CIO Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
Daily Briefing for Technology's Top Decision-Makers
Saturday, July 31st 
Home
Enterprise Software
Enterprise Hardware
Network Security
Compliance
CRM Systems
Data Storage
Chips & Processors
Operating Systems
Communications
World Wide Web
Wireless Tech
Small Business
CIO Issues
Business Briefing
After Hours
Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement
Enterprise Software

Patch Tuesday Plugs 12 Holes in Microsoft Office

Patch Tuesday Plugs 12 Holes in Microsoft Office
March 12, 2008 8:21AM

Bookmark and Share
Excel zero-day vulnerability is fixed in Microsoft Patch Tuesday release focused entirely on Microsoft Office. Symantec says Microsoft's Web Office Components patch is the most critical because hackers have targeted ActiveX components. Microsoft's Patch Tuesday security patches also include a vulnerability in Microsoft's Outlook e-mail client.


On Patch Tuesday, Microsoft fixed 12 vulnerabilities in four security Relevant Products/Services bulletins. Every one of them fixes bugs in Microsoft Office.

Included is a fix for the zero-day remote-code vulnerability in Excel. The exploit was made public in January and is corrected by the MS08-014 patch that addresses seven vulnerabilities in Excel. The other patches, MS08-015, MS08-016 and MS08-017, address issues in Outlook, Office and Office Web Components, respectively.

All the security bulletins are serious, but the Office Web Components patch stands out because these ActiveX components are widely distributed and relatively easy to exploit, according to Ben Greenbaum, senior research manager for Symantec Security Response. Symantec has observed attackers continuing to target Web plug-ins to quickly and quietly install malicious code.

"While browser plug-ins of all kinds represent an increasingly attractive vector for attackers, the security of other nonnetwork-facing applications is still a relevant issue as well," Greenbaum said. "With seven vulnerabilities being addressed in the Microsoft Excel patch, it's clear that users need to keep all software patched and up to date. Additionally, full-featured security software can protect users from attacks against some vulnerabilities well in advance of the availability of patches."

Don't Delay

Because all four of the patches affect Microsoft Office, these patches cannot be ignored or delayed, urged Don Leatham, director of solutions and strategy at Lumension Security. The broad install base of Microsoft Office, he said, makes Office vulnerabilities an enticing target for hackers and cybercriminals.

"Microsoft Outlook is the dominant e-mail client in use today, and e-mail is also one of the most common attack vehicles used by hackers against organizations," Leatham said. "This will make Bulletin 2, a critical, remote-code-execution vulnerability which affects virtually all versions of Outlook, the biggest priority for IT Relevant Products/Services administrators. This vulnerability affects all versions of Outlook, including Outlook 2007 running on Windows XP and Vista."

Where's the Missing Patch?

Sheldon Malm, director of vulnerability research for nCircle, a network Relevant Products/Services-security firm that works with companies like Visa, US Cellular and Archer Daniels Midland, sees all four patches as equally important because they address client-side vulnerabilities. Of the 17 advisories so far in 2008, nine affected client-side technologies. That's not counting the 12 in Tuesday's release.

"My question is, where did the VBScript/JScript patch go that was announced and then pulled from the February updates?" Malm asked. "Attackers have had more than a month to uncover the vulnerability and write exploits. If there isn't an exploit in the wild on this one yet, I'm sure we'll see it before too long. This, perhaps, defines the one flaw in the advanced notification system -- we inform hackers of vulnerabilities of which they may not be aware and give them ample time to exploit."

Understanding the Attack Methods

The usual attack method targeting client-side applications is to entice an end user to open an infected attachment, or click on a hyperlink that leads to an infected attachment, according to Amol Sarwate, manager of the vulnerability research lab at Qualys. When the attachment is activated, systems become vulnerable to a remote system takeover.

"These attacks are especially nefarious as there is no simple traditional security approach, such as blocking an incoming traffic port, that would be able to detect and prevent its delivery to the intended recipient," Sarwate said. "Rather, prevention relies heavily on end-user education and regular system patching."

Tell Us What You Think
Comment:

Name:

Advertisement



 Enterprise Software
1. Safari 5.0.1 Offers Extensions Gallery
2. SAP's Second-Quarter Profit Jumps
3. Google Offers Apps for Government
4. Salesforce.com Breaks the CEO Mold
5. Rackspace and NASA Open Up Cloud


advertisement


 Most Popular Articles
1. A Big Error: Apple Says iPhone Meter Needs Update
2. Sunbelt Software Acquired by GFI
3. Jobs Offers Free Cases, Scolds Media for 'Antennagate'
4. With Palm Deal Complete, HP Moves To Expand webOS
5. EMC Will Acquire Greenplum for Data Storage in the Cloud

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  BlackPad Tablet Expected from RIM
  FCC Approves First LTE 4G Phone
  Google Cries Wolf in China Outage
  Windows 7 Being Retooled for Tablets
  YouTube Videos Can Be 15 Minutes

 Technology Marketplace
Cloud & Virtualization
Rackspace ®: The World's Leader in Hosting & Cloud Computing
 
Communications
Optimize 802.11n performance with Cisco CleanAir technology.
 
Compliance
Stand out from other IS Professionals and increase your earning potential.®.
Manage limitless content today—read EMC’s 15-minute guide to ECM.
 
Customer Service
Rackspace ® Managed Hosting - Experience Fanatical Support ®
 
Data Storage
Isilon scale-out storage is simple. Simple is smart.
 
Enterprise I.T.
Rackspace ®: The World's Leader in Hosting & Cloud Computing
Stand out from other IS Professionals and increase your earning potential.®.
 
Enterprise Software
Manage limitless content today—read EMC’s 15-minute guide to ECM.
 
Mobile Gadgets
White Paper Better your mobile work life with an enterprise digital assistant.
 
Mobile Industry News
Better your mobile work life with an enterprise digital assistant
 
Mobile Phones
Better your mobile work life with an enterprise digital assistant
 
Wireless Connectivity
Optimize 802.11n performance with Cisco CleanAir technology.
 
Navigation
CIO Today
Home/Top News | Enterprise Software | Enterprise Hardware | Network Security | Compliance | CRM Systems | Data Storage
Chips & Processors | Operating Systems | Communications | World Wide Web | Wireless Tech | Small Business | CIO Issues
Business Briefing | After Hours | Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 CIO Today. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.