More Microsoft Security Issues

Search

New member
Joined
Sep 21, 2004
Messages
2,617
Tokens
Microsoft on Wednesday warned of several flaws in its ubiquitous Office products, the most serious of which could allow an attacker to take control of a user's computer.

• Microsoft Patches Office 2000 Bug
• Microsoft Still Bugged by Software Problems

Deemed "critical" is a flaw in Visual Basic for Applications (VBA), a technology that is part of Microsoft Office products and used to run customized applications on top of Office. A flaw exists in the way VBA checks the properties of a document when it is opened in an Office application, potentially allowing an attacker to run code on a victim's computer, Microsoft said in Security Bulletin MS03-037.

To exploit the flaw, an attacker would have to get a victim to open a specially-crafted document. This could be any document type that supports VBA, including Word, Excel, or PowerPoint documents, Microsoft said. Also, if Word is used as the e-mail editor for Outlook, the default setting in Office XP/2002, an attacker could strike via e-mail. The attack would only be successful if the recipient forwards or replies to the e-mail message, Microsoft said.

The VBA flaw affects Access, Excel, PowerPoint, and Word in Microsoft Office 97, 2000, and XP/2002 as well as Word 98, Project 2000 and 2002, Publisher 2002, Visio 2000 and 2002, Works Suite 2001, 2002, and 2003, plus several Microsoft Business Solutions products that also include VBA, Microsoft said.

Microsoft urges users of the affected products to patch at their earliest available opportunity. Users of more than one affected product may have to apply multiple software fixes, Microsoft said.

More Flaws Found

In addition to the VBA flaw, Microsoft also warned of three more security vulnerabilities in Office products, two carrying an "important" severity rating and one "moderate."

Rated important is a flaw in Word that could result in macros running automatically, instead of asking the user first or going by the level of macro security a user has set, Microsoft said in Security Bulletin MS03-035.

Macros are executable code meant to automate commonly-performed tasks and can perform any action a user can on a PC. An attacker could create a malicious document that automatically runs a macro when opened, Microsoft said.

The flaw affects Word versions 97, 98, 2000, and XP/2002 as well as the Works Suite versions 2001, 2002, and 2003, Microsoft said.

Also important is a buffer overrun vulnerability in the WordPerfect Converter that is part of Office 97, 2000, and XP/2002 as well as Word 98, FrontPage 2000 and 2002, Publisher 2000 and 2002, and the Works Suite versions 2001, 2002, and 2003, Microsoft said in Security Bulletin MS03-036.

The converter does not correctly validate certain parameters when opening a WordPerfect document. As a result, an attacker could craft a special WordPerfect document that would allow code to run on a computer when opened with an application that uses the converter, Microsoft said.

Final Flaw

The last of the four flaws that affect Office detailed Wednesday is rated moderate and affects the Access Snapshot Viewer, a tool used to view Access databases without Access installed on a computer, Microsoft said in Security Bulletin MS03-038.

Access Snapshot Viewer comes as part of all versions of Office, but is not installed by default. It is also offered online so users who do not have Access can still view Access databases, Microsoft said.

The flaw lies in an ActiveX control used by the viewer. To exploit the flaw, an attacker would have to lure a user to a Web page containing special code, Microsoft said.

Microsoft has a four-tiered system for rating security issues. Vulnerabilities that could be exploited to allow malicious Internet worms to spread without user action are rated critical. Issues that are rated important could still expose user data or threaten system resources. Vulnerabilities rated moderate are hard to exploit because of factors such as default configuration or auditing, or difficulty of exploitation, according to Microsoft.
 
Joined
Sep 21, 2004
Messages
28,775
Tokens
F'ing junk....Thanks for the FYI.

(This means to hit windowsupdate.com if you haven't since yesterday.)
 

Another Day, Another Dollar
Joined
Mar 1, 2002
Messages
42,730
Tokens
DirectX 9.0b End-User Runtime*
Download size: 293 KB, < 1 minute
DirectX 9.0b includes security and performance updates. Download now to get the latest DirectX updates. After you install this item, you may have to restart your computer. Once you have installed this item, it cannot be removed. Read more...

* Must be installed separately from other updates

This item has been selected.AddRemove
820291: Recommended Update (Windows XP)
Download size: 1.0 MB, < 1 minute
This update adds a new icon for the “Set Program Access and Defaults” feature to the second column of the Start menu. It also adds a “Help” button and help content. After you install this item, you may have to restart your computer. Read more...

This item has been selected.AddRemove
Recommended Update for Windows XP SP1 (817778)
Download size: 1.2 MB, < 1 minute
The Advanced Networking Pack for Windows XP is a set of platform technologies designed for the use and deployment of advanced networking solutions. It includes an updated IPv6 stack supporting NAT traversal for IPv6 applications, an IPv6 firewall, and a peer-to-peer platform for writing distributed solutions. After you install this item, you may have to restart your computer. Read more...

This item has been selected.AddRemove
814995: Recommended Update
Download size: 994 KB, < 1 minute
This update addresses the "Some Application Compatibility Fixes Stop Working After You Install the 328310 Update" issue in Windows XP, and is discussed in Microsoft Knowledge Base (KB) Article 814995. Download now to update application compatibility fixes. After installing this update, you may have to restart your computer. Read more...

