Privacy and Legal Notice

CIAC INFORMATION BULLETIN

R-103: Vulnerability in Vector Markup Language (929969)

[Microsoft Security Bulletin MS07-004]

January 9, 2007 20:00 GMT
[REVISED 11 Jan 2007]
[REVISED 18 Jan 2007]
[REVISED 23 May 2007]

PROBLEM: A remote code execution vulnerability exists in the Vector Markup Language (VML) implementation in Microsoft Windows.
PLATFORM: Tested Software and Security Update Download Locations:
Affected Software:
• Microsoft Windows 2000 Service Pack 4
• Microsoft Windows XP Service Pack 2
• Microsoft Windows XP Professional x64 Edition
• Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1
• Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
• Microsoft Windows Server 2003 x64 Edition

Non-Affected Software:
• Windows Vista

Tested Microsoft Windows Components:
Affected Components:
• Internet Explorer 5.01 Service Pack 4 on Microsoft Windows 2000 Service Pack 4
• Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4
• Internet Explorer 7 on Microsoft Windows XP Service Pack 2
• Internet Explorer 7 on Microsoft Windows XP Professional x64 Edition
• Internet Explorer 7 on Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1
• Internet Explorer 7 on Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
• Internet Explorer 7 on Microsoft Windows Server 2003 x64 Edition

Storage Management Appliance v2.1 Software running on Storage Management Appliance I, II, III
DAMAGE: An attacker could exploit the vulnerability by constructing a specially crafted Web page or HTML e-mail that could potentially allow remote code execution if a user visited the Web page or viewed the message. An attacker who successfully exploited this vulnerability could take complete control of an affected system.
SOLUTION: Upgrade to the appropriate version.

VULNERABILITY
ASSESSMENT:
The risk is HIGH. An attacker could exploit the vulnerability by constructing a specially crafted Web page or HTML e-mail that could potentially allow remote code execution if a user visited the Web page or viewed the message. An attacker who successfully exploited this vulnerability could take complete control of an affected system.

LINKS:  
  CIAC BULLETIN: http://www.ciac.org/ciac/bulletins/r-103.shtml
  ORIGINAL BULLETIN: Microsoft Security Bulletin MS07-004 (929969)
   http://www.microsoft.com/technet/security/Bulletin/MS07-004.mspx
  ADDITIONAL LINK: Visit Hewlett-Packards Subscription Service for:
   HPSBST02184 SSRT071296 rev. 1
  CVE: CVE-2007-0024

REVISION HISTORY:
	01/11/2007 - revised to reflect changes Microsoft has made in MS07-004 where
                 they updated "Restart Requirement" update for each update to 
				 properly reflect that restarts are not required if the affected 
				 file, vgx.dll, is not in use.
	01/18/2007 - revised to add a link to Hewlett-Packards Subscription Service for 
                 HPSBST02184 SSRT071296 rev. 1 for Storage Management Appliance
                 v2.1 Software running on Storage Management Appliance I, II, III. 
	05/23/2007 - revised R-103 to reflect changes Microsoft has made in MS07-004 that
                 customers who install Windows Internet Explorer 7 on Windows Server 
				 2003 Service Pack 2 will also need to apply this security update. 
				 
				 
[***** Start Microsoft Security Bulletin MS07-004 *****]


Microsoft Security Bulletin MS07-004

Vulnerability in Vector Markup Language Could Allow Remote Code Execution (929969)

Published: January 9, 2007 | Updated: May 22, 2007

Version: 1.2

Summary

Who Should Read this Document: Customers who use Microsoft Windows

Impact of Vulnerability: Remote Code Execution

Maximum Severity Rating: Critical

Recommendation: Customers should apply the update immediately

Security Update Replacement: This bulletin replaces a prior security update. See the frequently asked questions (FAQ) section of this bulletin for the complete list.

