February 13, 2007
Microsoft Security Bulletin: February 2007 Security Bulletin
Advisory Overview
February 13, 2007 - Qualys® Vulnerability R&D Lab has released new vulnerability checks in QualysGuard® to protect organizations against the 12 new vulnerabilities present in Microsoft Windows, Microsoft Office and other Microsoft applications that were announced today. Customers can immediately audit their networks for these and other new vulnerabilities by accessing their QualysGuard subscription.
Vulnerability Details
Microsoft has released 12 security patches to fix 20 newly discovered flaws in Microsoft Windows, Microsoft Office and other Microsoft applications.

Qualys has released the following checks for these new vulnerabilities:
Vulnerability in Step-by-Step Interactive Training Could Allow Remote Code Execution
SEVERITY: Urgent Urgent-5 5
QUALYS ID: 90379
VENDOR REFERENCE: MS07-005, 923723
CVE REFERENCE: CVE-2006- 3448
CVSS SCORES: Base 3.4/ Temporal 2.5
THREAT: A remote code execution vulnerability exists in Step-by-Step Interactive Training because of the way that Step-by-Step Interactive Training handles bookmark link files.
IMPACT: An attacker who successfully exploited this vulnerability could take complete control of an affected system. However, user interaction is required to exploit this vulnerability.
SOLUTION: Refer to Microsoft Security Bulletin MS07-005 for more information and instructions on downloading the patch that fixes this issue.

Microsoft has rated this issue as Important.

Vulnerability in Windows Shell Could Allow Elevation of Privilege
SEVERITY: Critical Critical-4 4
QUALYS ID: 90380
VENDOR REFERENCE: MS07-006, 928255
CVE REFERENCE: CVE-2007-0211
CVSS SCORES: Base 2.7/ Temporal 2
THREAT: A privilege elevation vulnerability exists in Windows Shell in the way that the operating system performs detection and registration of new hardware.
IMPACT: This vulnerability could allow an authenticated user to take complete control of the system.
SOLUTION: Refer to Microsoft Security Bulletin MS07-006 for more information and instructions on downloading the patch that fixes this issue.

Microsoft has rated this issue as Important.

Windows Image Acquisition Service Could Allow Elevation of Privilege
SEVERITY: Urgent Urgent-5 5
QUALYS ID: 90384
VENDOR REFERENCE: MS07-007, 927802
CVE REFERENCE: CVE-2007-0210
CVSS SCORES: Base 1.6/ Temporal 1.2
THREAT: A privilege elevation vulnerability exists due to an unchecked buffer in the Windows Image Acquisition service in Windows XP Service Pack 2.

Windows Image Acquisition (WIA) enables imaging programs to communicate with imaging devices such as digital cameras and scanners.
IMPACT: An attacker who successfully exploited this vulnerability could take complete control of an affected system.
SOLUTION: Refer to Microsoft Security Bulletin MS07-007 for further details on these vulnerabilities and patch instructions.

Microsoft has rated these issues as Important.

HTML Help ActiveX Control Could Allow Remote Code Execution
SEVERITY: Critical Critical-4 4
QUALYS ID: 90383
VENDOR REFERENCE: MS07-008, 928843
CVE REFERENCE: CVE-2007-0214
CVSS SCORES: Base 6.7/ Temporal 5
THREAT: Microsoft HTML Help is the standard help system for the Windows platform. HTML Help ActiveX control is a program that is used to insert help navigation and secondary window functionality into an HTML file. HTML Help ActiveX control methods do not perform sufficient parameter validation.
IMPACT: An attacker could exploit the vulnerability by constructing a specially crafted Web page that could potentially allow remote code execution if a user visited that page. An attacker who successfully exploited this vulnerability could take complete control of an affected system.
SOLUTION: Refer to Microsoft Security Bulletin MS07-008 for further details on these vulnerabilities and patch instructions.

Microsoft has rated these issues as Critical.

