Microsoft KB Archive/918118

= MS07-013: Vulnerability in Microsoft RichEdit could allow remote code execution =

Article ID: 918118

Article Last Modified on 10/11/2007

-

APPLIES TO

 Microsoft Office 2000 Service Pack 3, when used with:  Microsoft Access 2000 Standard Edition

 Microsoft Excel 2000 Standard Edition

 Microsoft FrontPage 2000 Standard Edition

 Microsoft Outlook 2000 Standard Edition</li></ul>

 Microsoft PowerPoint 2000 Standard Edition</li></ul>

 Microsoft Publisher 2000 Standard Edition</li></ul>

 Microsoft Word 2000 Standard Edition</li></ul> </li> Microsoft Office XP, All Editions Service Pack 3 (SP-3), when used with:  Microsoft Access 2002 Standard Edition</li></ul>

 Microsoft Excel 2002 Standard Edition</li></ul>

 Microsoft FrontPage 2002 Standard Edition</li></ul>

 Microsoft Outlook 2002 Standard Edition</li></ul>

 <li>Microsoft PowerPoint 2002 Standard Edition</li></ul>

<ul> <li>Microsoft Publisher 2002 Standard Edition</li></ul>

<ul> <li>Microsoft Word 2002 Standard Edition</li></ul> </li> <li>Microsoft Office 2003 Service Pack 2, when used with: <ul> <li>Microsoft Office Access 2003</li></ul>

<ul> <li>Microsoft Office Excel 2003</li></ul>

<ul> <li>Microsoft Office FrontPage 2003</li></ul>

<ul> <li>Microsoft Office InfoPath 2003</li></ul>

<ul> <li>Microsoft Office OneNote 2003</li></ul>

<ul> <li>Microsoft Office Outlook 2003</li></ul>

<ul> <li>Microsoft Office PowerPoint 2003</li></ul>

<ul> <li>Microsoft Office Publisher 2003</li></ul>

<ul> <li>Microsoft Office Word 2003</li></ul>

<ul> <li>Microsoft Office Word Viewer 2003</li></ul> </li> <li>Microsoft Office Project 2003 Service Pack 2</li> <li>Microsoft Office Visio 2003 Service Pack 2</li> <li>Microsoft Office XP Service Pack 1, when used with: <ul> <li>Microsoft Project 2002 Standard Edition</li></ul> </li> <li>Microsoft Visio 2002 Service Pack 2</li> <li>Microsoft Project 2000 Service Pack 1</li> <li>Microsoft Office 2000 with MultiLanguage Pack</li> <li>Microsoft Office 2004 for Mac Professional Edition</li> <li>Microsoft Office 2004 for Mac Standard Edition</li> <li>Microsoft Office 2004 for Mac Student and Teacher Edition</li> <li>Microsoft Office X for Mac Standard Edition</li> <li>Microsoft Windows 2000 Advanced Server</li> <li>Microsoft Windows 2000 Datacenter Server</li> <li>Microsoft Windows 2000 Service Pack 4</li> <li>Microsoft Windows 2000 Professional Edition</li> <li>Microsoft Windows Server 2003 R2 Standard Edition (32-bit x86)</li> <li>Microsoft Windows Server 2003 R2 Enterprise Edition (32-Bit x86)</li> <li>Microsoft Windows Server 2003 R2 Datacenter Edition (32-Bit x86)</li> <li>Microsoft Windows Server 2003 R2 Standard x64 Edition</li> <li>Microsoft Windows Server 2003 R2 Enterprise x64 Edition</li> <li>Microsoft Windows Server 2003 R2 Datacenter x64 Edition</li> <li>Microsoft Windows Server 2003, Standard x64 Edition</li> <li>Microsoft Windows Server 2003, Enterprise x64 Edition</li> <li>Microsoft Windows Server 2003, Datacenter x64 Edition</li> <li>Microsoft Windows Server 2003 SP1, when used with: <ul> <li>Microsoft Windows Server 2003, Standard Edition (32-bit x86)</li></ul>

<ul> <li>Microsoft Windows Server 2003, Enterprise Edition</li></ul>

<ul> <li>Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)</li></ul>

<ul> <li>Microsoft Windows Server 2003, Web Edition</li></ul>

<ul> <li>Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems</li></ul>

<ul> <li>Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems</li></ul> </li> <li>Microsoft Windows Server 2003, Standard Edition (32-bit x86)</li> <li>Microsoft Windows Server 2003, Enterprise Edition</li> <li>Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)</li> <li>Microsoft Windows Server 2003, Web Edition</li> <li>Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems</li> <li>Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems</li> <li>Microsoft Windows XP Media Center Edition 2002</li> <li>Microsoft Windows XP Tablet PC Edition</li> <li>Microsoft Windows XP Tablet PC Edition 2005</li> <li>Microsoft Windows XP Media Center Edition 2005</li> <li>Microsoft Windows XP Service Pack 2, when used with: <ul> <li>Microsoft Windows XP Professional</li></ul>

<ul> <li>Microsoft Windows XP Home Edition</li></ul> </li> <li>Microsoft Windows XP Professional x64 Edition</li></ul>

-

<div class="summary_section">

SUMMARY
Microsoft has released security bulletin MS07-013. The security bulletin contains all the relevant information about the security update. This information includes file manifest information and deployment options. To view the complete security bulletin, visit one of the following Microsoft Web sites: <ul> <li>Home users:

http://www.microsoft.com/athome/security/update/bulletins/200702.mspx

</li> <li>IT professionals:

http://www.microsoft.com/technet/security/bulletin/ms07-013.mspx

</li></ul>

Windows Server 2003
The version numbers of the following two binaries that are included in Microsoft Windows Server 2003 Service Pack 2 (SP2) are lower than the version numbers that are included in the MS07-013 Windows Server 2003 security update (KB918118):
 * RichEd20.dll
 * Msftedit.dll

In both of the following scenarios, Windows Server 2003 will be updated with the security update that is mentioned in the MS07-013 security update (KB918118):
 * Scenario 1

You install Windows Server 2003 SP2, and you had not previously installed the MS07-013 security update.
 * Scenario 2

You install Windows Server 2003 SP2 after you install the MS07-013 security update.

Note In this scenario, the binaries that are installed as part of the MS07-013 security update will remain on the system after you install Windows Server 2003 SP2.

Keywords: kbbug kbfix kbsecvulnerability kbqfe kbsecurity kbsecbulletin kbpubtypekc kbwin2000presp5fix kbexpertiseinter kbexpertisebeginner KB918118

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.