Microsoft XML Core Services SubstringData Integer Overflow Vulnerability
BID:25301
Info
Microsoft XML Core Services SubstringData Integer Overflow Vulnerability
| Bugtraq ID: | 25301 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-2223 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 14 2007 12:00AM |
| Updated: | Jun 24 2008 11:01PM |
| Credit: | Anonymous researchers working with the VeriSign iDefence VCP, and the Zero Day Initiative reported this issue. |
| Vulnerable: |
Microsoft XML Core Services 6.0 Microsoft XML Core Services 5.0 SP1 Microsoft XML Core Services 5.0 Microsoft XML Core Services 4.0 Microsoft XML Core Services 3.0 SP7 Microsoft XML Core Services 3.0 SP5 Microsoft XML Core Services 3.0 SP4 Microsoft XML Core Services 3.0 SP3 Microsoft XML Core Services 3.0 Microsoft Word Viewer 2003 0 Microsoft Windows XP Tablet PC Edition SP3 Microsoft Windows XP Tablet PC Edition SP2 Microsoft Windows XP Tablet PC Edition SP1 Microsoft Windows XP Tablet PC Edition Microsoft Windows XP Professional x64 Edition SP2 Microsoft Windows XP Professional x64 Edition Microsoft Windows XP Professional SP3 Microsoft Windows XP Professional SP2 Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Media Center Edition SP3 Microsoft Windows XP Media Center Edition SP2 Microsoft Windows XP Media Center Edition SP1 Microsoft Windows XP Media Center Edition Microsoft Windows XP Home SP3 Microsoft Windows XP Home SP2 Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows XP Gold 0 Microsoft Windows XP 64-bit Edition Version 2003 SP1 Microsoft Windows XP 64-bit Edition Version 2003 Microsoft Windows XP 64-bit Edition SP1 Microsoft Windows XP 64-bit Edition Microsoft Windows XP 0 Microsoft Windows Vista x64 Edition 0 Microsoft Windows Vista Home Premium 64-bit edition SP1 Microsoft Windows Vista Home Basic 64-bit edition SP1 Microsoft Windows Vista Enterprise 64-bit edition SP1 Microsoft Windows Vista Business 64-bit edition SP1 Microsoft Windows Vista Ultimate Microsoft Windows Vista SP1 Microsoft Windows Vista Home Premium SP1 Microsoft Windows Vista Home Premium Microsoft Windows Vista Home Basic SP1 Microsoft Windows Vista Home Basic Microsoft Windows Vista Enterprise SP1 Microsoft Windows Vista Enterprise Microsoft Windows Vista Business SP1 Microsoft Windows Vista Business Microsoft Windows Vista 0 Microsoft Windows Server 2008 Standard Edition 0 Microsoft Windows Server 2008 for x64-based Systems 0 Microsoft Windows Server 2008 for Itanium-based Systems 0 Microsoft Windows Server 2008 for 32-bit Systems 0 Microsoft Windows Server 2008 Enterprise Edition 0 Microsoft Windows Server 2008 Datacenter Edition 0 Microsoft Windows Server 2003 x64 SP2 Microsoft Windows Server 2003 x64 SP1 Microsoft Windows Server 2003 Web Edition SP2 Microsoft Windows Server 2003 Web Edition SP1 Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Standard Edition SP2 Microsoft Windows Server 2003 Standard Edition SP1 Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Itanium SP2 Microsoft Windows Server 2003 Itanium SP1 Microsoft Windows Server 2003 Itanium 0 Microsoft Windows Server 2003 Enterprise x64 Edition SP2 Microsoft Windows Server 2003 Enterprise x64 Edition Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Beta 1 Microsoft Windows Server 2003 Enterprise Edition Itanium 0 Microsoft Windows Server 2003 Enterprise Edition SP1 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter x64 Edition Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Beta 1 Microsoft Windows Server 2003 Datacenter Edition Itanium 0 Microsoft Windows Server 2003 Datacenter Edition SP1 Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows Server 2003 SP2 Microsoft Windows Server 2003 SP1 Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server Microsoft SharePoint Server 2007 0 Microsoft Office Compatibility Pack 2007 0 Microsoft Office 2007 0 Microsoft Office 2003 SP2 Microsoft Office 2003 SP1 Microsoft Office 2003 0 Microsoft Groove Server 2007 0 Microsoft Expression Web 0 HP Storage Management Appliance III HP Storage Management Appliance II HP Storage Management Appliance I HP Storage Management Appliance 2.1 HP Storage Management Appliance 2.1 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya CIE 1.0.2 Avaya CIE 1.0 |
| Not Vulnerable: | |
Discussion
Microsoft XML Core Services SubstringData Integer Overflow Vulnerability
Microsoft XML Core Services is prone to an integer-overflow vulnerability because the application fails to ensure that integer values are not overrun.
