Microsoft has released today the following security bulletins:
5 Critical
Microsoft Security Bulletin MS06-035
Vulnerability in Server Service Could Allow Remote Code Execution (917159)
This update resolves two vulnerabilities in the Server service, the most serious of which could allow remote code execution.
Microsoft Security Bulletin MS06-036
Vulnerability in DHCP Client Service Could Allow Remote Code Execution (914388)
This update resolves a vulnerability in the DHCP Client service that could allow remote code execution.
Microsoft Security Bulletin MS06-037
Vulnerability in Microsoft Excel Could Allow Remote Code Execution (917285)
This update resolves several vulnerabilities in Excel, the most serious of which could allow remote code execution.
Microsoft Security Bulletin MS06-038
Vulnerability in Microsoft Office Could Allow Remote Code Execution (915384)
This update resolves two vulnerabilities in Office, the most serious of which could allow remote code execution.
Microsoft Security Bulletin MS06-039
Vulnerability in Microsoft Office Could Allow Remote Code Execution (915384)
This update resolves two vulnerabilities in Office, the most serious of which could allow remote code execution.
2 Important
Microsoft Security Bulletin MS06-033
Vulnerability in ASP.NET Could Allow Information Disclosure (917283)
This vulnerability could allow an attacker to bypass ASP.Net security and gain unauthorized access to objects in the Application folder explicitly by name. Note that this vulnerability would not allow an attacker to execute code or to elevate their user rights directly, but it could be used to produce useful information that could be used to try to further compromise the affected system.
Microsoft Security Bulletin MS06-034
Vulnerability in Microsoft Internet Information Services using Active Server Pages Could Allow Remote Code Execution (917537)
This vulnerability could allow an attacker to take complete control of an affected system. Note that the attacker must have valid logon credentials, but if a server has been purposely configured to allow users, either anonymous or authenticated, to upload web content such as .ASP pages to web sites, the server could be exploited by this vulnerability.
View the summary and all the details here
http://www.microsoft.com/technet/sec.../ms06-jul.mspx