MS07-012: Vulnerability in Microsoft Foundation Classes could allow for remote code execution

INTRODUCTION

Microsoft has released security bulletin MS07-012. The security bulletin contains all the relevant information about the security update. This information includes file manifest information and deployment options. To view the complete security bulletin, visit one of the following Microsoft Web sites:

Known issues after you install this security update

  • After you apply this security update to a computer that is running the original release version (RTM) of Windows Server 2003, and then you apply Windows Server 2003 Service Pack 1 (SP1), the computer may again be susceptible to the vulnerabilities that are described in this Knowledge Base article.



    Note Customers who have applied Windows Server 2003 Service Pack 2 (SP2) are not affected by this problem.


    To resolve this problem, do either of the following:

    • Reinstall this security update.
    • Install Windows Server 2003 SP2.

      For more information, click the following article number to view the article in the Microsoft Knowledge Base:
      889100 How to obtain the latest service pack for Windows Server 2003
  • The MFC source file Oleui2.cpp is not updated when you install the security update for Visual Studio .NET 2003 Service Pack 1 in MS07-012. This does not apply to customers who do not have Visual Studio .NET 2003 installed on their systems.

    For more information, click the following article number to view the article in the Microsoft Knowledge Base:

    933273 FIX: The MFC source file Oleui2.cpp is not updated when you install security update MS07-012

  • The Mfc42u.dll file is not updated when you install security update MS07-012.

    For more information, click the following article number to view the article in the Microsoft Knowledge Base:

    933339 The version number of the Mfc42u.dll file is not updated when you apply security update MS07-012

References

For more information, click the following article number to view the article in the Microsoft Knowledge Base:

924641 Description of the security update for the Microsoft Visual Studio .NET 2002 development platform

924642 Description of the security update for the Microsoft Visual Studio .NET 2002 Service Pack 1 development platform

924643 Description of the security update for the Visual Studio .NET 2003 development platform

927696 Description of the security update for the Visual Studio .NET 2003 Service Pack 1 development platform

918118 MS07-013: Vulnerability in Microsoft RichEdit could allow remote code execution

926436 MS07-011: Vulnerability in Microsoft OLE Dialog could allow remote code execution

Properties

Article ID: 924667 - Last Review: Apr 30, 2009 - Revision: 1

Feedback