Once again, it is the second Tuesday of the month, and time for Microsoft patches. This month, there are four security bulletins (three for Windows, one for Office), which address a total of 22 identified vulnerabilities. One of the bulletins, for Windows, has a maximum severity rating of Critical; the other three bulletins are rated Important. All supported versions of Windows are affected; for a breakdown of bulletin severity by Windows version, please see my preview post of last Thursday. The Office bulletin affects Microsoft Visio, Service Pack 3. If you use Visio, this is an important update; code to exploit the underlying vulnerability has been published. More details and download links are in the Security Bulletin Summary for July 2011.
Microsoft says that the three Windows patches will definitely require a reboot, and the Office patch may require one, depending on the configuration of your system. As usual, I recommend that you install these patches as soon as you conveniently can.
If you are using the Vista version of Windows, you should note that today is the last day that Windows Vista with Service Pack 1 is supported. I suggest you check to make sure that you have Service Pack 2 installed (that setup will continue to be supported). If you need to get Windows Service Packs, you can download them here.
As usual, the folks at the SANS Internet Storm Center have published their summary of the bulletins, with their own severity rating and comments.