Attackers can exploit this issue by enticing unsuspecting users to view malicious web content. Specially crafted scripts could issue requests to MSXML that trigger memory corruption.
Successfully exploiting this issue allows remote attackers to corrupt heap memory and execute arbitrary code in the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Microsoft XML Core Services is prone to an integer-overflow vulnerability because the application fails to ensure that integer values are not overrun.
Attackers can exploit this issue by enticing unsuspecting users to view malicious web content. Specially crafted scripts could issue requests to MSXML that trigger memory corruption.
Successfully exploiting this issue allows remote attackers to corrupt heap memory and execute arbitrary code in the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Microsoft XML Core Services SubstringData Integer Overflow Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
Microsoft XML Core Services SubstringData Integer Overflow Vulnerability
Solution:
Microsoft has released an advisory and fixes to address this issue. Please see the references for more information.
Microsoft Windows Server 2003 Datacenter Edition SP1
Microsoft Windows XP Media Center Edition SP2
Microsoft Windows Server 2003 Itanium SP1
Microsoft Windows Server 2003 Itanium 0
Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Beta 1
Microsoft Windows Vista x64 Edition 0
Microsoft Windows XP Tablet PC Edition SP2
Microsoft Word Viewer 2003 0
Microsoft XML Core Services 6.0
Microsoft Office 2003 SP2
Microsoft Windows Server 2003 Enterprise Edition Itanium 0
Microsoft Windows Server 2003 Web Edition SP2
Microsoft Windows Vista Home Premium
Microsoft Windows Server 2003 Standard Edition SP1
Microsoft Windows Server 2003 x64 SP1
Microsoft Windows Vista Enterprise
Microsoft Windows XP Professional x64 Edition SP2
Microsoft Windows Server 2003 Standard Edition
Microsoft Windows Vista 0
Microsoft Windows Vista Business
Microsoft Windows Server 2003 x64 SP2
Microsoft Windows Server 2003 Enterprise x64 Edition
Microsoft Windows Server 2003 Datacenter Edition Itanium 0
Microsoft Windows Server 2003 Datacenter x64 Edition
Microsoft Windows Server 2003 Enterprise Edition SP1
Microsoft Office 2003 0
Microsoft Windows Vista Home Basic
Microsoft Windows Server 2003 Datacenter Edition
Microsoft XML Core Services 4.0
Microsoft Windows 2000 Advanced Server SP4
Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Beta 1
Microsoft Windows Vista Ultimate
Microsoft Windows Server 2003 SP2
Microsoft Office Compatibility Pack 2007 0
Microsoft Windows Server 2003 Enterprise Edition
Microsoft Windows Server 2003 Standard Edition SP2
Microsoft Windows XP Home SP2
Microsoft Windows 2000 Datacenter Server SP4
Microsoft Windows Server 2003 SP1
Microsoft Windows Server 2003 Itanium SP2
Microsoft Windows Server 2003 Web Edition
Solution:
Microsoft has released an advisory and fixes to address this issue. Please see the references for more information.
