ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Microsoft leaves Word flaws unpatched

Joris Evers CNET News.com

Published: 10 Jan 2007 09:52 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft on Tuesday released fixes for vulnerabilities in its Windows and Office software, but left several known Word zero-day flaws without a patch.

As part of its monthly patch cycle, Microsoft published four security bulletins with fixes for 10 vulnerabilities. Three of the bulletins are deemed "critical", the company's most serious rating; the fourth is tagged "important", a notch lower. All bulletins, however, address flaws that could allow an attacker to commandeer a PC.

"Microsoft does recommend that all customers sign up for Microsoft Update and enable its Automatic Updates functionality to receive all updates available this month and to help make their systems more secure," a Microsoft representative said in an emailed statement.

Among Microsoft's fixes are three vulnerabilities that were previously known. Still, the company left several known zero-day vulnerabilities without a patch.

"Conspicuous by their absence are patches for the zero-day exploits in Word," Andrew Storms, director of security operations at network security firm nCircle, said in a statement. These patches were probably pulled due to quality issues, he said. Microsoft on Friday postponed four of its planned eight security bulletins.

All of the security vulnerabilities addressed by Microsoft's first fixes of 2007 relate to how multiple versions of Windows and Office handle specific files. Attackers could create malicious files that, when opened, at worst could give the attacker control of a vulnerable PC, according to Microsoft's bulletins.

Nine of the 10 security holes Microsoft provided fixes for lie in Office applications. Five affect Excel, three hit Outlook, and one impacts the Brazilian Portuguese grammar checker for Office. Opening rigged files could trigger the flaws and allow an attack to occur, Microsoft said. Both Windows and Mac versions of Office are affected.

"Today's patch release illustrates once again that the volume of client-side vulnerabilities for the Windows platform is not slowing down," Oliver Friedrichs, a Symantec Security Response director, said in a statement. "Attackers are exploiting vulnerabilities with increasing speed, and it's imperative that computer users protect themselves by installing updated software patches as quickly as possible."

The tenth hole is in Windows and is similar to a bug Microsoft rushed out a fix for in September after Windows users came under attack. The vulnerability lies in a Windows component called "vgx.dll" that is meant to support Vector Markup Language documents in the operating system. VML is used for high-quality vector graphics on the Web.

Like the first VML hole, this vulnerability can be exploited by tricking a user into viewing a malicious VML file on a website with Internet Explorer. All recent versions of Windows are vulnerable with all recent versions of IE, including IE 7, according to Microsoft. The exception is Windows Vista, which is not affected, it said.

Microsoft's patches will be distributed via Automatic Updates and the company's Microsoft Update downloads website.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
42 out of 47 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Website Developer - ASP.Net, C#, SQL Server in Bristol

An international company in Bristol requires an experienced web developer to join their IT team. You will be working in .Net on 7 websites for UK ...

Webmaster / Website administrator

My exciting client requires a Webmaster. This exciting 3 month + contract based in the Thames Valley, requires experience of Intelligent Content ...

Website / Web Developer Required - Wiltshire - New Media 25 - 30k

Huxley Associates are looking for a talented Web Developer to work for our exclusive client based in Wiltshire to work for our well known client. You ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment