Word flaw left out of Patch Tuesday

By
Follow google news

Actively targeted vulnerability not included in security update.

Word flaw left out of Patch Tuesday
Microsoft will not be including a fix for the recently discovered Word vulnerability in its scheduled security update on 12 December.  

The software giant has admitted that its next 'Patch Tuesday' update will not address a recently discovered vulnerability in Word that is currently being exploited. 

A Microsoft spokesman told vnunet.com that the company is still investigating the matter. 

Although the fix is not currently included in the December security update, the spokesman said that Microsoft has not ruled out releasing a separate fix before the next monthly release in January 2007.

The Word vulnerability, which affects at least nine Mac and PC versions of Word and Microsoft Works, has been given the highest possible alert rating of 'extremely critical' by security firm Secunia. 

The exploit could allow an attacker to remotely execute malware on a user's system. Security firm F-Secure advises users not to open or save any Word files that come from untrusted sources or arrive unexpectedly from trusted sources. 

Microsoft's update due on 12 December fixes five vulnerabilities in Windows, some of which are listed as 'critical', the company's highest security rating.

A fix for Visual Studio that addresses 'critical' vulnerabilities will also be included. As a single Microsoft security bulletin can address several versions of the same application, the security rating for a vulnerability will often differ between releases.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:

Most Read Articles

Poor WA gov M365 security led to $71k theft and children's data breached

Poor WA gov M365 security led to $71k theft and children's data breached

US medical device maker Stryker's Microsoft environment attacked

US medical device maker Stryker's Microsoft environment attacked

CBA chief impersonated in global investment fraud on Facebook

CBA chief impersonated in global investment fraud on Facebook

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Log In

  |  Forgot your password?