Microsoft Windows Server 2003 Datacenter Edition SP1
-
Microsoft Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)
http://www.microsoft.com/downloads/details.aspx?FamilyId=021E12F5-CB46 -43DF-A2B8-185639BA2807 -
Microsoft Security Update for Microsoft XML Core Services 6.0 and Service Pack 1 (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=70C92E77-9E5A -41B1-A9D2-64443913C976 -
Microsoft Security Update for Windows Server 2003 (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=12618ad0-aefd -4c9a-a769-4b14a7603d6e
Microsoft Windows XP Media Center Edition SP2
-
Microsoft Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)
http://www.microsoft.com/downloads/details.aspx?FamilyId=021E12F5-CB46 -43DF-A2B8-185639BA2807 -
Microsoft Security Update for Microsoft XML Core Services 6.0 and Service Pack 1 (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=70C92E77-9E5A -41B1-A9D2-64443913C976 -
Microsoft Security Update for Windows XP (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=dea6a48f-fb00 -43f3-a374-3220f9759c2d
Microsoft Windows Server 2003 Itanium SP1
-
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=b0285dd7-bf66 -4226-9948-26e8aae99046
Microsoft Windows Server 2003 Itanium 0
-
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=b0285dd7-bf66 -4226-9948-26e8aae99046
Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Beta 1
-
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=b0285dd7-bf66 -4226-9948-26e8aae99046
Microsoft Windows Vista x64 Edition 0
-
Microsoft Security Update for Windows Vista for x64-based Systems (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=928da3d2-b0b9 -447a-b37a-4350497fe563 -
Microsoft Security Update for Windows Vista for x64-based Systems (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=0a465d77-a737 -4d26-82a1-570f9c788a8a
Microsoft Windows XP Tablet PC Edition SP2
-
Microsoft Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)
http://www.microsoft.com/downloads/details.aspx?FamilyId=021E12F5-CB46 -43DF-A2B8-185639BA2807 -
Microsoft Security Update for Microsoft XML Core Services 6.0 and Service Pack 1 (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=70C92E77-9E5A -41B1-A9D2-64443913C976 -
Microsoft Security Update for Windows XP (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=dea6a48f-fb00 -43f3-a374-3220f9759c2d
Microsoft Word Viewer 2003 0
-
Microsoft Security Update for Office 2003 (KB936048)
http://www.microsoft.com/downloads/details.aspx?FamilyId=A339CB7B-E08A -47F8-AC0B-DF449191424A
Microsoft XML Core Services 6.0
-
Microsoft Security Update for Microsoft XML Core Services 6.0 and Service Pack 1 (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=70C92E77-9E5A -41B1-A9D2-64443913C976
Microsoft Office 2003 SP2
-
Microsoft Security Update for Office 2003 (KB936048)
http://www.microsoft.com/downloads/details.aspx?FamilyId=A339CB7B-E08A -47F8-AC0B-DF449191424A
Microsoft Windows Server 2003 Enterprise Edition Itanium 0
-
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=b0285dd7-bf66 -4226-9948-26e8aae99046
Microsoft Windows Server 2003 Web Edition SP2
-
Microsoft Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)
http://www.microsoft.com/downloads/details.aspx?FamilyId=021E12F5-CB46 -43DF-A2B8-185639BA2807 -
Microsoft Security Update for Microsoft XML Core Services 6.0 and Service Pack 1 (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=70C92E77-9E5A -41B1-A9D2-64443913C976 -
Microsoft Security Update for Windows Server 2003 (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=12618ad0-aefd -4c9a-a769-4b14a7603d6e
Microsoft Windows Vista Home Premium
-
Microsoft Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)
http://www.microsoft.com/downloads/details.aspx?FamilyId=021E12F5-CB46 -43DF-A2B8-185639BA2807 -
Microsoft Security Update for Windows Vista (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=14270529-3ae5 -43bf-a471-722ab010d81e -