Caveats: None

Tested Software and Security Update Download Locations:

Affected Software:

Microsoft Windows 2000 Service Pack 4

Microsoft Windows XP Service Pack 2 — Download the update

Microsoft Windows XP Professional x64 Edition — Download the update

Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1 — Download the update

Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems — Download the update

Microsoft Windows Server 2003 x64 Edition — Download the update

Non-Affected Software:

Windows Vista

Tested Microsoft Windows Components:

Affected Components:

Internet Explorer 5.01 Service Pack 4 on Microsoft Windows 2000 Service Pack 4 — Download the update

Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4 — Download the update

Internet Explorer 7 on Microsoft Windows XP Service Pack 2 — Download the update

Internet Explorer 7 on Microsoft Windows XP Professional x64 Edition — Download the update

Internet Explorer 7 on Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1 — Download the update

Internet Explorer 7 on Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems — Download the update

Internet Explorer 7 on Microsoft Windows Server 2003 x64 Edition — Download the update

The software in this list has been tested to determine whether the versions are affected. Other versions either no longer include security update support or may not be affected. To determine the support life cycle for your product and version, visit the Microsoft Support Lifecycle Web site.

Note The security updates for Microsoft Windows Server 2003, Windows Server 2003 Service Pack 1, and Windows Server 2003 x64 Edition also apply to Windows Server 2003 R2.

Top of sectionTop of section

General Information

Executive Summary

Executive Summary:

This update resolves a public vulnerability as well as additional issues discovered through internal investigations. The vulnerability is documented in the "Vulnerability Details" section of this bulletin.

If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

We recommend that customers apply the update immediately.

Severity Ratings and Vulnerability Identifiers:

Vulnerability Identifiers Impact of Vulnerability Windows 2000 Service Pack 4 Windows XP Service Pack 2 Windows Server 2003 Windows Server 2003 Service Pack 1

VML Buffer Overrun Vulnerability - CVE-2007-0024

Remote Code Execution

Critical

Critical

Critical

Moderate

This assessment is based on the types of systems that are affected by the vulnerability, their typical deployment patterns, and the effect that exploiting the vulnerability would have on them.

Note By default, Internet Explorer on Windows Server 2003 runs in a restricted mode that is known as Enhanced Security Configuration. See the FAQ section for this security update for more information about Internet Explorer Enhanced Security Configuration.

Note The severity ratings for non-x86 operating system versions map to the x86 operating systems versions as follows:

The Windows XP Professional x64 Edition severity rating is the same as the Windows Server XP Service Pack 2.

The Windows Server 2003 for Itanium-based Systems severity rating is the same as the Windows Server 2003 severity rating.

The Windows Server 2003 with SP1 for Itanium-based Systems severity rating is the same as the Windows Server 2003 Service Pack 1 severity rating.

The Windows Server 2003 x64 Edition severity rating is the same as the Windows Server 2003 Service Pack 1 severity rating.

Frequently Asked Questions (FAQ) Related to This Security Update

Vulnerability Details

VML Buffer Overrun Vulnerability - CVE-2007-0024:

A remote code execution vulnerability exists in the Vector Markup Language (VML) implementation in Microsoft Windows. An attacker could exploit the vulnerability by constructing a specially crafted Web page or HTML e-mail that could potentially allow remote code execution if a user visited the Web page or viewed the message. An attacker who successfully exploited this vulnerability could take complete control of an affected system.

Mitigating Factors for VML Buffer Overrun Vulnerability - CVE-2007-0024:
Workarounds for VML Buffer Overrun Vulnerability - CVE-2007-0024:
FAQ for VML Buffer Overrun Vulnerability - CVE-2007-0024:

Security Update Information

Affected Software:

For information about the specific security update for your affected software, click the appropriate link:

Internet Explorer 5.01 Service Pack 4 on Windows 2000 (all versions)

Internet Explorer 6 Service Pack 1 for Windows 2000 Service Pack 4 (all versions)

Windows XP Service Pack 2 (all versions)