July '10 Patch Tuesday Detailed
Article by George Norman
On 14 Jul 2010
Redmond-based software developer Microsoft, as part of the Patch Tuesday program, releases updates for its products every second Tuesday of the month. Yesterday, the 13th of July, was the second Tuesday of the month. So Microsoft rolled out 4 security bulletins that plugged a total of 5 security holes which plagued the Windows operating system and the Microsoft office productivity suite.

Until now, all we knew about these security bulletins was this: 2 affect the Windows operating system and the other 2 affect the Microsoft Office productivity suite. Out of the 2 bulletins that affect Windows, one has received the maximum severity rating – critical. The other bulletin has been rated as important. Both security bulletins that affect the Office productivity suite have been rated as critical.

Advertising

Now that the 4 bulletins have been rolled out to the general public, Microsoft has shared a few more details about them. Here are those details:

Title: MS10-042 Vulnerability in Help and Support Center Could Allow Remote Code Execution
Rating: Critical (remote code execution; actively exploited in the wild)
Description: a publicly disclosed vulnerability in the Windows Help and Support Center feature that is delivered with supported editions of Windows XP and Windows Server 2003. This vulnerability could allow remote code execution if a user views a specially crafted Web page using a Web browser or clicks a specially crafted link in an e-mail message. The vulnerability cannot be exploited automatically through e-mail.
Affected software: Microsoft Windows
- Microsoft Windows Server 2003 Service Pack 2
- Microsoft Windows Server 2003 x64 Edition Service Pack 2
- Microsoft Windows XP Service Pack 2
- Microsoft Windows XP Service Pack 3
- Windows Server 2003 with SP2 for Itanium-based Systems
- Windows XP Professional x64 Edition Service Pack 2

Title: MS10-043 Vulnerability in Canonical Display Driver Could Allow Remote Code Execution
Rating: Critical (remote code execution, no known exploits)
Description: a publicly disclosed vulnerability in the Canonical Display Driver (cdd.dll). Although it is possible that the vulnerability could allow code execution, successful code execution is unlikely due to memory randomization. In most scenarios, it is much more likely that an attacker who successfully exploited this vulnerability could cause the affected system to stop responding and automatically restart
Affected software: Microsoft Windows
- Windows 7 for x64-based Systems
- Windows Server 2008 R2 for x64-based Systems

Title: MS10-044 Vulnerabilities in Microsoft Office Access ActiveX Controls Could Allow Remote Code Execution
Rating: Critical (remote code execution, no known exploits)
Description: Two privately reported vulnerabilities in Microsoft Office Access ActiveX Controls. The vulnerabilities could allow remote code execution if a user opened a specially crafted Office file or viewed a Web page that instantiated Access ActiveX controls.
Affected software: Microsoft Office
- 2007 Microsoft Office System Service Pack 1
- 2007 Microsoft Office System Service Pack 2
- Microsoft Office 2003 Service Pack 3

