<< Back
CVE Number Vulnerability Product Severity Date
MS07-027 Cumulative Security Update for Internet Explorer (931768) Microsoft Windows Critical 09-05-2007

Technical Information

Brief overview of the risk:
If a user is logged on with administrative user rights, an attacker who successfully exploited the most severe of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Detailed Information on the risk:
This bulletin covers 6 remote code execution vulnerabilities in Microsoft Internet Explorer. The most critical of these is an arbitrary file overwrite vulnerability that can be easily leveraged through an ActiveX control (mdsauth.dll) that ships with Microsoft Windows Media Server. Administrators are advised to remediate this as soon as possible. The bulletin also covers a problem with an ActiveX control that ships with certain East Asian language packages that shouldn’t be instantiated in Internet Explorer. The other 4 vulnerabilities involve potentially exploitable crashes that occur when Internet Explorer encounters certain conditions. In some cases those conditions involve the combination of user interation and html which is not necessarily malformed.Further information on this exploit is available at : MS07-027

Affected Software

Microsoft Windows 2000 Service Pack 4
Microsoft Windows XP Service Pack 2
Microsoft Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2
Microsoft Windows Server 2003 Service Pack 1 and Microsoft Windows Server 2003 Service Pack 2
Microsoft Windows Server 2003 with SP1 for Itanium-based Systems and Microsoft Windows Server 2003 with SP2 for Itanium-based Systems
Microsoft Windows Server 2003 x64 Edition Service Pack 1 and Microsoft Windows Server 2003 x64 Edition Service Pack 2
Windows Vista
Windows Vista x64 Edition