Home | Patch Tuesday: August 14, 2007

Patch Tuesday: August 14, 2007

The eEye Digital Security Research Team is dedicated to finding and educating the public about new and existing security vulnerabilities. Below is a list of resources to help you understand the scope of the vulnerabilities behind this month's patches and how to make informed decisions about best ways to proceed with patch installation.

Patch Tuesday Email Bulletin
Immediately following each Patch Tuesday's releases from Microsoft, eEye provides an email bulletin detailing the specifics of each patch's underlying vulnerability, along with information to help administrators plan for patch deployment. The email is available to subscribers of eEye's "Alert" mailing list only. Subscribers also receive timely bulletins when important network security events are unfolding, such as worms and zero-day exploits.
Subscribe Now!

Free Webinar: Vulnerability Expert Forum
As a service to the network security community, eEye's Research Team - headed by Marc Maiffret, eEye's CTO/Founder and Chief Technology Officer - conducts a Vulnerability Expert Forum web seminar during the second week of every month. This Vulnerability Expert Forum enables participants to stay current on the potential risks and remediation requirements, such as those announced Tuesday, by exploring the effect that high-risk vulnerabilities and exploits have on network environments and infrastructures.
Register Now!

Trial Downloads
Each of eEye's vulnerability management products is designed to help you better prepare your network for remediation activities resulting from Patch Tuesday.
Retina® Network Security Scanner

Retina proactively identifies known vulnerabilities, allowing security teams to remediate them before they are exploited.
Blink® Endpoint Vulnerability Prevention

For organizations where patching isn't an immediate option, Blink offers host-based intrusion prevention for total protection of systems, without the need for patching.
Iris® Network Traffic Analyzer

Iris captures network traffic and allows for the sessions to be played back in its native format, allowing security admins to identify and track certains types of traffic associated with today's flaws.

eEye Research's Zero-Day Tracker
eEye tracks a running list of archived and active zero-day vulnerabilities that have been publicly disclosed and/or used in attacks, and do not have any published vendor-supplied patch.
Zero-Day Tracker

Retina Audits

MS07-042
Microsoft XML Core Services Remote Code Execution (936227) - XML3 Core (5914)
Microsoft XML Core Services Remote Code Execution (936227) - XML5 Core (5915)
Microsoft XML Core Services Remote Code Execution (936227) - 2000/XP/2003 (5916)
Microsoft XML Core Services Remote Code Execution (936227) - XML6 Core (5917)
Microsoft XML Core Services Remote Code Execution (936227) - XML4 Core (5918)
Microsoft XML Core Services Remote Code Execution (936227) - XML4 Core x64 (5920)
Microsoft XML Core Services Remote Code Execution (936227) - XML6 Core x64 (5921)

MS07-043
Microsoft OLE Automation Remote Code Execution (921503) (5909)

MS07-044
Microsoft Excel Multiple Vulnerabilities (940965) - Excel 2000 (5902)
Microsoft Excel Multiple Vulnerabilities (940965) - Excel 2002 (5903)
Microsoft Excel Multiple Vulnerabilities (940965) - Excel 2003 (5904)
Microsoft Excel Multiple Vulnerabilities (940965) - Excel Viewer 2003 (5905)

MS07-045
Microsoft Internet Explorer Cumulative Security Update (937143) (5896)

MS07-046
Microsoft Windows GDI Remote Code Execution (938829) (5897)

MS07-047
Microsoft Windows Media Player Skin Parsing Code Execution (936782) - MP 7.1 (5898)
Microsoft Windows Media Player Skin Parsing Code Execution (936782) - MP 9 (5899)
Microsoft Windows Media Player Skin Parsing Code Execution (936782) - MP 10 (5900)
Microsoft Windows Media Player Skin Parsing Code Execution (936782) - MP 11 (5901)
Microsoft Windows Media Player Skin Parsing Code Execution (936782) - MP10 x64 (5922)

MS07-048
Microsoft Windows Gadgets Multiple Vulnerabilities (938123) - Vista (5912)
Microsoft Windows Gadgets Multiple Vulnerabilities (938123) - Vista 64-bit (5913)

MS07-049
Microsoft Virtual PC and Virtual Server Privilege Escalation (937986) - PC (5910)
Microsoft Virtual PC and Virtual Server Privilege Escalation (937986) - Server (5911)

MS07-050
Microsoft Internet Explorer VML Buffer Overrun (938127) (5908)