Search Perform an advanced search query SOFTPEDIA
 
SOFTPEDIA
Updated one minute ago
HomeSubmit a program for being reviewedAdvertise on our websiteGet help on surfing our websitesSend us your feedbackGet information about our XML/RSS backend and how to use itBrowse the news archiveVisit our discussion forumVizitati forumul in limba romana



KLIP
  1. HOME
  2. SCIENCE
  3. TECHNOLOGY
  4. WEBMASTER
  5. SECURITY
  6. MICROSOFT
  7. LINUX
  8. APPLE
  9. GAMES
  10. TELECOMS
  11. REVIEWS
  12. LIFE & STYLE
  13. EDITORIALS
  14. INTERVIEWS
  15. RSS
Welcome!
Hello, Guest

Login if you have a Softpedia.com account.

Otherwise, register for one.

PATCHES AND VULNERABILITIES

Latest Vulnerability Attacks Steer Clear of Vista SP1, but Not XP SP3

- Exploits target the Microsoft Jet Database Engine

By: Marius Oiaga, Technology News Editor

The latest attacks targeting vulnerabilities in Microsoft's software products have steered clear of Windows Vista Service Pack 1. And despite the fact that the Redmond company touted security advancements when it introduced SP1 for Vista, available as of March 18, the fact of the matter is that neither Windows Vista RTM is impacted by exploits targeting a buffer overrun vulnerability in the Microsoft Jet Database Engine. The security flaw can be exploited through Word, Microsoft informed.

Bill Sisk, Microsoft Security Response Center Communications Manager, wanted to clarify the
situation and revealed that the company had detected "very limited, targeted attack exploiting a vulnerability in Microsoft Jet Database Engine. Our initial investigation has shown that this vulnerability affects customers using Microsoft Word 2000 Service Pack 3, Microsoft Word 2002 Service Pack 3, Microsoft Word 2003 Service Pack 2, Microsoft Word 2003 Service Pack 3, Microsoft Word 2007 and Microsoft Word 2007 Service Pack 1 on Microsoft Windows 2000, Windows XP, or Windows Server 2003 Service Pack 1."

Apparently, in addition to Vista RTM and Vista SP1, Windows Server 2003 SP2 is also not vulnerable. This because all three operating systems feature a Microsoft Jet Database Engine that is not impacted by the buffer overrun vulnerability. However, because of the general Windows XP reference made by Microsoft, it is clear that both SP1, SP2 and even the upcoming Service Pack 3 are vulnerable. Still, the company claims that the risk is limited.

"The attacker first created a malicious Access file exploiting the unpatched CVE-2007-6026. Next, to bypass Outlook restrictions mentioned before, the .mdb file was renamed with a different file extension (.asd, a video format). With this trick, as clearly showed in the following picture, Access files are no longer blocked by Outlook because the protection triggers just on the file extension and not on the file format itself. The attacker needs only to find a trick to force the MS Jet library to open the file and trigger the vulnerability that will run the malicious shellcode. Some social engineering and a little help from Office applications will work out well in this specific attack," explained Elia Florio, Symantec Security Response Engineer.

MORE RELATED ARTICLES: Free SP1 Adds VoIP Capabilities to Microsoft Response Point Free Vista SP1 and XP SP3 Support Free Vista SP1 Deployment Toolkit Available – Nothing for XP SP3 Microsoft Hints Windows 7 to Be the First Modular Windows Client Nail Service Pack 1 (SP1) Down on Windows Vista RTM Forever Will the Real Availability Date for XP SP3 Please Stand Up New Kernel for Vista SP1, New Kernel for Windows 7 Vista Ultimate SP1 vs. OS X Leopard 10.5.2 vs. Ubuntu 7.10 Get Ready for the Next Wave of Windows Vista SP1 RTM 8 Reasons Why You Can't Get Vista SP1 RTM
 
Comments | Link here | Subscribe
Print | Send to friend
Today's News | Yesterday's News

Search:


24th March 2008, 17:28 GMT | Copyright (c) 2008 Softpedia | Contact:
Read by 1,622 user(s) | Rating: | 6 vote(s) so far | Cast your vote:
Latest Vulnerability Attacks Steer Clear of Vista SP1, but Not XP SP3 - USER OPINIONS




We are sorry, there are no opinions available for this article.






SHARE YOUR OPINION ABOUT Latest Vulnerability Attacks Steer Clear of Vista SP1, but Not XP SP3

Since you are not logged on, your comments will have to be approved before being displayed.
Click here to login, or register.
Your Name:
Your Email:
Type in the result:
Your Opinion:
 


DO YOU WANT TO CONTACT US?  

If you have some comments or you want to send us some information you can send us an email directly to .
You can use the form below for the same purpose.
Your full name: (at least 3 characters)
Your email address: (at least 5 characters)
Message subject: (at least 5 characters)
Message text:
(at least 10 characters)
Type in the result:
 
 



© 2001 - 2008 Softpedia. All rights reserved.
Softpedia™ and Softpedia™ logo are registered trademarks of SoftNews NET SRL.
Copyright Information | Privacy Policy | Terms of Use | Contact Softpedia | Update your software | Archive