Important Security Hotfix MS07-059
Please Install New Security Hotfix MS07-059
We will be releasing a security hotfix for Windows SharePoint Services MS07-059 on October 9th. Be sure to note that as Windows SharePoint Services 3.0 is included with all editions of Office SharePoint Server 2007, Microsoft Office Project Server 2007, and Performance Point Server as well as any others which include WSS 3.0 you need to apply this hotfix on those environments as well.
We recommend applying this hotfix during your next planned downtime, or change management window and scheduling this with priority. This hotfix contains previously released hotfixes including the DST (Daylight Savings Time) hotfix.
First, if you have deployed “host named site collections” previously known as “host header” sites you should contact product support if you have more than 50 host named site collections and ask for the fix related to KB 943594. This fix includes the same hotfixes as the October 9 public update in addition to the host named site collection update performance related hotfix. <update 10/18/07> This WSS Hotfix KB for customers which meet this condition of "Header Site Collection mode" is now live, http://support.microsoft.com/kb/943594. </update>
The most important thing as the title suggests is this hotfix addresses a security vulnerability in Microsoft Windows SharePoint Services 3.0 that could allow cross-site scripting. This update resolves this vulnerability. Please read the entire contents of the KB article before applying the hotfix as there are a number of known issues which should be well understood.
http://support.microsoft.com/kb/942017
To view the complete security bulletin, visit the following Microsoft Web site:
http://www.microsoft.com/technet/security/bulletin/ms07-059.mspx
WSS 3.0
http://support.microsoft.com/?id=934525 (http://support.microsoft.com/kb/934525/) Description of the security update for Windows SharePoint Services 3.0: October 9, 2007
DOWNLOADS
Security Update for Windows SharePoint Services 3.0 x64 Edition (KB934525)
http://www.microsoft.com/downloads/info.aspx?na=22&p=1&SrcDisplayLang=en&SrcCategoryId=&SrcFamilyId=&u=%2fdownloads%2fdetails.aspx%3fFamilyID%3d667335dd-df2e-4f14-a130-5758701be055%26DisplayLang%3den
Security Update for Windows SharePoint Services 3.0 (KB934525)
http://www.microsoft.com/downloads/info.aspx?na=22&p=2&SrcDisplayLang=en&SrcCategoryId=&SrcFamilyId=&u=%2fdownloads%2fdetails.aspx%3fFamilyID%3d76fc2225-2802-46e5-a294-a842e3841877%26DisplayLang%3den
MOSS
http://support.microsoft.com/?id=937832 (http://support.microsoft.com/kb/937832/) Description of the security update for SharePoint Server 2007: October 9, 2007
DOWNLOADS
Security Update for Microsoft Office SharePoint Server 2007 x64 (KB937832), http://www.microsoft.com/downloads/info.aspx?na=22&p=1&SrcDisplayLang=en&SrcCategoryId=&SrcFamilyId=&u=%2fdownloads%2fdetails.aspx%3fFamilyID%3d1d319164-d133-4493-be27-1aeda62362c4%26DisplayLang%3den
Security Update for Microsoft Office SharePoint Server 2007 (KB937832), http://www.microsoft.com/downloads/info.aspx?na=22&p=2&SrcDisplayLang=en&SrcCategoryId=&SrcFamilyId=&u=%2fdownloads%2fdetails.aspx%3fFamilyID%3daaea9695-f541-4c4c-9107-81ead5cfc8c9%26DisplayLang%3den
How to deploy software updates for Windows SharePoint Services 3.0
We recommend that you follow the process and procedures in the Deploy software updates for Windows SharePoint Services 3.0 topic for most deployment scenarios, from stand-alone server deployments to very large server farms.
http://technet2.microsoft.com/windowsserver/WSS/en/library/91649a7e-6b5a-4e5a-9ee5-51951f4b857f1033.mspx
If you are running Office SharePoint Server you may find additional guidance in the article Deploy software updates for Office SharePoint Server 2007.
http://technet2.microsoft.com/Office/en-us/library/f484f5f2-35bb-4d70-bf56-dd1c4c287c721033.mspx
<Updated 11/23>
Important Troubleshooting Info on this Hotfix
Product support and MS IT has shared some of their experience with troubleshooting issues related to the patch.
Other relevant recent posts:
Hotfixes, Service packs, and password resets
Daylight Savings Time Hotfix post
FAQ on DST and Hotfix