Newsletter:

Skip Navigation LinksHome > News > Security > Microsoft leaves major Word flaws unpatched

Microsoft leaves major Word flaws unpatched

By Matt Chapman
11 January 2007 03:04PM
Tags: microsoft | word

Still no fix for three critical vulnerabilities.

Microsoft's latest Patch Tuesday updates have failed to block known software flaws in Word that are currently being exploited. 

Redmond has known about three zero-day flaws affecting its Word software since November and December last year, but has failed to fix them in the previous two patch releases. 

Security firm McAfee said that it had expected Microsoft to patch the three Word vulnerabilities in this release. 

"Business applications continue to be a prime target for malicious code writers, which is evident in today's vulnerabilities patched by Microsoft," said Dave Marcus, security research and communications manager at McAfee's Avert Labs.

"Coverage for this vector of threats continues to be a primary area of research for McAfee and we recommend that users of these applications take extra precautions to protect their systems."

Three of the four patches released did fix 'critical' vulnerabilities in Microsoft Outlook, Excel and the Vector Markup Language that could allow malicious code to be run on a user's machine.

Microsoft had originally announced eight updates for January, but revised that figure to four a few days later.

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch





Product Reviews

Star Rating
The AdventNet Manage-Engine Password Manager Pro provides a complete system for password management in one...
Star Rating
The Cyber-Ark Enterprise Password Vault, or EPV, is a high-end password management powerhouse.
Star Rating
The Hitachi ID-Archive sets its focus on password randomisation.
Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Unified Communications Podcast Centre

TopTopics
(6648) -  internet
(6417) -  iinet
(6392) -  copyright
(6392) -  afact
(5990) -  servers
(5990) -  mipi
(4809) -  telstra
(4499) -  broadband
(4441) -  nbn
(2945) -  internode
(2483) -  microsoft
(1885) -  network
(1473) -  data
(1409) -  software
(1365) -  google