Vulnerability in Microsoft Data Access Components Could Allow Remote Code Execution
SEVERITY: Urgent Urgent-5 5
QUALYS ID: 90385
VENDOR REFERENCE: MS07-009, 927779
CVE REFERENCE: CVE-2006-5559
CVSS SCORES: Base 8/ Temporal 5.9
THREAT: A remote code execution vulnerability exists in the ADODB.Connection ActiveX control that is provided as part of the ActiveX Data Objects (ADO) and that is distributed in MDAC. An attacker who successfully exploited this vulnerability could take complete control of an affected system.
IMPACT: An attacker who successfully exploited this vulnerability could take complete control of an affected system.
SOLUTION: Refer to Microsoft Security Bulletin MS07-009 for more information and instructions on downloading the patch that fixes this issue.

Microsoft has rated this issue as Important.

Vulnerability in Microsoft Malware Protection Engine Could Allow Remote Code Execution
SEVERITY: Urgent Urgent-5 5
QUALYS ID: 90382
VENDOR REFERENCE: MS07-010, 932135
CVE REFERENCE: CVE-2006-5270
CVSS SCORES: Base 4.8/ Temporal 3.5
THREAT: Microsoft Malware Protection Engine is exposed to remote code execution issue because of the way that it parses Portable Document Format (PDF) files.
IMPACT: An attacker could exploit the vulnerability by constructing a specially crafted PDF File that could potentially allow remote code execution when the target computer system receives, and the Microsoft Malware Protection Engine scans, the PDF file.
SOLUTION: Refer to Microsoft Security Bulletin MS07-010 for more information and instructions on downloading the patch that fixes this issue.

Microsoft has rated this issue as Critical.

Vulnerability in Microsoft OLE Dialog Could Allow Remote Code Execution
SEVERITY: Urgent Urgent-5 5
QUALYS ID: 90378
VENDOR REFERENCE: MS07-011, 926436
CVE REFERENCE: CVE-2007-0026
CVSS SCORES: Base 8/ Temporal 5.9
THREAT: A remote code execution vulnerability exists in the OLE Dialog component provided with Microsoft Windows. An attacker could attempt to exploit this vulnerability when a user interacts with a malformed embedded OLE object within a Rich Text Format (RTF) file.
IMPACT: An attacker who successfully exploited this vulnerability could take complete control of an affected system.
SOLUTION: Refer to Microsoft Security Bulletin MS07-011 for more information and instructions on downloading the patch that fixes this issue.

Microsoft has rated this issue as Important.

Vulnerability in Microsoft MFC Could Allow Remote Code Execution
SEVERITY: Urgent Urgent-5 5
QUALYS ID: 90381
VENDOR REFERENCE: MS07-012, 924667
CVE REFERENCE: CVE-2007-0025
CVSS SCORES: Base 4.8/ Temporal 3.5
THREAT: MFC component provided with Microsoft Windows and Visual Studio is exposed to remote code execution issue. An attacker could exploit this vulnerability when a user interacts with a malformed embedded OLE object within a Rich Text Format (RTF) file.
IMPACT: If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights.
SOLUTION: Refer to Microsoft Security Bulletin MS07-012 for more information and instructions on downloading the patch that fixes this issue.

Microsoft has rated this issue as Important.

Vulnerability in Microsoft RichEdit Could Allow Remote Code Execution
SEVERITY: Urgent Urgent-5 5
QUALYS ID: 110054
VENDOR REFERENCE: MS07-013, 924667
CVE REFERENCE: CVE-2006-1311
CVSS SCORES: Base 4.1/ Temporal 3
THREAT: RichEdit components provided with Microsoft Windows and Microsoft Office are exposed to remote code execution. An attacker could exploit this vulnerability when a user interacts with a malformed embedded OLE object within a Rich Text Format (RTF) file.
IMPACT: If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights.
SOLUTION: Refer to Microsoft Security Bulletin MS07-013 for more information and instructions on downloading the patch that fixes this issue.

Microsoft has rated this issue as Important.

Microsoft Word 2000 Vulnerability Could Allow Remote Code Execution
SEVERITY: Urgent Urgent-5 5
QUALYS ID: 110052
VENDOR REFERENCE: MS07-014, 929434
CVE REFERENCE: CVE-2006-5994, CVE-2006-6456, CVE-2006-6561, CVE-2007-0208, CVE-2007-0209, CVE-2007-0515
CVSS SCORES: Base 3.4/ Temporal 2.6
THREAT: Microsoft update MS07-014 resolves several discovered vulnerabilities in Microsoft Word.

The following specific issues were reported:
  • A remote code execution vulnerability exists when Microsoft Word handles Word files with a specially crafted string.
  • A remote code execution vulnerability exists when Microsoft Word handles Word files with a specially crafted data structure.
  • A remote code execution vulnerability exists when Microsoft Word parses a file and processes an unchecked count.
  • A remote code execution vulnerability exists when Microsoft Word parses a file and processes a malformed drawing object.
  • A remote code execution vulnerability exists when Microsoft Word parses a file and processes a malformed function.
Previously this was a Zero Day vulnerability.
IMPACT: As a result, an attacker could take complete control of the target host.
SOLUTION: Refer to Microsoft Security Bulletin MS07-014 for further details on these vulnerabilities and patch instructions.

Microsoft has rated these issues as Critical.

Vulnerabilities in Microsoft Office Could Allow Remote Code Execution
SEVERITY: Urgent Urgent-5 5
QUALYS ID: 110053
VENDOR REFERENCE: MS07-015, 932554
CVE REFERENCE: CVE-2006-3877
CVSS SCORES: Base 7.2/ Temporal 4.8
THREAT: Microsoft Office is prone to a remote code execution vulnerability. This issue occurs when the application processes maliciously crafted files.
IMPACT: An attacker who successfully exploits this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights.
SOLUTION: Refer to Microsoft Security Bulletin MS07-015 for more information and instructions on downloading the patch that fixes this issue.

Microsoft has rated this issue as Important.

Cumulative Security Update for Internet Explorer
SEVERITY: Urgent Urgent-5 5
QUALYS ID: 100045
VENDOR REFERENCE: MS07-016, 928090
CVE REFERENCE: CVE-2006-4697 CVE-2007-0219 CVE-2007-0217
CVSS SCORES: Base 6.4/ Temporal 4.7
THREAT: Multiple remote code execution vulnerabilities exist in Internet Explorer.
IMPACT: An attacker who successfully exploited these vulnerabilities could take complete control of an affected system.
SOLUTION: Refer to Microsoft Security Bulletin MS07-016 for more information and instructions on downloading the patch that fixes this issue.

Microsoft has rated this issue as Critical.

This new vulnerability check is included in Qualys vulnerability signatures v1.16.77-5. Each QualysGuard account is automatically updated with the latest vulnerability signatures as they become available. To view the vulnerability signature version in your account, from the QualysGuard HOME menu, select the Account Info tab.

SELECTIVE SCAN INSTRUCTIONS USING QUALYSGUARD:

To perform a selective vulnerability scan, configure a scan profile to use the following options:

  1. Ensure access to TCP ports 135 and 139 are available.
  2. Enable Windows Authentication (specify Authentication Records).
  3. Enable the following Qualys IDs:
    • 90379
    • 90380
    • 90384
    • 90383
    • 90385
    • 90382
    • 90378
    • 90381
    • 110054
    • 110053
    • 110052
    • 100045
  4. If you would like the scan to return the Windows Hostname, also include QID 82044 and ensure access to UDP port 137 is available.
  5. If you would like to be notified if QualysGuard is unable to logon to a host (if Authentication fails), also include QID 105015.

In addition, prior to running a scan for these new vulnerabilities, you can estimate your exposure to these new threats by running the Risk Matrix Report, available from the QualysGuard HOME page.


Technical Support
For more information, customers may contact Qualys Technical Support directly at support@qualys.com or by telephone toll free at:
US: 1 866.801.6161 | EMEA: 33 1 44.17.00.41 | UK: +44 1753 872102
About QualysGuard
QualysGuard is an on-demand security audit service delivered over the web that enables organizations to effectively manage their vulnerabilities and maintain control over their network security with centralized reports, verified remedies, and full remediation workflow capabilities with trouble tickets. QualysGuard provides comprehensive reports on vulnerabilities including severity levels, time to fix estimates and impact on business, plus trend analysis on security issues. By continuously and proactively monitoring all network access points, QualysGuard dramatically reduces security managers' time researching, scanning and fixing network exposures and enables companies to eliminate network vulnerabilities before they can be exploited.

Access for QualysGuard customers: https://qualysguard.qualys.com

Free trial of QualysGuard service: http://www.qualys.com/forms/trials/qualysguard_trial/