This item has been selected.AddRemove
Microsoft .NET Framework version 1.1
Download size: 23.1 MB, 2 minutes
The .NET Framework is a component of the Windows operating system. For developers, the .NET Framework makes it easy to rapidly create powerful software that maximizes performance, scalability, opportunities for integration, reliability, security, and the end-user experience, while minimizing the costs of deployment and management. After you install this item, you may have to restart your computer. Read more...

This item has been selected.AddRemove
Q322011: Recommended Update
Download size: 417 KB, < 1 minute
This update addresses the "Preview is Unavailable in Fax Console with Windows XP SP1" issue in Windows XP, and is discussed in Microsoft Knowledge Base (KB) Article Q322011. Download now to use Preview in the Fax Console with Windows XP. After you install this item, you may have to restart your computer. Read more...

This item has been selected.AddRemove
Q327405: Recommended Update (Windows XP Home Edition)
Download size: 985 KB, < 1 minute
This update provides new information about security and privacy. Download now to learn what steps you can take to help protect the privacy of your personal information and the security of your computer. Read more...

This item has been selected.AddRemove
327979: Recommended Update
Download size: 862 KB, < 1 minute
This update addresses the "Game Stops Responding (Hangs) or Quits Unexpectedly When Introductory Video Clip Is Played" issue in Windows XP, and is discussed in Microsoft Knowledge Base (KB) Article 327979. Download now to prevent your computer from not responding during video playback. Read more...

This item has been selected.AddRemove
Q810243 Update: Watch television shows recorded by Media Center PCs on other Microsoft Windows XP PCs
Download size: 587 KB, < 1 minute
This supplement is an update to Microsoft® Windows® XP Service Pack 1 (SP1). Users who want to play Media Center PC digital recording files (.dvr-ms) in any other Windows XP SP1 system should download this update. You must use a player that supports DirectShow® and have a Windows XP compatible DVD decoder installed. Windows Media® Player Series 9 is an example of a DirectShow player that can support .dvr-ms files with this download. Read more...

This item has been selected.AddRemove
Q282010: Recommended Update for Microsoft Jet 4.0 Service Pack 7 (SP7) - Windows XP
Download size: 215 KB, < 1 minute
Microsoft Jet 4.0 Service Pack 7 (SP7) provides the latest updates to the Jet 4.0 database engine with Windows XP, and is discussed in Microsoft Knowledge Base Article Q282010. Download now to get the most current updates for Jet 4.0. After you install this item, you may have to restart your computer. Read more...

This item has been selected.AddRemove
Windows Error Reporting: Recommended Update (Windows XP)
Download size: 346 KB, < 1 minute
This update will enable the user to automatically view responses to Windows error reports. After submitting an error report, if information relating to the crash event is available such as a fix, workaround, or other information, then the response may be viewed immediately and automatically. After you install this item, you may have to restart your computer. Read more...

This item has been selected.AddRemove
Microsoft Windows Journal Viewer (Windows XP)
Download size: 7.0 MB, < 1 minute
This accessory allows people who do not have a computer running Windows XP Tablet PC Edition to view files that were created in Microsoft Windows Journal on a Tablet PC. Read more...

This item has been selected.AddRemove
Windows MovieMaker 2
Download size: 8.1 MB, < 1 minute
Windows Movie Maker 2 is an update to previous versions of Windows Movie Maker. New features such as a new user interface, wizards, transitions, effects, titles, and AutoMovie make creating home movies easier. Windows Movie Maker 2 also takes advantage of the latest Windows Media® 9 Series audio and video codecs. After you install this item, you may have to restart your computer. Once you have installed this item, it cannot be removed. Read more...

This item has been selected.AddRemove
Windows Media Player 9 Series (Windows XP)*
Download size: 9.7 MB, < 1 minute
Enjoy fast and flexible music and video playback with Microsoft (r) Windows Media(r) Player 9 Series. Over 120 new features, including Fast Streaming, quicker startup, and smart jukebox features make this the best Player yet. Optimized for Windows XP. After you install this item, you may have to restart your computer. Read more...

* Must be installed separately from other updates

This item has been selected.AddRemove
 

Cui servire est regnare
Joined
Sep 21, 2004
Messages
11,033
Tokens
Take it all, its best to have the most up to date patches/software running. Keep your system humming in synch with everything.
 

New member
Joined
Sep 21, 2004
Messages
852
Tokens
Don't use outlook or outlook express and you will sail through 99% of this shit. Hackers know bill has most of the market locked down. Who do you think they are going to target?
 

Old Fart
Joined
Sep 21, 2004
Messages
2,395
Tokens
If I install the latest Windows Media Play 9.-, will it have any negative on the latest Real One Player?

I prefer the Real One, because of the baseball broadcasts and don't want to mess it up with the newer Windows version????????????
 

Another Day, Another Dollar
Joined
Mar 1, 2002
Messages
42,730
Tokens
oldmantime,

Since I did this yesterday, you will be able to select what you want to play in Media vs real one during the update.
 

Old Fart
Joined
Sep 21, 2004
Messages
2,395
Tokens
Thanks General

One can never be too carefull with Windows stuff. The audeo player is one thing they don't have a monopoly on--so I'm carefull with their toys.
 

Forum statistics

Threads
1,119,858
Messages
13,574,195
Members
100,877
Latest member
businesstalkmag
The RX is the sports betting industry's leading information portal for bonuses, picks, and sportsbook reviews. Find the best deals offered by a sportsbook in your state and browse our free picks section.FacebookTwitterInstagramContact Usforum@therx.com