Microsoft Tuesday released its first four patches of 2007 as part of its monthly security update cycle including three rated critical that effect Office and Windows.
Two of the patches listed as critical effect Office applications Excel and Outlook, while one is related to Windows and Internet Explorer. All of the vulnerabilities involve the ability for remote code execution.
The “critical” rating is the highest level of urgency on Microsoft’s ranking system and indicates that the vulnerability could be exploited to run malicious software on a PC with no action on the part of the user.
Microsoft patch MS07-002 covers versions of Excel in Office 2000 SP3, XP SP3 and 2003 SP2, and in Microsoft Works Suite 2004, 2005 for Windows, and 2004 and v.X versions for Macintosh.
Patch MS07-003 covers versions of Outlook in Office 200 SP3, XP SP3 and 2003 SP2. In total, the patches fix eight bugs in the Office software. None of the vulnerabilities, however, are present in the just released Office 2007.
The other critical patch, MS07-004, covers Windows 2000 SP4, XP SP2, XP Professional x64 Edition, and Windows Server 2003 and 2003 SP, Server 2003 for Itanium-based systems and Microsoft Windows Server 2003 SP1 for Itanium-based systems, and 2003 x64 Edition. The vulnerabilities are present in IE 5.01, 6 and 7.
The vulnerabilities are not present in the just released Vista operating system.
The fourth and final patch, MS07-001, is rated “important” and is in the Office 2003 Brazilian Portuguese grammar checker.
Microsoft had originally said last week that it would issue eight patches on Tuesday, but the company canceled four of the patches on Friday. One was rated “critical for Windows, while the three others addressed vulnerabilities in Windows, the Office business software suite and Visual Studio. The ratings on those vulnerabilities were “important.”
A Microsoft spokesman said that Microsoft’s advanced notification of security update releases has always included wording that the number of bulletins are subject to change until they are released.
“There are many factors that impact the release of a security update, and every vulnerability presents its own unique challenges,” the spokesman said.
He added that Microsoft is continuing to test the patches it held back from Tuesday’s scheduled release.
“Upon completion of its testing, Microsoft will take the appropriate action to protect our customers, which may include a security update through its monthly release process, depending on customer needs,” the spokesman said.
In addition to the updates issued, which are available from the Microsoft TechNet Web site, the company also released the latest version of its malicious software removal tool. The update eliminates Win32/Haxdoor and WinNT/Haxdoor.
In 2006, Microsoft on average issued nearly seven patches per month for a total of 78 security updates.
The IDG News Service contributed to this report.




