December 12, 2006
Microsoft Security Bulletin: December 2006 Security Bulletin
Advisory Overview
December 12, 2006 – Qualys® Vulnerability R&D Lab has released six new vulnerability checks in QualysGuard® to protect organizations against the four new vulnerabilities present in Microsoft Windows that were announced today and detections for two newly available Microsoft Cumulative Security Updates. Customers can immediately audit their networks for these and other new vulnerabilities by accessing their QualysGuard subscription.
Vulnerability Details
Microsoft has released security patches to fix 6 discovered flaws in the Microsoft Windows operating system, Visual Studio 2005, Internet Explorer, and Windows Media Player.

Qualys has released the following checks for these new vulnerabilities:
Cumulative Security Update for Outlook Express
SEVERITY: Urgent Urgent-5 5
QUALYS ID: 90368
VENDOR REFERENCE: MS06-076, 923694
CVE REFERENCE: CVE ID: CVE-2006-2386
CVSS SCORES: Base 4.3/ Temporal 3.3
THREAT: A remote code execution vulnerability in a component of Outlook Express could allow an attacker who sent a Windows Address Book file to a user of an affected system to take complete control of the system.
IMPACT: If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights.
SOLUTION: Refer to Microsoft Security Bulletin MS06-076 for further details and patches.

Microsoft has rated this issue as Important.

Cumulative Security Update for Internet Explorer
SEVERITY: Urgent Urgent-5 5
QUALYS ID: 90371
VENDOR REFERENCE: MS06-072, 925454
CVE REFERENCE: CVE ID: CVE-2006-5579, CVE-2006-5581, CVE-2006-5578, CVE-2006-5577
CVSS SCORES: Base 8.0/ Temporal 5.9
THREAT: Not installing this security update allows the system to remain vulnerable to the following Internet Explorer vulnerabilities:
  • Script Error Handling Memory Corruption Vulnerability (CVE-2006-5579)
  • DHTML Script Function Memory Corruption Vulnerability (CVE-2006-5581)
  • TIF Folder Information Disclosure Vulnerability (CVE-2006-5578)
  • TIF Folder Information Disclosure Vulnerability (CVE-2006-5577)
IMPACT: Successful exploitation of these issues allows a total compromise of the affected system.
SOLUTION: Refer to Microsoft Security Bulletin MS06-072 for further details and patches.

Microsoft has rated this issue as Critical.

Visual Studio 2005 Could Allow Remote Code Execution
SEVERITY: Critical Critical-4 4
QUALYS ID: 115448
VENDOR REFERENCE: MS06-073, 925674
CVE REFERENCE: CVE ID: CVE-2006-4704
CVSS SCORES: Base 3.4 / Temporal 2.7
THREAT: A remote code execution vulnerability exists in the WMI Object Broker control that the WMI Wizard uses in Visual Studio 2005. An attacker could exploit the vulnerability by constructing a specially crafted Web page that could potentially allow remote code execution if a user viewed the Web page. An attacker who successfully exploited this vulnerability could take complete control of an affected system.
IMPACT: If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system.
SOLUTION: Refer to Microsoft Security Bulletin MS06-073 for further details and patches.

Microsoft has rated this issue as Critical.

Vulnerability in Windows Media Format Could Allow Remote Code Execution
SEVERITY: Critical Critical-4 4
QUALYS ID: 90367
VENDOR REFERENCE: MS06-078, 923689
CVE REFERENCE: CVE ID: CVE-2006-6134
CVSS SCORES: Base 4.4/ Temporal 3.3
THREAT: Windows Media Player is prone to a denial of service issue because it fails to properly handle overly long playlist file names. An attacker can exploit this issue by tricking an unsuspecting user into opening a malicious ASX playlist file containing an overly long filename. As a result, the Windows Media Player application will stop responding, effectively denying service to legitimate users of the application.
IMPACT: An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
SOLUTION: Refer to Microsoft Security Bulletin MS06-078 for further details and patches.

Microsoft has rated this issue as Critical.

