internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Norton AntiVirus 2008

Most Popular Software Downloads
Ad-Aware 2008 Free
Windows XP Service Pack 3
Internet Explorer 7
QuickTime for Windows
Adobe Flash Player
AVG Anti-Virus Free
Paint Shop Pro
Windows Live Suite
CCleaner (Crap Cleaner)
Winamp

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

A Trio of Office Exploits Rears Its Ugly Head
Three New Vulnerabilities for MS Office Exposed
Andy Patrizio

Talk about timing. Just as Microsoft was issuing its monthly array of patches, three new vulnerabilities for Microsoft Office were exposed. Fortunately, it was not one of those situations where the viruses were timed to come out after Patch Tuesday. Rather, it was a bit of good luck.

McAfee's Avert Labs reports there are three exploits. Two cause a denial-of-service within the infected computer, throttling the CPU to 100 percent and slowing it way down. The third is reported to be a buffer overflow that allows for remote code execution, but Microsoft (Quote) is denying that.

David Marcus, security research and communications manager for Avert, told internetnews.com that the vulnerabilities don't affect Office 2007, which Microsoft has confirmed. Two of the exploits affect Word and the third affects the HLP files in Office's help system.

Marcus said that the code Avert obtained was proof of concept and not really capable of doing anything. But proof-of-concept malware (define) inevitably means the bad stuff is on its way.

"What [virus writers] do is circulate the sample code on the underground amongst themselves to modify it and make it more impactful. They are very good at information sharing there," he said.

Marcus felt it was odd that sample code got out so soon, since it's in an inert stage. The code was posted to a secret forum for combating viruses by a source Marcus would not identify.

"If I could put my guessing hat on, probably a good-guy security researcher came across these proof of concept codes and decided to share them with the security community. What happened is the rest of the security community got a look at these before it got fleshed out," he said.

Microsoft has yet to say anything on its Security Response Center blog, where it usually announces such findings. The company, along with McAfee (Quote) and other antivirus vendors, are still doing their source code forensics.

In a statement, Microsoft said it is investigating "new public reports of possible vulnerabilities in Microsoft Office. Microsoft is not aware of any attacks attempting to use the reported vulnerability or of customer impact at this time. Microsoft will continue to investigate the public reports to help provide additional guidance for customers as necessary."

This would bring the number of outstanding Office security issues to four, as one buffer overflow, CVE-2007-0870, has been hanging fire since February.

Even if Microsoft chooses to wait until the scheduled patches in May, McAfee and other antivirus vendors will provide their own protections. "Mind you, it would be better for them to patch sooner rather than later, but from our point of view, we're providing protection for it," said Marcus.

News courtesy of internetnews.com

April 12, 2007

Download Windows Live OneCare Now!Download

Download Microsoft Windows Malicious Software Removal Tool Now!Download

View All Microsoft Service & Security Releases

Contents:
1. Three New Vulnerabilities for MS Office Exposed






JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
Microsoft Article: 7.0, Microsoft's Lucky Version?
Microsoft Article: Hyper-V--The Killer Feature in Windows Server 2008
Avaya Article: How to Feed Data into the Avaya Event Processor
Microsoft Article: Install What You Need with Windows Server 2008
HP eBook: Putting the Green into IT
Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
Avaya Article: Setting Up a SIP A/S Development Environment
IBM Article: How Cool Is Your Data Center?
Microsoft Article: Managing Virtual Machines with Microsoft System Center
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Video: Are Multi-core Processors Here to Stay?
On-Demand Webcast: Five Virtualization Trends to Watch
HP Video: Page Cost Calculator
Intel Video: APIs for Parallel Programming
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Sun Download: Solaris 8 Migration Assistant
Sybase Download: SQL Anywhere Developer Edition
Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
Red Gate Download: SQL Compare Pro 6
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
IBM Article: Collaborating in the High-Performance Workplace
HP Demo: StorageWorks EVA4400
Intel Featured Algorhythm: Intel Threading Building Blocks--The Pipeline Class
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES