U.S. Cert explained that "a remote, unauthenticated attacker could execute arbitrary code on a vulnerable system. An attacker may also be able to cause a denial of service or launch cross-site scripting attacks."
- MS07-018. Critical. Could allow Remote Code Execution. Affects Microsoft Content Management Server.
- MS07-019. Critical. Could allow Remote Code Execution. Affects Universal Plug and Play.
- MS07-020. Critical. Could allow Remote Code Execution. Affects Microsoft Agent.
- MS07-021. Critical. Could allow Remote Code Execution. Affects CSRSS (Windows Client/Server Run-time Subsystem).
- MS07-022. Important. Could allow Remote Elevation of Privilege. Affects Windows Kernel.
"Many versions of Windows, including the latest edition of Windows Vista, are affected by these critical security flaws," said Graham Cluley, senior technology consultant at Sophos. "Hackers will show no mercy in taking advantage of these vulnerabilities in Microsoft's code unless companies and home consumers patch against them as a matter of priority. Anyone not taking these flaws seriously is asking for trouble."