NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Microsoft Confirms Fifth Office Zero-Day Vulnerability

In Security Advisory (932553)

By Marius Oiaga, Technology News Editor

3rd of February 2007, 11:10 GMT

Adjust text size:


Microsoft Office vulnerabilities keep pouring in. The Redmond Company has now confirmed the existence of the fifth zero-day unpatched vulnerability affecting various Office suites since
December 2006. Currently, Microsoft has yet to issue security patches addressing any of the five security holes in Office.

Security Program Manager Alexandra Huft, from the Microsoft Security Response Center, has delivered a few details concerning the new zero-day. "I wanted to let people know about a new issue that we've activated our Software Security Incident Response Process (SSIRP) for: we have some information we can share from the investigation so far and I wanted to share it with you. This involves an issue that is currently being exploited using Excel documents. However, the issue can affect all Office documents," informed Huft.

In Security Advisory (932553), Microsoft reveals that via the newly discovered vulnerability, an attacker could achieve remote code execution on a compromised machine. Microsoft Office 2000, Microsoft Office XP, Microsoft Office 2003, and Microsoft Office 2004 for Mac are all affected by the Excel vulnerability. According to Microsoft, Office 2007 is safe.

Microsoft warned that it has detected limited and targeted the attack using the vulnerability in Excel as an attack vector, but additionally informed that other Office applications are also vulnerable.

A user has to first execute a malformed Office file in order to become infected. Microsoft's only workaround is a piece of advice for Office users: "do not open or save Office files that you receive from un-trusted sources or that you receive unexpectedly from trusted sources. This vulnerability could be exploited when a user opens a specially crafted Office file."
Read by 1,221 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.8/5) 5 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Microsoft Debuts the 2007 Patching Season

It's Raining Word Vulnerabilities

Mac BU's General Manager Talks About XML Converters

4 January Microsoft Security Bulletins Discontinued

Vista Is "Best Of CES"

Highly Critical Microsoft Word Zero-Day

Microsoft Confirms Word 2000 Zero-Day

Office 2007 Crack

Insight on the Office 2008 for Mac

Download January 2007 Security Releases ISO Image

Fingerprint Windows Vista

Simplify Windows Vista and Office Deployments

8 Microsoft Security Bulletins in January

Windows Vista Is Unaffected by the VML Vulnerability

Internet Explorer 7 vs. Firefox 2.0

Microsoft Unveils Office 2008 for Mac

Early Deployments of Vista and Office = High Risk

Top Security Companies Align to Support Windows Vista

The 12 to Guard Vista

Security Insight on Windows Home Server

Microsoft Is Testing a Subscription-Based Payment System for Office 2003

Test Drive Office 2007 Online

Microsoft Is Already Running Internet Explorer 8.0

Windows Vista & IE7 Vulnerabilities Cost from $8,000 to $12,000

Microsoft Phonetically Corrects Excel Patch

Microsoft's Closed Doors Security Summit

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM