.0 on Windows Vista, which can be addressed by applying the download available in Microsoft Knowledge Base Article 941833."
Recommended Actions: Persons who manage, maintain or use affected versions of Windows are encouraged to read the update information (including any associated caveats, system requirements, etc) and (if required and appropriate) apply the upgrade immediately as per the instructions provided by the vendor.
**Vista Administrators/Users are cautioned to pay attention to the compatibility issues with XML Core Services mentioned in this update. A direct link to the knowledge base article pertaining to this issue is included at the bottom of this alert.
ITS Actions: At this time, ITS is taking no specific additional actions to address this software update release.
Resources:
Microsoft Security Bulletin MS07-042 (Updated):
http://www.microsoft.com/technet/security/bulletin/ms07-042.mspx
Microsoft Knowledge Base Article 941833 (details Vista Compatibility Issue):
http://support.microsoft.com/kb/941833/