ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Desktop platforms Toolkit in association with http://ad.doubleclick.net/clk;205413468;14699245;m?http://adfarm.mediaplex.com/ad/ck/2397-58840-22058-14

Office XP hole compromises personal data

Wendy McAuliffe ZDNet.co.uk

Published: 18 Oct 2001 17:07 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Companies using Microsoft Office XP and Internet Explorer version 5 have been warned that documents containing personal information could be sent to Microsoft along with debugging information in the event of a program crash.

The Error Reporting feature sends crash and debug information back to Microsoft to help the company detect and fix bugs in its software. But the US Computer Incident Advisory Service (CIAC) has released a security bulletin claiming that the debugging information contains a memory dump, which may include all or part of the document being viewed or edited.

"If a sensitive document is resident in the memory dump, this could be sent to Microsoft," said Graham Cluley, senior technology consultant at antivirus firm Sophos. "This is not a serious problem but an interesting foible."

The CIAC bulletin states that the Error Reporting function is configured to "automatically" send debugging information to Microsoft, and claims that the relevant dialogue box does not make it obvious that the contents of the document being edited may be sent along with information about the programme crash.

But Microsoft contests that the reporting function asks for user permission before any information is forwarded, while additionally offering the option of turning the feature off from all company desktops.

"We make it clear to customers that when a problem occurs, their Digital Product ID and Internet Protocol (IP) address will be sent to us," said Neil Laver, Windows marketing manager. "The report could also contain customer-specific information which could be used to identify a person's identity, but will not be used." Microsoft additionally claims that it limits the number of people who have access to the bug reports.

The Error Reports are sent via a standard security protocol, which is sufficient in protecting confidentiality, according to Microsoft. "This encrypts data sent over the Internet, but not the document," Laver clarified.

Cluley thinks it unlikely that many companies will be sending bug reports over the Internet, but warns that, "whenever any kind of communication takes place on the Internet, there is always the opportunity for people to intercept it."

See the Viruses and Hacking News Section for the latest headlines.

See the Net Crime News Section for the latest on hacking, fraud, viruses and related issues.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
31 out of 78 people found this useful


Full Talkback thread

1 comment

  1. not just office, even windows XP has those. just... Anonymous

Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Service Support Manager (ITIL) - Manchester

Additionally, you will have demonstrable experience and passion in delivering and improving client-focused and responsive ICT services. These ...

SQL Server Developer / Pro DBA - Legal Firm

Additionally you will be required to maintain the Finance (currently CMS) and document management (currently ROLE Reporting to the head of IT, the ...

Service Support Manager (ITIL) - Manchester

Additionally, you will have demonstrable experience and passion in delivering and improving client-focused and responsive ICT services. Service Desk ...

Featured Talkback

So if you upgrade to XP SP3 you can't uninstall Internet Explorer, I'm quite sure I'm having a Deja-vu feeling about MS preventing people from uninstalling Internet Explorer in other Windows products.

By: TheKLF99

Read full story:
Upgraders to XP SP3 warned over IE downgrades

Desktop Management Benchmarking

Test Your Desktop Management Systems

How good are your company's desktop management solutions? How do they compare with those of your peers?

Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.