No fix yet for zero-day flaw in Word

By Joris Evers, CNET News.com
Friday, December 08, 2006 09:46 AM

As part of its monthly patch cycle, Microsoft plans to release next week six security bulletins, at least two of them deemed "critical."

Five of the security bulletins will include fixes for vulnerabilities in Windows, Microsoft said in a notice on its Web site Thursday. The sixth bulletin will offer an update for Visual Studio, it said.

Microsoft has not scheduled a patch for Office. Earlier this week, it warned that a yet-to-be-patched security hole in multiple versions of Word--part of the Office suite--is being exploited in cyberattacks. The software maker is working on a security update, but apparently needs more time.

The company did not specify how many flaws Tuesday's updates will address or in which components of Windows the holes lie. The Visual Studio update could offer a patch for a zero-day vulnerability in the developer tools that was made public last month.

The company has tagged the security hole in the developer tool as "critical," its highest risk rating. Critical vulnerabilities typically can allow a worm to spread or allow a Windows system to be fully compromised with minor or no interaction from the person using it. However, it did not offer details on exactly what will be fixed in Visual Studio.

Also next week, Microsoft will release an updated version of its Windows Malicious Software Removal Tool. The program detects and removes common malicious code placed on computers.

Last month, the software maker delivered six security bulletins, five of which were described as critical.

Microsoft gave no further information on the upcoming bulletins, other than stating that some of the Windows fixes may require restarting the computer or server.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web