NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Office 2007 Is Strong as a Rock

According to the Redmond Company

By Marius Oiaga, Technology News Editor

13th of April 2007, 11:09 GMT

Adjust text size:


Office 2007
Enlarge picture
Microsoft is strongly disputing claims of three zero-days vulnerabilities affecting the 2007 Office System. According to the Redmond Company, the initial investigation of three different
Office 2007 issues reported failed to confirm the fact that users are exposed to attacks.

Mati Aharoni of Offensive-Security.com, in Israel, has made available malformed Word documents together with proof of concept code for the three Office 2007 vulnerabilities. The examples were posted on the Milw0rm and SecurityVulns.com websites. Microsoft's reaction has prompted Aharoni to accuse the Redmond Company of confusion.

"A few days ago I released a few proof of concepts to full disclosure doc files which crashed my Word 2007, and a hlp file which when analysed looked like a classic heap overflow, with a twist or two. It looks like there is some confusion by Microsoft - who for some reason are not able to reproduce these bugs. I've recieved many mails from full disclosure members confirming the crash. Someone even mentioned Word 2004 crashing on OSX. So just to make things clear - here are some screenshots of the crashes. I fully hope that Microsoft will find the resources to figure this out," Aharoni commented.

A representative of the Microsoft Security Response Center claimed that the examples offered by Aharoni do not demonstrate in any manner the existence of vulnerabilities in Word 2007 or in the Office System for that matter. Accordingly, Microsoft will not label any of the issues reported by Aharoni as security flaws.

"In fact, the behavior observed in Microsoft Word 2007 in this instance is a by-design behavior that improves security and stability by exiting Microsoft Word when it has run out of options to try and reliably display a malformed Word document," a MSRC spokeswoman told ComputerWorld even if Aharoni provided screenshots of Word 20076 crashes as proof of the validity of his findings.

TAGS:

Office 2007 | vulnerability | Microsoft
Read by 1,479 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.6/5) 12 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Single Language Packs Available for Office 2007

Who Knew Office 2007 Could Be Funny?

Microsoft Office 2007 Basic, Standard, Small Business, Professional and Ultimate - Comparison

Microsoft Office System 2007 Virtual Lab

Microsoft's Messaging and Conferencing Server Goes Into Public Beta

Microsoft Office Swims in Zero-Day Infested Waters

The First Universal Office for Mac Goes Beta

Exchange Server 2007 SP1 Beta Available

Some Versions of Windows XP SP2 and Office 2007 Have Already Expired

Windows Vista False Start and Failed Expectations

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM