Procedure

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Sunday, December 9, 2012

Word vulnerability tops Microsoft's targets for Patch Tuesday

Posted on 4:44 PM by Unknown

A flaw in Microsoft Word ranks among the top security problems addressed by December's Patch Tuesday fixes, closing a hole that allows remotely executing malicious code on targeted machines regardless of whether users open the infected file. The bulletin is one of five marked critical by Microsoft in its advanced notification about vulnerabilities this month, and several security experts say the Word vulnerability is the top priority.
HELP: 11 (FREE!) Microsoft tools to make life easier 
FIRST LOOK: Surface RT 
"In this case we assume the 'critical' rating comes from Outlook, which can be configured to use Word to visualize documents in its preview pane," says Qualys CTO Wolfgang Kandek. "This is an automatic mechanism that does not require user interaction. In any case, this will be an important bulletin to watch out for."
The patch is rated as Important for Word 2003 SP3 and critical for Word 2007 SP2 & 3 and Word 2010 SP1.
This bulletin is similar to one issued earlier this year in that it deals with an issue with rich text format documents that can be parsed in the Outlook Preview Pane, thereby executing the vulnerability, says Alex Horan, a senior product manager with CORE Security .

"This is classic client side fodder, send an email with a job offer attached, or the new 401k plan attached and get control of a user's machine," says Paul Henry, a security and forensic analyst with Lumension, "plus if you exploit Bulletin 2, you get control of everything."
Bulletin 2 applies to all versions of Windows, including Windows 8 and Windows RT, Microsoft's two new operating systems. Given that it affects older operating systems as well, the vulnerability is likely with code from those earlier operating systems that is included in Windows 8 and RT.
"They don't say if this is a vulnerability on those systems that could be attacked over the network or if you need to be able to run code locally," says Horan, "but having an exploit that would potentially work against a wide range of windows systems is a great utility to have in your bag."
Still the actual danger may be limited, Henry says, and "because executing on this vulnerability would be time consuming and difficult, this is less important than the Word and [Internet Explorer] issues."

IE patch due

The IE problem threatens Target IE6 through 10, and provides a means for remotely executing code on a victim's computer. "This is a good one," says Horan, "a client side for Windows 7 and 8. A very attractive exploit [for] attackers to have."
He says that fixing a vulnerability found in Exchange 2007 SP3 and 2010 SP1 and 2 are important because these servers face the Internet and so are open to widespread attack. Fixing them may be troublesome. "You don't just randomly turn off email servers without generating howls of protest from your company," Horan says.
The same vulnerability is found in SharePoint and Microsoft Office Web Apps SP1, the latter of which may have less impact on enterprises because they don't use the platform widely, Kandek says.
The final critical bulletin is again a remote-code execution flaw affecting Windows XP SP3, Server 2003 SP2, Vista SP2, Server 2008 SP2, Windows 7 SP0 and 1, and Windows 2008 SP0 and 1. "Essentially, when Windows Explorer parses a file name, it hits this vulnerability," Henry says.
In looking back on 2012 Patch Tuesdays, Henry notes that the total number, 83, was fewer than the even 100 logged in 2011.
The number of critical and moderate bulletins remained about the same year to year, but the number of bulletins ranked important dropped from 63 to 46, he says.

source
Email ThisBlogThis!Share to XShare to Facebook
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • How to create a Windows 8 shutdown tile
    1. It starts, ironically, in Desktop mode, which you can reach by clicking/tapping the Desktop tile or pressing  Win-D  (that's the Wind...
  • How to change ur static ip
    To start off, you need a direct connection to your modem and computer. If you have a router, disconnect it and directly hook up your modem t...
  • Obama opposes Silicon Valley firms on immigration reform
    President Obama opposes an immigration reform bill backed by companies including Apple, Microsoft, and Adobe that would let U.S.-educated co...
  • Learn to build a PC in under two minutes
    Building a computer is a great way to get a custom configuration, save some money and have fun. In this how-to video, we'll show you how...
  • No Sound on Computer?
    No sound from computer? It is an annoying problem which bothers thousands of computer users. I got this problem once. When I used windows me...
  • Put your passwords in your pocket and take them everywhere you go
    My own personal favorite password manager,  Password Safe , isn't officially portable. But in practice, it sort of is. After you install...
  • The "Other" Facebook inbox you didn't know you had
    I know loads of Facebook users who never bother to check their notifications. You know, that area in the top-left corner of the screen, the ...
  • Three quick ways to ease your transition to Windows 8
    Indeed, for anyone brand new to Windows 8, anyone who's already familiar with an earlier version of Windows, that tile-based interface c...
  • Apple wins design patents for slide-to-unlock, original iPhone
    U.S. Patent and Trademark Office grants design patents for the contentious user interface asset. Apple was granted design patents today for ...
  • Windows Blue: How it could reinvent Windows (or sink Windows 8)
    With Windows 8's much ballyhooed launch barely a month behind us, alleged details of Microsofts  next  next-generation operating system ...

Categories

  • apple
  • browser
  • buy
  • christmas
  • computer information
  • crack
  • cyber monday
  • download
  • files
  • firewall
  • flash disk
  • font
  • graphene
  • hard disk
  • hidden
  • Hot News
  • how to
  • intel
  • Internet
  • Internet Explorer
  • iOS
  • iPad
  • Mac
  • Malware
  • nokia
  • notebook
  • play station 4
  • processor
  • removal
  • safe
  • samsung
  • samsung. microsoft
  • security
  • sony
  • ssd
  • The Meaning Is
  • tips
  • twitter
  • ubuntu
  • video card
  • virus
  • vulnerability
  • What to do
  • windows 8
  • windows7

Blog Archive

  • ►  2013 (90)
    • ►  October (2)
    • ►  September (6)
    • ►  August (3)
    • ►  July (4)
    • ►  June (5)
    • ►  May (9)
    • ►  April (14)
    • ►  March (11)
    • ►  February (17)
    • ►  January (19)
  • ▼  2012 (27)
    • ▼  December (22)
      • Suppliers hint at changes to MacBook Air -- Digitimes
      • Apple drops patent claim against Samsung Galaxy S3...
      • Fresh iPad rumor: Thinner, lighter version due in ...
      • MERRY CHRISTMAS
      • Will Samsung top Apple by withholding revolutionar...
      • Apple loses bid for permanent ban on Samsung phone...
      • Twitter rolls out option to download tweet archive
      • Why Microsoft redesigned Windows
      • One OS, three installation options: What's the bes...
      • Firefox gets an all-new private browsing mode
      • Google Maps returns to iOS as an app after Apple's...
      • Twitter takes on Instagram with new photo filters
      • Google Maps lets users explore NASA's 'Black Marble'
      • Word vulnerability tops Microsoft's targets for Pa...
      • Three reasons a Windows 8 laptop leads, MacBook lags
      • Another Apple touch-screen patent in trouble
      • Beyond quad-core: What's next for mobile processin...
      • 8 things Microsoft is doing wrong
      • Lock and encode your flash drives with BitLocker T...
      • Six awesome built-in Windows utilities no one know...
      • Windows Blue: How it could reinvent Windows (or si...
      • McAfee nabbed? His blog says maybe, following CNN ...
    • ►  November (5)
  • ►  2010 (4)
    • ►  June (1)
    • ►  January (3)
  • ►  2009 (32)
    • ►  December (2)
    • ►  November (11)
    • ►  October (11)
    • ►  September (2)
    • ►  March (2)
    • ►  February (4)
  • ►  2008 (39)
    • ►  October (2)
    • ►  September (2)
    • ►  August (1)
    • ►  June (1)
    • ►  May (3)
    • ►  March (1)
    • ►  February (7)
    • ►  January (22)
  • ►  2007 (46)
    • ►  December (8)
    • ►  November (9)
    • ►  September (4)
    • ►  August (2)
    • ►  July (9)
    • ►  June (14)
Powered by Blogger.

About Me

Unknown
View my complete profile