MS07-057: Cumulative security update for Internet Explorer
Description: This important security update resolves three privately reported vulnerabilities and one publicly disclosed vulnerability. The vulnerability with the most serious security impact could allow remote code execution if a user viewed a specially crafted Web page using Internet Explorer.
Update type: Important
Release date: October 9, 2007
Applies to: All versions
Knowledge base: support.microsoft.com/kb/939653
Download link: 32-bit | 64-bit
Comments: Following is more information on the four vulnerabilities:
- Address Bar Spoofing Vulnerability - CVE-2007-3892
- Error Handling Memory Corruption Vulnerability - CVE-2007-3893
- Address Bar Spoofing Vulnerability - CVE-2007-1091 & CVE-2007-3826
There are a number of possible side effects of this update:
- You may receive an error message that resembles the following when you try to visit a Web page in Windows Internet Explorer 7:
Webpage cannot be displayed
- When you browse from one Web site to a different Web site in Microsoft Internet Explorer 6 in Windows XP, Internet Explorer 6 may crash.
- ActiveX controls that prompt before they are loaded.
- The use of monikers is no longer supported in Internet Explorer.
This update also includes a number of non-security related fixes:
- Internet Explorer 6 may exit with an access violation when the JavaScript garbage collector runs and you have dynamically removed a TBODY, THEAD, or TFOOT HTML tag from a table in Windows XP
- ActiveX controls are inactive when you access a Web page by using Internet Explorer 7
- Windows Internet Explorer 7 does not download an ActiveX control that is referenced in a CODEBASE attribute when you open a Web page that contains the OBJECT element and the CLSID attribute is missing
- You cannot open a Web page by using Windows Internet Explorer 7 if the URL of the Web page contains non-ASCII characters
- Focus is not set to the Web page if you minimize the browser window and then maximize it from the taskbar in Internet Explorer 7
- You cannot log on to an FTP site or you are redirected to the root folder of the FTP site in Internet Explorer 7
For more information on this issue, including potential causes, workarounds, and resolutions, see: Microsoft KB Article KB939653.

Start
About
FAQ
Blogroll
Shop
Tips and Tricks
Windows Updates
Hotfixes
Keyboard Shortcuts
Vista's Services
Vista's Commands
Product Reviews
Glossary
Videos
Web Links

Comments
Important Update for Internet Explorer in Windows Vista: KB939653
Oct 10, 2007 at 11:29 am
[...] You can read the rest of this blog post by going to the original source, here [...]
Piet (NL)
Oct 13, 2007 at 7:00 am
It seems like every two months I get a malicious update for Vista, that disables me surfing the internet. After KB933566 in june and KB937143 in august, its this KB939653 in october that blocked me once again.
Finding out which of the seven updates, that came as a package, is the villain is time consuming as I have to uninstall each individual update and check whether that brings me back to the internet.
Jeff
Oct 17, 2007 at 12:06 pm
I’ve been having problems since August with my laptop (vista). It won’t access any web pages. If this is the problem (which I think it is after many hours with the laptop manufacturers tech support), would simply uninstalling the three updates and restarting the computer solve the problem?
internet explorer » Important Update for Internet Explorer in Windows Vista: KB939653
Oct 29, 2007 at 1:19 am
[...] Read the rest of this great post here [...]
Leave a Comment