Microsoft Office Visio 2007 Service Pack 3 (SP3) and Microsoft Office Visio Language Pack 2007 SP3 provide the latest updates to Office Visio 2007 and to Office Visio Language Pack 2007. These updates include two main categories of fixes:
Previously unreleased fixes that were made specifically for this service pack. In addition to general product fixes, this includes improvements in stability, in performance, and in security.
All the public updates, security updates, cumulative updates, and hotfixes that were released through August 2011.
Because Office service packs are cumulative, you do not have to install Service Pack 1 or Service Pack 2 before you install Service Pack 3. Service Pack 3 includes all fixes which were included in Service Pack 1 and Service Pack 2.
More





此安全更新可解决主机集成服务器中两个公开披露的漏洞。如果远程攻击者将特制网络数据包发送到侦听 UDP 端口 1478 或 TCP 端口 1477 和 1478 的主机集成服务器,则这些漏洞可能允许拒绝服务。采用防火墙最佳做法和标准的默认防火墙配置,有助于保护网络免受从企业外部发起的攻击。按照最佳做法,应使连接到 Internet 的系统所暴露的端口数尽可能少。在这种情况下,应阻止从 Internet 访问主机集成服务器端口。
此安全更新解决 Internet Explorer 中的 11 个秘密报告的漏洞。最严重的漏洞可能在用户使用 Internet Explorer 查看特制网页时允许远程执行代码。成功利用这些漏洞的攻击者可以获得与本地用户相同的用户权限。那些帐户被配置为拥有较少系统用户权限的用户比具有管理用户权限的用户受到的影响要小。
此安全更新可解决 Microsoft Forefront Unified Access Gateway (UAG) 中五个秘密报告的漏洞。如果用户使用特制的 URL 访问受影响的网站,则其中最严重的漏洞可能允许远程执行代码。但是,攻击者无法强迫用户访问该网站。相反,攻击者必须说服用户访问该网站,方法通常是让用户单击电子邮件或 Instant Messenger 消息中的链接以使用户链接到攻击者的网站。