On CBS News: Check out today's news on Barack Obama
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers, News.com
Posted on ZDNet News: Sep 12, 2006 9:42:00 PM

Microsoft on Tuesday provided patches for three security flaws, but it does not have a fix yet for a Word 2000 vulnerability being exploited in cyberattacks.

As part of its monthly patch cycle, Microsoft released updates for Office and Windows users to repair a trio of security flaws, a tally that is notably fewer than in previous months. The software maker deems the Office problem "critical"--its most serious rating. The Windows problems have a lower severity rating.

"What's not there is more news than what is there, from what we can see," said Amol Sarwate, research manager at vulnerability management company Qualys."The first thing we noticed is a lack of a patch for the Microsoft Word vulnerability at large; they did not have enough time to produce a patch."

Microsoft last week warned that miscreants are using a previously unknown flaw in Word 2000 in cyberattacks. These attacks come by way of rigged Word documents attached to an e-mail or otherwise provided to the targeted person. Microsoft has said that it is working on a patch, but in a security advisory posted Sept. 6, it did not give an expected release date.

The yet-to-be addressed Word 2000 flaw is similar to the Office flaw that Microsoft did tackle on Tuesday. This vulnerability affects Microsoft Publisher in Office 2000, Office XP and Office 2003. An attacker could exploit it by crafting a malicious Publisher file and tricking someone into opening it, perhaps by hosting it on a Web site or sending it by e-mail, Microsoft said in security bulletin MS06-054.

"An attacker who successfully exploited this vulnerability could take complete control of an affected system," Microsoft said. "We recommend that customers apply the update immediately."

Publisher is Microsoft's desktop publishing application. The software maker recommends all Office users install the patch, regardless of whether Publisher is installed, because other Office applications use some of the same compromised files.

Of the two Windows vulnerabilities addressed by Tuesday's fixes, one could allow an attacker to remotely take control of a PC and the other could lead to information disclosure, Microsoft said.

A flaw in a protocol for data exchange in Windows XP could let an intruder hijack a vulnerable system by sending it a special data packet, according to Microsoft security bulletin MS06-052. However, the Pragmatic General Multicast, or PGM, protocol is part of Microsoft Message Queuing technology version 3.0, which is not enabled by default, Microsoft said.

The information disclosure vulnerability exists because of a cross-site scripting flaw in a part of Microsoft's Indexing Service, Microsoft said in security bulletin MS06-053. An attacker could exploit the flaw to run script code on a vulnerable PC. The script could spoof content, disclose information or take any action that the user could take on a specific Web site, Microsoft said.

The patches are available online and will be pushed out via Microsoft's Automatic Updates service. As for the unpatched Word flaw, Qualys recommends Windows users install multiple layers of security software and use caution when opening e-mail attachments.

  • Talkback
  • Most Recent of 23 Talkback(s)
Sorry...
... but I seem to have missed the sarcasm tag... :)... (Read the rest)
Posted by: Wizard Prang Posted on: 09/18/06 You are currently: Logged In | Log out
Classic MS Craftmanship ... ;-) michael_t   | 09/12/06
ROTFLMAO , where is L.D. now Beyond the Vista, a Snow Leopard is stalking .   | 09/12/06
re: layers Arm A. Geddon   | 09/12/06
Low Priority bka1959   | 09/12/06
You got it right Argonnj   | 09/12/06
They'd be better off using Apple products . Beyond the Vista, a Snow Leopard is stalking .   | 09/12/06
Upgrade people Suicida|   | 09/12/06
Maybe they don't have a spare $300 laying around Argonnj   | 09/12/06
Whatever you say No_Ax_To_Grind Beyond the Vista, a Snow Leopard is stalking .   | 09/12/06
Errr... Did you read carefully next to the subject name? Grayson Peddie   | 09/12/06
I did , and I'll say it again , he's No-Ax Beyond the Vista, a Snow Leopard is stalking .   | 09/12/06
Why should I? voska   | 09/13/06
Bumping the Priority Yagotta B. Kidding   | 09/12/06
No fix yet for Word 2000 flaw Loverock Davidson   | 09/12/06
Yes you got mentioned again , NIMROD , NIMCOMPOOP , MORON ! Beyond the Vista, a Snow Leopard is stalking .   | 09/12/06
But...But.... Shelendrea   | 09/13/06
But nothing Loverock Davidson   | 09/13/06
What number fudging? Shelendrea   | 09/13/06
You don't understand, Shelendrea... Zeppo9191   | 09/13/06
What you fail to understand, Loverock... Zeppo9191   | 09/13/06
Completely Agree TripleII   | 09/13/06
Sorry... Wizard Prang   | 09/18/06
Patch will be ready as soon as Linux Geek finishes it Boot_Agnostic   | 09/13/06

What do you think?

advertisement
advertisement

The Green Enterprise

advertisement
Click Here