NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > The Office System

The Office System


Office 2007 Service Pack 2 More Secure than SP1

Vista not the only product with 50% less vulnerabilities

By Marius Oiaga, Technology News Editor

27th of November 2008, 12:46 GMT

Adjust text size:


Office
Enlarge picture
In order to support applauding the security enhancements in Windows Vista, Microsoft has played the vulnerability counting game on more than one occasion, comparing the volume of security flaws in the latest edition of the Windows client with previous releases, and even with Linux and Mac OS X.

However, Windows Vista is not the sole example of the Redmond company managing to slash the number of vulnerabilities in half. The same is the case with the software giant's other flagship product, Office 2007. David LeBlanc, a senior software development engineer at Microsoft, offered internal statistics from Microsoft on a range of Office editions, taking into consideration CVE entries and bulletin count from 9/18/2007 to 11/17/2008.

“While we did a lot of good work to try and make Office 2003 more secure than previous versions, against the attacks we're seeing in 2007, it wasn't any better than Office XP,” LeBlanc stated.

“Now, if you factor in huge amounts of work (no magic, no silver bullet, just lots and lots of work) that we did fixing fuzz bugs in Office 2007 and Office 2003 SP3, it looks like we've cut the incoming vulnerability rate by approximately half. If we look at it app-by-app, I think PowerPoint is a clear winner – they've had 5 CVE entries for older versions and only 1 for PowerPoint 2007 since 1/1/2007! Word has also done very well, dropping from 11 and 12 CVE entries, in prior versions, to only 2 for Word 2007, over the same period.”

The CVE count for Office 2007 SP1 was of just 16 items in approximately one year, while that for the RTM version of the system was of 19. In fact, Office 2003 SP3 and Office 2007 RTM were almost on a par in this regard. However, for releases preceding Office 2003 SP3, the CVE count was almost double. LeBlanc stated that Microsoft was committed to continuing to improve security for the Office System with the next release, namely SP2 for Office 2007.

Office CVE Count
Enlarge picture
“It will be interesting to see how much additional gain that gives us. I'd like to see us do even better over time – while we've clearly made some significant gains, we still have more work remaining. We are currently doing about as many fuzzing iterations per weekend as we're required to do to meet SDL requirements for the entire product cycle (to be fair, the requirement is for clean runs, and we're not there yet, and when we do get there, we use a different fuzzer). We've done twice as many fuzz iterations against Office 2007 SP2 as we did against Office 2007 during the entire product cycle, and 4x more against Office 14 than against Office 2007,” LeBlanc stated.

Office 2007 SP1 is available for download here.

Office 2003 SP3 is available for download here.

TAGS:

Office 2007 | SP1 | SP2 | Office 2003 | SP3
Read by 3,276 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
NOT RATED 0 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2010 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Fake Windows “Antivirus” Code Infected 1 Million Computers

New President for Microsoft Russia

Microsoft FusionX Appliance

Microsoft: Banks Need to Adapt to the Customer's Digital Lifestyles

Silverlight 3 in 2009

Exchange Online and SharePoint Online Go RTW

Windows 7 – 20 Features to Make Users Forget Vista SP1/SP2 and XP SP3

Windows Live Wave 3 New Icons and Graphical User Interface

Visual Studio 2010 and .NET Framework 4.0 Training Kit

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM