ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Microsoft fixes 'critical' flaws in new programs

Joris Evers CNET News.com

Published: 09 May 2007 09:56 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft on Tuesday released fixes for 19 security flaws in several of its products, including the new Internet Explorer 7, Office 2007 and Exchange 2007.

The company published seven security bulletins as part of its monthly patch cycle. All are tagged "critical", its highest rating. Critical vulnerabilities typically allow an attacker to gain full control of an affected system with very little, if any, action by the user.

Most of the vulnerabilities addressed by Tuesday's fixes can only be exploited after someone visits a rigged website or opens a malicious file, attack approaches that are increasingly popular among cybercrooks.

Microsoft's MS07-027 update fixes six flaws in Internet Explorer that could be exploited through malicious websites. Three Microsoft updates deal with flaws in Office applications, including Office 2007. Most of these bugs exist because of errors in the way the applications handle certain files and could be exploited through a rigged Office file.

Exchange is flawed in a way that could allow a system running the email server software to be fully compromised without any special user action. There are four vulnerabilities in Exchange, including Exchange 2007, addressed by Microsoft's MS07-026 fix. The most serious bug exists in the way Exchange encodes email messages.

The fact that several of the newly reported vulnerabilities critically affect Internet Explorer 7, Office 2007 and Exchange 2007, hurts Microsoft's security message, said Amol Sarwate, manager of the vulnerability research lab at Qualys. Microsoft has marketed these programs as secure, citing its security development process.

"Microsoft 2007 software, including Exchange and Office, continues to come up vulnerable, demonstrating that the security development lifecycle is not infallible," Sarwate said. Last month's Microsoft patches included a fix for a zero-day flaw in Windows that also affected Vista.

Another vulnerability that may affect many users lies in "Capicom", a component to add cryptography to applications. It is flawed in the way it handles specific data, a bug that could let an attacker commandeer a computer running the component, Microsoft said in bulletin MS07-028.

Among Microsoft's updates are fixes for a trio of zero-day vulnerabilities. This includes an expected patch for a flaw in the Windows domain name system, or DNS. The vulnerability affects Windows 2000 Server and Windows Server 2003. Microsoft warned of the problem last month and has said it was being used in "limited" attacks.

The remaining zero-day vulnerabilities for which fixes are now available are in Internet Explorer and Word, Microsoft said. The Word flaw had also been used in cyberattacks, it said.

Microsoft's fixes will be made available to Windows users via the Automatic Updates feature and are also available for download from Microsoft Update and Windows Update.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
5 out of 7 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Exception Java Developer Hedgefund Algo Execution Trading - DMA/FIX

Links/messaging protocols for order execution both direct to exchanges and via prime brokers through FIX connectivity. Exception Algorithmic Trading. ...

Equities & FIX Application Support Specialist - Contract

Working knowledge of the FIX protocol (versions 4.0; 4.2 and 4.4). My Client has a requirement for an Equity and Exchange Connectivity Support ...

Hardware Break/Fix Engineer

ESG provides hardware support in the form of COTS Integration and Installation, and Break/Fix services to EDS Defence Projects based mainly in Hook. ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment