[Home]   [Full version]  

MS Word Vulnerabilities Reported on Exploit Sites

Apr 11 ,Technology


Microsoft says it has found no attacks attempting to exploit the reported Office vulnerabilities, but it is continuing to investigate.

Microsoft is investigating public reports of vulnerabilities in Microsoft Office.

Reports of several new security holes in Microsoft Office have been made public on known exploit sites. The company did not release specific information about the vulnerabilities, citing potential risk to users.

"Microsoft is not aware of any attacks attempting to use the reported vulnerability or of customer impact at this time," said a spokesperson for the company, based in Redmond, Wash. "Microsoft will continue to investigate the public reports to help provide additional guidance for customers as necessary."

Postings about the vulnerabilities indicate that exploitation could lead to a program crash or the execution of arbitrary code.

Amol Sarwate, manager of vulnerability research at Qualys, a provider of on-demand security risk and compliance management solutions, based in Redwood Shores, Calif., said the widespread use of Microsoft Word makes the vulnerabilities even more threatening.

"Considering the prevalence of Microsoft Word, the fact that these vulnerabilities target unsuspecting users and also the consequence - total compromise of the system - I would say these vulnerabilities are very serious," Sarwate said. "In addition, zero-day targeted attacks - for CVE-2007-0870 - have amplified the need for a patch."

However, Sarwate added it is important to differentiate between proof-of-concept code and exploit code. "When POC - zero-day - code exists, is does raise the concern, but does not necessarily mean that exploit code will be released or that people will be exploited," he said.

Copyright 2007 by Ziff Davis Media, Distributed by United Press International

Related stories:

iPhones-Macintosh computers become apples of hackers' eyes
Security specialists said Saturday that hackers are taking increasing aim at iPhones and Macintosh computers as the hot-selling Apple devices gain popularity worldwide.
Security loophole found in Windows operating system
A group of researchers headed by Dr. Benny Pinkas from the Department of Computer Science at the University of Haifa succeeded in finding a security vulnerability in Microsoft's "Windows 2000" operating system.
Samba Repels Three Bugs with New Release
Vulnerabilities have been uncovered in Samba, the popular file-and-print software.
Java Security Traps Getting Worse
A year ago at JavaOne , Fortify Software Founder and Chief Scientist Brian Chess gave a presentation titled " 12 Java Technology Security Traps and How to Avoid Them ."
MS Patch Tuesday Fires Off 14 Critical Updates
System administrators will have to prioritize between updating Exchange and DNS servers while leaving equally important server and application updates dangling, experts say.
MS First Look: Word 2007 Not Bitten by Bugs
Microsoft says it is still investigating reports of posted security holes, but it has found no evidence that the Office 2007 suite is vulnerable to the reported flaws.
AJAX Apps Ripe Targets for JavaScript Hijacking
A pervasive vulnerability that allows an attacker to take over any Web browser and silently intercept sensitive data input occurs in Web 2.0 settings from Yahoo to ASP .Net to Google, security firm Fortify says.
Symantec Voices Security Concerns over Vista's Use of Tunneling Protocol
Security company Symantec says new research supports fears that Windows Vista's use of the IP tunneling protocol Teredo is potentially insecure.

News discussion:

Technology news

[Home]   [Full version]