********************************************************************
Title: Microsoft Security Bulletin Summary for July 2007
Issued: July 10, 2007
Version Number: 1.0
********************************************************************
This bulletin summary lists security bulletins released for July 2007.
The full version of the Microsoft Security Bulletin Summary for July
2007 can be found at
http://www.microsoft.com/technet/security/bulletin/MS07-jul.mspxWith the release of the bulletins for July 2007, this bulletin summary replaces the bulletin advance notification originally issued July 5, 2007. For more information about the bulletin advance notification service, see
http://www.microsoft.com/technet/security/Bulletin/advance.mspx.To receive automatic notifications whenever Microsoft Security Bulletins are issued, subscribe to Microsoft Technical Security Notifications on
http://www.microsoft.com/technet/security/bulletin/notify.mspx.Microsoft is hosting a webcast to address customer questions on these bulletins on Wednesday, July 11, 2007, at 11:00 AM Pacific Time (US & Canada). Register for the July Security Bulletin Webcast at
http://www.microsoft.com/technet/security/bulletin/summary.mspx.After this date, this webcast is available on-demand.
Microsoft also provides information to help customers prioritize monthly security updates with any non-security, high-priority updates that are being released on the same day as the monthly security updates. Please see the section, Other Information.
Bulletin Information
====================
The security bulletins for this month are as follows, in order of
severity:
Critical Security Bulletins
===========================
MS07-036 - Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (936542)
Affected Software:
- Excel 2000 Service Pack 3
- Excel 2003 Service Pack 2
- Excel 2003 Viewer
- Excel 2007
- Office Compatibility Pack for Word, Excel,
and PowerPoint 2007 File Formats
- Impact: Remote Code Execution
- Version Number: 1.0
MS07-039 - Vulnerability in Windows Active Directory Could Allow Remote Code Execution (926122)
Affected Software:
- Windows 2000 Server Service Pack 4
- Windows Server 2003 Service Pack 1
- Windows Server 2003 Service Pack 2
- Windows Server 2003 with SP1 for Itanium-based Systems
- Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Server 2003 x64 Edition
- Windows Server 2003 x64 Edition Service Pack 2
- Impact: Remote Code Execution
- Version Number: 1.0
MS07-040 - Vulnerabilities in .NET Framework Could Allow Remote Code Execution (931212)
Affected Software:
- Windows 2000 Service Pack 4
- Windows XP Service Pack 2
- Windows XP Professional x64 Edition
- Windows XP Professional x64 Edition Service Pack 2
- Windows Server 2003 Service Pack 1
- Windows Server 2003 Service Pack 2
- Windows Server 2003 x64 Edition
- Windows Server 2003 x64 Edition Service Pack 2
- Windows Server 2003 with SP1 for Itanium-based Systems
- Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Vista
- Windows Vista x64
- Impact: Remote Code Execution
- Version Number: 1.0
Important Security Bulletins
============================