Word flaw left out of Patch Tuesday

By
Follow google news

Actively targeted vulnerability not included in security update.

Word flaw left out of Patch Tuesday
Microsoft will not be including a fix for the recently discovered Word vulnerability in its scheduled security update on 12 December.  

The software giant has admitted that its next 'Patch Tuesday' update will not address a recently discovered vulnerability in Word that is currently being exploited. 

A Microsoft spokesman told vnunet.com that the company is still investigating the matter. 

Although the fix is not currently included in the December security update, the spokesman said that Microsoft has not ruled out releasing a separate fix before the next monthly release in January 2007.

The Word vulnerability, which affects at least nine Mac and PC versions of Word and Microsoft Works, has been given the highest possible alert rating of 'extremely critical' by security firm Secunia. 

The exploit could allow an attacker to remotely execute malware on a user's system. Security firm F-Secure advises users not to open or save any Word files that come from untrusted sources or arrive unexpectedly from trusted sources. 

Microsoft's update due on 12 December fixes five vulnerabilities in Windows, some of which are listed as 'critical', the company's highest security rating.

A fix for Visual Studio that addresses 'critical' vulnerabilities will also be included. As a single Microsoft security bulletin can address several versions of the same application, the security rating for a vulnerability will often differ between releases.
Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:

Most Read Articles

Labor bets on agency to monitor AI companies

Labor bets on agency to monitor AI companies

Australia, US and UK sanction Russian cyber firms over ransomware links

Australia, US and UK sanction Russian cyber firms over ransomware links

Startup finds flaws in popular VoIP products

Startup finds flaws in popular VoIP products

JPMorgan, Citi, Morgan Stanley client data may be exposed by vendor's hack

JPMorgan, Citi, Morgan Stanley client data may be exposed by vendor's hack

Log In

  |  Forgot your password?