NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Microsoft Office Swims in Zero-Day Infested Waters

The Redmond Company claims Office 2007 is not affected

By Marius Oiaga, Technology News Editor

12th of April 2007, 10:57 GMT

Adjust text size:



Enlarge picture
Microsoft's Office productivity suite is swimming in waters that are infested, or dare I say, infected with zero-day exploits. At this point in time Microsoft only managed to deny the fact that attacks exploiting
three new zero-day vulnerabilities in Office apply to version 2007 of its suite. Attacks impacting the newly discovered Office vulnerabilities came on the heels of the Microsoft April patch cycle.

On April 9, 2007 McAfee "saw the release of several Microsoft Office zero-day exploits in security forums. Some of these flaws may allow for remote code execution. McAfee Avert Labs is investigating all these zero-days. Today is Patch Tuesday for April. So, yes: this is yet another time that zero-day flaws have been published around a Patch Tuesday, possibly to maximize the public's exposure to these flaws until the next month's Patch Tuesday," revealed McAfee researcher Karthik Raman.

Microsoft confirmed the existence of the three vulnerabilities and announced that it is currently investigating the issues. However, the Redmond Company emphasized the fact that Office 2007 products are not impacted, following the initial analysis of the vulnerabilities. Microsoft denied the existence of attacks exploiting any of the zero-day Office vulnerabilities.

"Further research by Avert Labs indicates that all but one of the Office zero-days reported yesterday result in denial of service. There is one heap-overflow flaw that might be exploited for code execution. Avert Labs has been analyzing proof-of-concept code for a zero-day vulnerability in Microsoft Windows's handling of HLP files. This is another heap-overflow flaw that might be exploited for code execution," Raman added.

TAGS:

Office | vulnerability | McAfee
Read by 850 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.3/5) 3 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Single Language Packs Available for Office 2007

Who Knew Office 2007 Could Be Funny?

Microsoft Office 2007 Basic, Standard, Small Business, Professional and Ultimate - Comparison

Some Versions of Windows XP SP2 and Office 2007 Have Already Expired

The Next Microsoft Operating System Is Not Windows - It's SharePoint

Microsoft Needs YOU, to Support Open XML

Microsoft Building a Google Apps Killer

Microsoft Dynamics NAV 5.0 Drops March 31, 2007

Microsoft Dreams of a Chinese Utopia

Microsoft: Vista Has Changed the Piracy Game

Zero Reasons to Upgrade to Windows Vista? Here's 30 of Them!

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM