Microsoft fixes critical holes in Windows, Word, Publisher

By Elinor Mills, CNET News.com
Wednesday, May 14, 2008 08:58 AM

Microsoft on late Tuesday issued security patches that plug critical holes in Microsoft Word and Publisher and a vulnerability in Windows for which a zero-day exploit has been available for weeks.

Zero-day exploits are considered particularly dangerous. While most security holes are plugged before an exploit is released, computers running vulnerable software for which there is a zero-day exploit already released are open to attack until the patch is available.

The critical Windows vulnerability was discovered in Microsoft Jet Database Engine 4.0. It allows an attacker to take complete control of an affected system, including installing malicious programs and modifying data.

Microsoft has acknowledged that people have been taking advantage of this vulnerability to compromise machines, said Amol Sarwate, manager of the vulnerability research lab at Qualys, which offers security as a service to corporations.

The other critical patches Microsoft released plug a hole in Microsoft Word and two holes in Microsoft Publisher that could allow attackers to remotely run code on an affected machine if the user were to open a specially crafted Word or Publisher file.

And Microsoft also fixed two holes rated "moderate" that would allow an attacker to shut down and restart the Microsoft Malware Protection Engine used in the company's security products including Windows Live OneCare and Windows Defender.

Missing from the patches was a fix for a vulnerability in the core Windows operating system for which there has been a zero-day exploit available for nearly a month, said Sarwate.

That unpatched vulnerability allows local users to escalate their privileges on a system and gain more access to resources and data. "It may look harmless," Sarwate says, but it not only gives insiders more control than they should have, but could enable outsiders to use the insider's escalated privileges to do damage.

"We were hoping to see a fix for that zero-day as well," he said.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.

Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Tech Jobs Now!

Replicating your infrastructure in a lab

Enterprise Servers & Storage

Learn two ways to replicate your current environment for testing and evaluation of new server platforms.


Read more »



  • HPC Applications

    Ever wondered if High Performing Computing systems really matter in our day-to-day world? HPC is not just reserved for the some obscure high-end scientific studies.

    David Scott from Intel Corporation gives you a quick tour to the process of developing HPC applications and the interesting world of HPC Applications in today's industries, including the lucrative oil industry.
    Play video


  • Maximize IT Spend: Business Acceleration

    How do you ensure your IT solutions are well integrated and streamlined across your enterprise? Rajendhiran Sanggaran from Oracle explains the processes and important considerations required to enable IT to fuel your business to the next level of growth.
    Play video

Tags

  1. attack
  2. attacks
  3. by
  4. cards
  5. china
  6. cisco
  7. companies
  8. concern
  9. critical
  10. cyberattack
  11. firefox
  12. google
  13. mac
  14. malware
  15. microsoft
  16. mobile
  17. online
  18. os
  19. prompts
  20. security
  21. server
  22. site
  23. threat
  24. trojan
  25. uk
  26. vista
  27. warning
  28. warns
  29. windows
  30. xp

What's the Indian definition of privacy?

Blog thumbnail

Two days back, I was having dinner at an aunt's place. She is a leading doctor. We were discussing my school friend, who happens to be her patient.

My aunt..... by Swati Prasad

Read more »