—Erek
for news
This market looks at several scenarios for Microsoft product security in March, 2007, looking at IE7, Vista, Office, and other products and remote code execution vulnerabilities. Decisions will be based on CVE vectors and Microsoft product bulletins.
At least one remote code execution vulnerability will be disclosed in March, 2007 for the Microsoft product Internet Explorer 7. This vulnerability MAY involve user interaction but MUST allow for arbitrary code execution of the attacker’s choice.
At least one remote code execution vulnerability will be disclosed in March, 2007 for the Microsoft product Windows Vista (excluding additional products such as MS Office). This vulnerability MAY NOT involve user interaction and MUST allow for arbitrary code execution of the attacker’s choice.
At least one remote code execution vulnerability will be disclosed in March, 2007 for the Microsoft product Office. This vulnerability MAY involve user interaction but MUST allow for arbitrary code execution of the attacker’s choice.
At least one remote code execution vulnerability will be disclosed in March, 2007 for the Microsoft products Outlook or Outlook Express. This vulnerability MAY involve user interaction but MUST allow for arbitrary code execution of the attacker’s choice.
At least one remote code execution vulnerability will be disclosed in March, 2007 for the Microsoft product Windows Media Player 10. This vulnerability MAY involve user interaction but MUST allow for arbitrary code execution of the attacker’s choice.