Title: MS10-045 Vulnerability in Microsoft Office Outlook Could Allow Remote Code Execution
Rating: Important (remote code execution, no known exploits)
Description: A privately reported vulnerability that could allow remote code execution if a user opened an attachment in a specially crafted e-mail message using an affected version of Microsoft Office Outlook. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user.
Affected software: Microsoft Office
- 2007 Microsoft Office System Service Pack 1
- 2007 Microsoft Office System Service Pack 2
- Microsoft .NET Framework 1.0 Service Pack 3 (Windows XP Service Pack 2)
- Microsoft .NET Framework 1.0 Service Pack 3 (Windows XP Service Pack 3)
- Microsoft .NET Framework 1.1 Service Pack 1 (Microsoft Windows 2000 Service Pack 4)
- Microsoft .NET Framework 1.1 Service Pack 1 (Windows Server 2003 Service Pack 2)
- Microsoft .NET Framework 1.1 Service Pack 1 (Windows Server 2003 with SP2 for Itanium-based Systems)
- Microsoft .NET Framework 1.1 Service Pack 1 (Windows Server 2003 x64 Edition Service Pack 2)
- Microsoft .NET Framework 1.1 Service Pack 1 (Windows Server 2008 for 32-bit Systems Service Pack 2)
- Microsoft .NET Framework 1.1 Service Pack 1 (Windows Server 2008 for 32-bit Systems)
- Microsoft .NET Framework 1.1 Service Pack 1 (Windows Server 2008 for Itanium-based Systems Service Pack 2)
- Microsoft .NET Framework 1.1 Service Pack 1 (Windows Server 2008 for Itanium-based Systems)
- Microsoft .NET Framework 1.1 Service Pack 1 (Windows Server 2008 for x64-based Systems Service Pack 2)
- Microsoft .NET Framework 1.1 Service Pack 1 (Windows Server 2008 for x64-based Systems)
- Microsoft .NET Framework 1.1 Service Pack 1 (Windows Vista Service Pack 1)
- Microsoft .NET Framework 1.1 Service Pack 1 (Windows Vista Service Pack 2)
- Microsoft .NET Framework 1.1 Service Pack 1 (Windows Vista x64 Edition Service Pack 1)
- Microsoft .NET Framework 1.1 Service Pack 1 (Windows Vista x64 Edition Service Pack 2)
- Microsoft .NET Framework 1.1 Service Pack 1 (Windows XP Professional x64 Edition Service Pack 2)
- Microsoft .NET Framework 1.1 Service Pack 1 (Windows XP Service Pack 2)
- Microsoft .NET Framework 1.1 Service Pack 1 (Windows XP Service Pack 3)
- Microsoft .NET Framework 2.0 Service Pack 1 (Windows Server 2008 for 32-bit Systems)
- Microsoft .NET Framework 2.0 Service Pack 1 (Windows Server 2008 for Itanium-based Systems)
- Microsoft .NET Framework 2.0 Service Pack 1 (Windows Server 2008 for x64-based Systems)
- Microsoft .NET Framework 2.0 Service Pack 1 (Windows Vista Service Pack 1)
- Microsoft .NET Framework 2.0 Service Pack 1 (Windows Vista x64 Edition Service Pack 1)
- Microsoft .NET Framework 2.0 Service Pack 2 (Microsoft Windows 2000 Service Pack 4)
- Microsoft .NET Framework 2.0 Service Pack 2 (Windows Server 2003 Service Pack 2)
- Microsoft .NET Framework 2.0 Service Pack 2 (Windows Server 2003 with SP2 for Itanium-based Systems)
- Microsoft .NET Framework 2.0 Service Pack 2 (Windows Server 2003 x64 Edition Service Pack 2)
- Microsoft .NET Framework 2.0 Service Pack 2 (Windows Server 2008 for 32-bit Systems Service Pack 2)
- Microsoft .NET Framework 2.0 Service Pack 2 (Windows Server 2008 for 32-bit Systems)
- Microsoft .NET Framework 2.0 Service Pack 2 (Windows Server 2008 for Itanium-based Systems Service Pack 2)
- Microsoft .NET Framework 2.0 Service Pack 2 (Windows Server 2008 for Itanium-based Systems)
- Microsoft .NET Framework 2.0 Service Pack 2 (Windows Server 2008 for x64-based Systems Service Pack 2)
- Microsoft .NET Framework 2.0 Service Pack 2 (Windows Server 2008 for x64-based Systems)
- Microsoft .NET Framework 2.0 Service Pack 2 (Windows Vista Service Pack 1)
- Microsoft .NET Framework 2.0 Service Pack 2 (Windows Vista Service Pack 2)
- Microsoft .NET Framework 2.0 Service Pack 2 (Windows Vista x64 Edition Service Pack 1)
- Microsoft .NET Framework 2.0 Service Pack 2 (Windows Vista x64 Edition Service Pack 2)
- Microsoft .NET Framework 2.0 Service Pack 2 (Windows XP Professional x64 Edition Service Pack 2)
- Microsoft .NET Framework 2.0 Service Pack 2 (Windows XP Service Pack 2)
- Microsoft .NET Framework 3.5 (Windows Server 2003 Service Pack 2)
- Microsoft .NET Framework 3.5 (Windows Server 2003 with SP2 for Itanium-based Systems)
- Microsoft .NET Framework 3.5 (Windows Server 2003 x64 Edition Service Pack 2)
- Microsoft .NET Framework 3.5 (Windows Server 2008 for 32-bit Systems)
- Microsoft .NET Framework 3.5 (Windows Server 2008 for x64-based Systems)
- Microsoft .NET Framework 3.5 (Windows Vista Service Pack 1)
- Microsoft .NET Framework 3.5 (Windows Vista x64 Edition Service Pack 1)
- Microsoft .NET Framework 3.5 (Windows XP Professional x64 Edition Service Pack 2)
- Microsoft .NET Framework 3.5 (Windows XP Service Pack 2)
- Microsoft .NET Framework 3.5 (Windows XP Service Pack 3)
- Microsoft .NET Framework 3.5 Service Pack 1 (Windows Server 2003 Service Pack 2)
- Microsoft .NET Framework 3.5 Service Pack 1 (Windows Server 2003 with SP2 for Itanium-based Systems)
- Microsoft .NET Framework 3.5 Service Pack 1 (Windows Server 2003 x64 Edition Service Pack 2)
- Microsoft .NET Framework 3.5 Service Pack 1 (Windows Server 2008 for 32-bit Systems Service Pack 2)
- Microsoft .NET Framework 3.5 Service Pack 1 (Windows Server 2008 for 32-bit Systems)
- Microsoft .NET Framework 3.5 Service Pack 1 (Windows Server 2008 for Itanium-based Systems Service Pack 2)
- Microsoft .NET Framework 3.5 Service Pack 1 (Windows Server 2008 for x64-based Systems Service Pack 2)
- Microsoft .NET Framework 3.5 Service Pack 1 (Windows Server 2008 for x64-based Systems)
- Microsoft .NET Framework 3.5 Service Pack 1 (Windows Vista Service Pack 1)
- Microsoft .NET Framework 3.5 Service Pack 1 (Windows Vista Service Pack 2)
- Microsoft .NET Framework 3.5 Service Pack 1 (Windows Vista x64 Edition Service Pack 1)
- Microsoft .NET Framework 3.5 Service Pack 1 (Windows Vista x64 Edition Service Pack 2)
- Microsoft .NET Framework 3.5 Service Pack 1 (Windows XP Professional x64 Edition Service Pack 2)
- Microsoft .NET Framework 3.5 Service Pack 1 (Windows XP Service Pack 3)
- Microsoft .NET Framework 3.5.1 (Windows 7 for 32-bit Systems)
- Microsoft .NET Framework 3.5.1 (Windows 7 for x64-based Systems)
- Microsoft .NET Framework 3.5.1 (Windows Server 2008 R2 for Itanium-based Systems)
- Microsoft .NET Framework 3.5.1 (Windows Server 2008 R2 for x64-based Systems)
- Microsoft Office 2003 Service Pack 3
- Microsoft Office XP Service Pack 3