Microsoft Security Update for Windows Vista (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c734d7de-5d87 -4904-81c3-714db2cb8b0d
Microsoft Windows Server 2003 Standard Edition SP1
-
Microsoft Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)
http://www.microsoft.com/downloads/details.aspx?FamilyId=021E12F5-CB46 -43DF-A2B8-185639BA2807 -
Microsoft Security Update for Microsoft XML Core Services 6.0 and Service Pack 1 (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=70C92E77-9E5A -41B1-A9D2-64443913C976 -
Microsoft Security Update for Windows Server 2003 (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=12618ad0-aefd -4c9a-a769-4b14a7603d6e
Microsoft Windows Server 2003 x64 SP1
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=61bf00a9-aeea -431a-86d3-526a4a373bb7 -
Microsoft Security Update for Windows XP x64 Edition (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=b8862ca9-1203 -4056-a257-29271838ac0d
Microsoft Windows Vista Enterprise
-
Microsoft Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)
http://www.microsoft.com/downloads/details.aspx?FamilyId=021E12F5-CB46 -43DF-A2B8-185639BA2807 -
Microsoft Security Update for Windows Vista (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=14270529-3ae5 -43bf-a471-722ab010d81e -
Microsoft Security Update for Windows Vista (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c734d7de-5d87 -4904-81c3-714db2cb8b0d
Microsoft Windows XP Professional x64 Edition SP2
-
Microsoft Security Update for Windows XP x64 Edition (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=b8862ca9-1203 -4056-a257-29271838ac0d
Microsoft Windows Server 2003 Standard Edition
-
Microsoft Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)
http://www.microsoft.com/downloads/details.aspx?FamilyId=021E12F5-CB46 -43DF-A2B8-185639BA2807 -
Microsoft Security Update for Microsoft XML Core Services 6.0 and Service Pack 1 (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=70C92E77-9E5A -41B1-A9D2-64443913C976 -
Microsoft Security Update for Windows Server 2003 (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=12618ad0-aefd -4c9a-a769-4b14a7603d6e
Microsoft Windows Vista 0
-
Microsoft Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)
http://www.microsoft.com/downloads/details.aspx?FamilyId=021E12F5-CB46 -43DF-A2B8-185639BA2807 -
Microsoft Security Update for Windows Vista (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=14270529-3ae5 -43bf-a471-722ab010d81e -
Microsoft Security Update for Windows Vista (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c734d7de-5d87 -4904-81c3-714db2cb8b0d
Microsoft Windows Vista Business
-
Microsoft Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)
http://www.microsoft.com/downloads/details.aspx?FamilyId=021E12F5-CB46 -43DF-A2B8-185639BA2807 -
Microsoft Security Update for Windows Vista (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=14270529-3ae5 -43bf-a471-722ab010d81e -
Microsoft Security Update for Windows Vista (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c734d7de-5d87 -4904-81c3-714db2cb8b0d
Microsoft Windows Server 2003 x64 SP2
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=61bf00a9-aeea -431a-86d3-526a4a373bb7 -
Microsoft Security Update for Windows XP x64 Edition (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=b8862ca9-1203 -4056-a257-29271838ac0d
Microsoft Windows Server 2003 Enterprise x64 Edition
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=61bf00a9-aeea -431a-86d3-526a4a373bb7 -
Microsoft Security Update for Windows XP x64 Edition (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=b8862ca9-1203 -4056-a257-29271838ac0d
Microsoft Windows Server 2003 Datacenter Edition Itanium 0
-
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=b0285dd7-bf66 -4226-9948-26e8aae99046
Microsoft Windows Server 2003 Datacenter x64 Edition
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=61bf00a9-aeea -431a-86d3-526a4a373bb7 -
