Word flaw left out of Patch Tuesday

By
Follow google news

Actively targeted vulnerability not included in security update.

Word flaw left out of Patch Tuesday
Microsoft will not be including a fix for the recently discovered Word vulnerability in its scheduled security update on 12 December.  

The software giant has admitted that its next 'Patch Tuesday' update will not address a recently discovered vulnerability in Word that is currently being exploited. 

A Microsoft spokesman told vnunet.com that the company is still investigating the matter. 

Although the fix is not currently included in the December security update, the spokesman said that Microsoft has not ruled out releasing a separate fix before the next monthly release in January 2007.

The Word vulnerability, which affects at least nine Mac and PC versions of Word and Microsoft Works, has been given the highest possible alert rating of 'extremely critical' by security firm Secunia. 

The exploit could allow an attacker to remotely execute malware on a user's system. Security firm F-Secure advises users not to open or save any Word files that come from untrusted sources or arrive unexpectedly from trusted sources. 

Microsoft's update due on 12 December fixes five vulnerabilities in Windows, some of which are listed as 'critical', the company's highest security rating.

A fix for Visual Studio that addresses 'critical' vulnerabilities will also be included. As a single Microsoft security bulletin can address several versions of the same application, the security rating for a vulnerability will often differ between releases.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:

Most Read Articles

Australia's critical infrastructure security laws "toothless"

Australia's critical infrastructure security laws "toothless"

"CanisterWorm" supply chain malware attacks npm

"CanisterWorm" supply chain malware attacks npm

Gov proposes disclosure delay for most serious cyberattacks

Gov proposes disclosure delay for most serious cyberattacks

US regulator bans imports of new foreign-made routers

US regulator bans imports of new foreign-made routers

Log In

  |  Forgot your password?