On CHOW: 10 good cheap liquors
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Sep 12, 2006 9:42:00 PM

Microsoft on Tuesday provided patches for three security flaws, but it does not have a fix yet for a Word 2000 vulnerability being exploited in cyberattacks.

As part of its monthly patch cycle, Microsoft released updates for Office and Windows users to repair a trio of security flaws, a tally that is notably fewer than in previous months. The software maker deems the Office problem "critical"--its most serious rating. The Windows problems have a lower severity rating.

"What's not there is more news than what is there, from what we can see," said Amol Sarwate, research manager at vulnerability management company Qualys."The first thing we noticed is a lack of a patch for the Microsoft Word vulnerability at large; they did not have enough time to produce a patch."

Microsoft last week warned that miscreants are using a previously unknown flaw in Word 2000 in cyberattacks. These attacks come by way of rigged Word documents attached to an e-mail or otherwise provided to the targeted person. Microsoft has said that it is working on a patch, but in a security advisory posted Sept. 6, it did not give an expected release date.

The yet-to-be addressed Word 2000 flaw is similar to the Office flaw that Microsoft did tackle on Tuesday. This vulnerability affects Microsoft Publisher in Office 2000, Office XP and Office 2003. An attacker could exploit it by crafting a malicious Publisher file and tricking someone into opening it, perhaps by hosting it on a Web site or sending it by e-mail, Microsoft said in security bulletin MS06-054.

"An attacker who successfully exploited this vulnerability could take complete control of an affected system," Microsoft said. "We recommend that customers apply the update immediately."

Publisher is Microsoft's desktop publishing application. The software maker recommends all Office users install the patch, regardless of whether Publisher is installed, because other Office applications use some of the same compromised files.

Of the two Windows vulnerabilities addressed by Tuesday's fixes, one could allow an attacker to remotely take control of a PC and the other could lead to information disclosure, Microsoft said.

A flaw in a protocol for data exchange in Windows XP could let an intruder hijack a vulnerable system by sending it a special data packet, according to Microsoft security bulletin MS06-052. However, the Pragmatic General Multicast, or PGM, protocol is part of Microsoft Message Queuing technology version 3.0, which is not enabled by default, Microsoft said.

The information disclosure vulnerability exists because of a cross-site scripting flaw in a part of Microsoft's Indexing Service, Microsoft said in security bulletin MS06-053. An attacker could exploit the flaw to run script code on a vulnerable PC. The script could spoof content, disclose information or take any action that the user could take on a specific Web site, Microsoft said.

The patches are available online and will be pushed out via Microsoft's Automatic Updates service. As for the unpatched Word flaw, Qualys recommends Windows users install multiple layers of security software and use caution when opening e-mail attachments.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 23 Talkback(s)
Sorry...
... but I seem to have missed the sarcasm tag... happy... (Read the rest)
Posted by: Wizard Prang Posted on: 09/18/06 You are currently: a Guest | | Terms of Use
Classic MS Craftmanship ... wink  michael_t | 09/12/06
ROTFLMAO , where is L.D. now  Intellihence | 09/12/06
re: layers  Arm A. Geddon | 09/12/06
Low Priority  bka1959 | 09/12/06
You got it right  DarthRidiculous | 09/12/06
They'd be better off using Apple products .  Intellihence | 09/12/06
Upgrade people  Suicida| | 09/12/06
Maybe they don't have a spare $300 laying around  DarthRidiculous | 09/12/06
Whatever you say No_Ax_To_Grind  Intellihence | 09/12/06
Errr... Did you read carefully next to the subject name?  Grayson Peddie | 09/12/06
I did , and I'll say it again , he's No-Ax  Intellihence | 09/12/06
Why should I?  voska | 09/13/06
Bumping the Priority  Yagotta B. Kidding | 09/12/06
No fix yet for Word 2000 flaw  Loverock Davidson | 09/12/06
Yes you got mentioned again , NIMROD , NIMCOMPOOP , MORON !  Intellihence | 09/12/06
But...But....  Shelendrea | 09/13/06
But nothing  Loverock Davidson | 09/13/06
What number fudging?  Shelendrea | 09/13/06
You don't understand, Shelendrea...  Zeppo9191 | 09/13/06
What you fail to understand, Loverock...  Zeppo9191 | 09/13/06
Completely Agree  TripleII | 09/13/06
Sorry...  Wizard Prang | 09/18/06
Patch will be ready as soon as Linux Geek finishes it  Boot_Agnostic | 09/13/06

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More