Microsoft Security Update for Windows XP x64 Edition (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=b8862ca9-1203 -4056-a257-29271838ac0d
Microsoft Windows Server 2003 Enterprise Edition SP1
-
Microsoft Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)
http://www.microsoft.com/downloads/details.aspx?FamilyId=021E12F5-CB46 -43DF-A2B8-185639BA2807 -
Microsoft Security Update for Microsoft XML Core Services 6.0 and Service Pack 1 (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=70C92E77-9E5A -41B1-A9D2-64443913C976 -
Microsoft Security Update for Windows Server 2003 (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=12618ad0-aefd -4c9a-a769-4b14a7603d6e
Microsoft Office 2003 0
-
Microsoft Security Update for Office 2003 (KB936048)
http://www.microsoft.com/downloads/details.aspx?FamilyId=A339CB7B-E08A -47F8-AC0B-DF449191424A
Microsoft Windows Vista Home Basic
-
Microsoft Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)
http://www.microsoft.com/downloads/details.aspx?FamilyId=021E12F5-CB46 -43DF-A2B8-185639BA2807 -
Microsoft Security Update for Windows Vista (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=14270529-3ae5 -43bf-a471-722ab010d81e -
Microsoft Security Update for Windows Vista (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c734d7de-5d87 -4904-81c3-714db2cb8b0d
Microsoft Windows Server 2003 Datacenter Edition
-
Microsoft Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)
http://www.microsoft.com/downloads/details.aspx?FamilyId=021E12F5-CB46 -43DF-A2B8-185639BA2807 -
Microsoft Security Update for Microsoft XML Core Services 6.0 and Service Pack 1 (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=70C92E77-9E5A -41B1-A9D2-64443913C976 -
Microsoft Security Update for Windows Server 2003 (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=12618ad0-aefd -4c9a-a769-4b14a7603d6e
Microsoft XML Core Services 4.0
-
Microsoft Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)
http://www.microsoft.com/downloads/details.aspx?FamilyId=021E12F5-CB46 -43DF-A2B8-185639BA2807
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)
http://www.microsoft.com/downloads/details.aspx?FamilyId=021E12F5-CB46 -43DF-A2B8-185639BA2807 -
Microsoft Security Update for Microsoft XML Core Services 6.0 and Service Pack 1 (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=70C92E77-9E5A -41B1-A9D2-64443913C976 -
Microsoft Security Update for Windows 2000 (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=245214ea-76f9 -4755-8a14-a74232e20c1c
Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Beta 1
-
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=b0285dd7-bf66 -4226-9948-26e8aae99046
Microsoft Windows Vista Ultimate
-
Microsoft Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)
http://www.microsoft.com/downloads/details.aspx?FamilyId=021E12F5-CB46 -43DF-A2B8-185639BA2807 -
Microsoft Security Update for Windows Vista (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=14270529-3ae5 -43bf-a471-722ab010d81e -
Microsoft Security Update for Windows Vista (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c734d7de-5d87 -4904-81c3-714db2cb8b0d
Microsoft Windows Server 2003 SP2
-
Microsoft Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)
http://www.microsoft.com/downloads/details.aspx?FamilyId=021E12F5-CB46 -43DF-A2B8-185639BA2807 -
Microsoft Security Update for Microsoft XML Core Services 6.0 and Service Pack 1 (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=70C92E77-9E5A -41B1-A9D2-64443913C976 -
Microsoft Security Update for Windows Server 2003 (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=12618ad0-aefd -4c9a-a769-4b14a7603d6e
Microsoft Office Compatibility Pack 2007 0
-
Microsoft Security Update for the 2007 Microsoft Office System (KB936960)
http://www.microsoft.com/downloads/details.aspx?FamilyId=7A97478A-832C -4A6B-B074-0E18B1E4ED33
Microsoft Windows Server 2003 Enterprise Edition
-
Microsoft Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)
http://www.microsoft.com/downloads/details.aspx?FamilyId=021E12F5-CB46 -43DF-A2B8-185639BA2807 -
Microsoft Security Update for Microsoft XML Core Services 6.0 and Service Pack 1 (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=70C92E77-9E5A -41B1-A9D2-64443913C976 -
Microsoft Security Update for Windows Server 2003 (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=12618ad0-aefd -4c9a-a769-4b14a7603d6e
Microsoft Windows Server 2003 Standard Edition SP2
-
Microsoft Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)
http://www.microsoft.com/downloads/details.aspx?FamilyId=021E12F5-CB46 -43DF-A2B8-185639BA2807 -
Microsoft Security Update for Microsoft XML Core Services 6.0 and Service Pack 1 (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=70C92E77-9E5A -41B1-A9D2-64443913C976 -
Microsoft Security Update for Windows Server 2003 (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=12618ad0-aefd -4c9a-a769-4b14a7603d6e
Microsoft Windows XP Home SP2
-
Microsoft Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)
http://www.microsoft.com/downloads/details.aspx?FamilyId=021E12F5-CB46 -43DF-A2B8-185639BA2807 -
Microsoft Security Update for Microsoft XML Core Services 6.0 and Service Pack 1 (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=70C92E77-9E5A -41B1-A9D2-64443913C976 -
Microsoft Security Update for Windows XP (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=dea6a48f-fb00 -43f3-a374-3220f9759c2d
Microsoft Windows 2000 Datacenter Server SP4
-
Microsoft Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)
http://www.microsoft.com/downloads/details.aspx?FamilyId=021E12F5-CB46 -43DF-A2B8-185639BA2807 -
Microsoft Security Update for Microsoft XML Core Services 6.0 and Service Pack 1 (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=70C92E77-9E5A -41B1-A9D2-64443913C976 -
Microsoft Security Update for Windows 2000 (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=245214ea-76f9 -4755-8a14-a74232e20c1c
Microsoft Windows Server 2003 SP1
-
Microsoft Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)
http://www.microsoft.com/downloads/details.aspx?FamilyId=021E12F5-CB46 -43DF-A2B8-185639BA2807 -
Microsoft Security Update for Microsoft XML Core Services 6.0 and Service Pack 1 (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=70C92E77-9E5A -41B1-A9D2-64443913C976 -
Microsoft Security Update for Windows Server 2003 (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=12618ad0-aefd -4c9a-a769-4b14a7603d6e
Microsoft Windows Server 2003 Itanium SP2
-
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=b0285dd7-bf66 -4226-9948-26e8aae99046
Microsoft Windows Server 2003 Web Edition
-
Microsoft Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)
http://www.microsoft.com/downloads/details.aspx?FamilyId=021E12F5-CB46 -43DF-A2B8-185639BA2807 -
Microsoft Security Update for Microsoft XML Core Services 6.0 and Service Pack 1 (KB933579)
http://www.microsoft.com/downloads/details.aspx?FamilyId=70C92E77-9E5A -41B1-A9D2-64443913C976 -
Microsoft Security Update for Windows Server 2003 (KB936021)
http://www.microsoft.com/downloads/details.aspx?FamilyId=12618ad0-aefd -4c9a-a769-4b14a7603d6e
References
Microsoft XML Core Services SubstringData Integer Overflow Vulnerability
References:
References:
- Microsoft XML Resource Site (Microsoft)
- iDefense Security Advisory 08.14.07: Microsoft XML Core Services XMLDOM Memory C (iDefense Labs
) - MS07-042 XMLDOM substringData() PoC ([email protected])
- ZDI-07-048: Microsoft Internet Explorer substringData Heap Overflow Vulnerabilit ([email protected])
- ASA-2007-356 MS07-042 Vulnerability in Microsoft XML Core Services Could Allow R (Avaya)
- Microsoft Security Bulletin MS07-042 (Microsoft)
- ZDI-07-048: Microsoft Internet Explorer substringData() Heap Overflow Vulnerabil (Zero Day Initiative)