The Microsoft Security Response Center (MSRC) has provided these visual representations of the July 2010 Patch Tuesday update.







Tags: Microsoft, Patch Tuesday
About the author: George Norman
George is a news editor.
You can follow him on Google+, Facebook or Twitter

I Hope you LIKE this blog post! Thank you!
What do YOU have to say about this
blog comments powered by Disqus
Popular News
By George Norman on 17 Aug 2017
With the blockbuster movie season upon us, Sony decided to celebrate the occasion with a sale: the Attack of the Blockbusters Sale that offers discounts of up to 50% (60% if you’re a PlayStation Plus member) on a ton of PS4 video games.
By George Norman on 17 Aug 2017
Samsung’s new T5 portable solid-state drive (PSSD) uses the latest 64-layer V-NAND technology, offers between 250GB and 2TB of storage capacity, has a lightweight and shock-resistant design that’s smaller than the average business card, and delivers industry-leading transfer speeds of up to 540 MB/s.
Related News
By George Norman on 19 Jun 2017
Don’t worry. I’m not going to rehash all those facts that everyone already knows about Bill Gates, like how he got arrested for driving without a license, that he is a college dropout, and that he plans to give most of his fortune to charity.
By George Norman on 31 Jul 2017
Microsoft has a new keyboard to offer: the new, premium quality Microsoft Modern Keyboard with Fingerprint ID. If you’re not familiar with it, then keep on reading and you’ll uncover pretty much everything there is to know about this keyboard.
By George Norman on 18 Jul 2017
Sure, text remains the main method of communicating with others when using a messenger application like Skype, but if you really want to get the message across, using an emoticon, emoji or sticker can’t hurt.
By George Norman on 07 Jun 2017
Yes, I know that the global PC market is in a downwards spiral for its nth quarter and that mobile usage is on the rise. Still, I argue that a desktop PC is better than all the other alternatives.
Sponsored Links
Hot Software Updates
Top Downloads
Become A Fan!
Link To Us!
July '10 Patch Tuesday Detailed
HTML Linking Code