SNMP Could Allow Remote Code Execution
SEVERITY: Critical Critical-4 4
QUALYS ID: 90372
VENDOR REFERENCE: MS06-074, 926247
CVE REFERENCE: CVE ID: CVE-2006-5583
CVSS SCORES: Base 4.7/ Temporal 3.5
THREAT: The Simple Network Management Protocol (SNMP) is an application layer protocol that facilitates the exchange of management information between network devices. The target Microsoft Windows machine is running a version of SNMP which is vulnerable to a memory corruption issue.
IMPACT: An attacker who successfully exploited this vulnerability could take complete control of an affected system.
SOLUTION: Refer to Microsoft Security Bulletin MS06-074 for further details and patches.

Microsoft has rated this issue as Important.

Vulnerability in Remote Installation Service Could Allow Remote Code Execution
SEVERITY: Critical Critical-4 4
QUALYS ID: 90370
VENDOR REFERENCE: MS06-077, 926121
CVE REFERENCE: CVE ID: CVE-2006-5584
CVSS SCORES: Base 3.4/ Temporal 2.5
THREAT: The Remote Installation Service enables a TFTP service on the server which by default could allow an anonymous user to potentially overwrite existing operating system files or upload a specially crafted file.
IMPACT: As a result, a remote attacker can gain complete control of a vulnerable machine.
SOLUTION: Refer to Microsoft Security Bulletin MS06-077 for further details and patches.

Microsoft has rated this vulnerability as Important.

Vulnerability in Windows Could Allow Elevation of Privilege
SEVERITY: Serious Serious-3 3
QUALYS ID: 90369
VENDOR REFERENCE: MS06-075, 926255
CVE REFERENCE: CVE ID: CVE-2006-5585
CVSS SCORES: Base 2.2/ Temporal 1.6
THREAT: A privilege elevation vulnerability exists in the way that Microsoft Windows starts applications with specially crafted file manifests. Microsoft has rated this vulnerability as Important.
IMPACT: This vulnerability could allow a logged on user to take complete control of the system.
SOLUTION: Refer to Microsoft Security Bulletin MS06-075 for further details and patches.

Microsoft has rated this issue as Important.

This new vulnerability check is included in Qualys vulnerability signatures v1.16.28-3. Each QualysGuard account is automatically updated with the latest vulnerability signatures as they become available. To view the vulnerability signature version in your account, from the QualysGuard HOME menu, select the Account Info tab.

SELECTIVE SCAN INSTRUCTIONS USING QUALYSGUARD:

To perform a selective vulnerability scan, configure a scan profile to use the following options:

  1. Ensure access to TCP ports 135 and 139 are available.
  2. Enable Windows Authentication (specify Authentication Records).
  3. Enable the following Qualys IDs:
    • 90368
    • 90367
    • 90371
    • 90370
    • 90369
    • 90372
    • 115448
  4. If you would like the scan to return the Windows Hostname, also include QID 82044 and ensure access to UDP port 137 is available.
  5. If you would like to be notified if QualysGuard is unable to logon to a host (if Authentication fails), also include QID 105015.

In addition, prior to running a scan for these new vulnerabilities, you can estimate your exposure to these new threats by running the Risk Matrix Report, available from the QualysGuard HOME page.


Technical Support
For more information, customers may contact Qualys Technical Support directly at support@qualys.com or by telephone toll free at:
US: 1 866.801.6161 | EMEA: 33 1 44.17.00.41 | UK: +44 1753 872102
About QualysGuard
QualysGuard is an on-demand security audit service delivered over the web that enables organizations to effectively manage their vulnerabilities and maintain control over their network security with centralized reports, verified remedies, and full remediation workflow capabilities with trouble tickets. QualysGuard provides comprehensive reports on vulnerabilities including severity levels, time to fix estimates and impact on business, plus trend analysis on security issues. By continuously and proactively monitoring all network access points, QualysGuard dramatically reduces security managers' time researching, scanning and fixing network exposures and enables companies to eliminate network vulnerabilities before they can be exploited.

Access for QualysGuard customers: https://qualysguard.qualys.com

Free trial of QualysGuard service: http://www.qualys.com/forms/trials/qualysguard_trial/