Windows Secrets

Subscribers: Sign in

Enter your e-mail address to get a free subscription.
We guarantee your privacy
Skip to content
  • Home
  • Newsletter Archives
    • Current
    • LangaList Plus
    • Patch Watch
    • Wacky Web Week
    • Security Baseline
  • E-Books
  • Lounge
  • About us
    • Refunds
    • Privacy Policy
    • Advertise
  • Contact
  • Your Account
    • Upgrade
    • Preferences
    • Bonus Download
    • Unsubscribe
Home>Over the Horizon>Microsoft leaves several Word holes unfixed

Microsoft leaves several Word holes unfixed

Tweet

Chris mosby By Chris Mosby

Well, here we are, another monthly patch day has come and gone this week.

After the smoke clears, as usual, we have to figure out what holes are left that weren’t patched this time around.


Who decides which Word/Windows holes to fix?

One of these days, I really hope that I have the opportunity to hold a discussion with some of the people over at Microsoft. I’d like to find out how they decide what gets patched and what doesn’t.

In the meantime, we’ll just have to wonder — and try to clean up this month’s list of known holes that didn’t get closed. This time around, Microsoft Word is the big concern.

Infected .doc files can get you via Word

A vulnerability in Microsoft Works 2004-2006, Word 2003 Viewer, and all versions of Microsoft Word except 2007, was recently reported in Microsoft security advisory 929433. The advisory was issued after Microsoft began investigating reports of “limited” attacks that are already exploiting the hole.

This flaw is due to an unidentified error in how Word handles documents. The error can cause memory corruption and allow infected code to run with the same rights as the user. A hacker trying to compromise computers would, of course, have to get a user to open an infected document in order to take of advantage of this exploit.

What to do: Microsoft, as usual, gives you the old chestnut, “Don’t open Word files that you receive from untrusted sources or that are received unexpectedly from trusted sources.” Now, this is good advice, no matter what you get in e-mail — but it doesn’t fix the problem. To do that, you could go out and buy Office 2007, which isn’t vulnerable to the hack, or simply hope Microsoft releases a patch for older versions of Word soon.

This article is part of our paid content. Subscribe.

Already a paid subscriber? Click here to login.

Related posts:

  1. Microsoft leaves some Java flaws unfixed
  2. Word, NetMeeting Security Holes (and Patches)
  3. Black Tuesday leaves several flaws unpatched
  4. New MS Word and Excel vulnerability
  5. Internet Explorer still has holes left
= Paid content

All Windows Secrets articles posted on 2006-12-14:

  • LangaList Plus What to do when a DLL goes missing
  • LangaList Plus Fix your PC’s broken bootup behavior
  • Over the Horizon Microsoft leaves several Word holes unfixed
  • Patch Watch Patches leave fewer zero day vulnerabilities
  •  Show all articles on a single page
E-books

We’ve pored through years of back issues, picking the best tips, to create these ebooks:

E-book series
  • PC Maintenance Guide
  • PC Security Guide
  • Windows 7 Guide Vol 1
  • Windows 7 Guide Vol 2
  • Win XP Survival Guide
See the e-book series
Top-scoring articles in the past 12 months
  • Leaving long cookie trails throughout the Web 5.00
  • Windows-like security for Android devices 5.00
  • Win7′s no-reformat, nondestructive reinstall 4.53
  • The sorry tale of the (un)Secure Sockets Layer 4.42
  • RPV: Win7′s least-known data-protection system 4.33
  • Recovery: the last step in total data security 4.30
  • Time for a .NET update we can’t ignore 4.30
  • Getting the most from Windows Search — Part 1 4.25
  • Revising printing habits saves money and trees 4.25
  • Upgrades end in erratic, partial hangs 4.25
  • Pros and cons of a ‘keyfile’ password 4.21
  • Beating back Duku and a plethora of other threats 4.21
  • Office 2007 gets its final service pack 4.19
  • Putting Registry-/system-cleanup apps to the test 4.19
  • One year and 99 security bulletins later 4.18
  • 1.8TB external drive goes down hard 4.17
  • Don’t pay for software you don’t need — Part 3 4.16
  • Internet Explorer gets another round of patches 4.15
  • Is your free AV tool a ‘resource pig?’ 4.15
  • Vacation’s over; it’s a big round of patches 4.15
  • Remote access leads to remote attacks 4.15
  • Keeping you up to date: say no to .NET — again 4.14
  • Take control of Google’s privacy policy settings 4.14
  • Office File Validation patch leads to problems 4.14
  • The advanced system-recover toolkit 4.13
  • New “419″ scam involves PayPal and Western Union 4.12
  • Readers’ best personal-privacy tips 4.11
  • Getting the most from Windows Search — Part 2 4.11
  • Re-examining Dropbox and its alternatives 4.10
  • Don’t pay for software you don’t need — Part 2 4.10
Connect with us Follow us on Twitter Connect with us on Facebook View our RSS Feeds
  • Home|
  • Newsletter|
  • About Windows Secrets|
  • Advertise with us|
  • Unsubscribe|
  • Sitemap|
  • Affiliates|
Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, WinFind, Windows Gizmos, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of iNET Interactive. All other marks are the trademarks or service marks of their respective owners.
iNET Interactive Copyright © 2011 iNET Interactive.
All rights reserved.
Terms of Use  |  Privacy Policy
Internet Services
  • Web Hosting Talk
  • HostingCon
  • Hosting Catalog
  • Host Voice
Web Development
  • Hot Scripts
  • DB Forums
Digital Marketing
  • ABestWeb
  • Search Marketing Standard
  • PayPerClickUniverse
  • SEMCompare
Consumer Tech
  • Windows Secrets
  • Overclockers
  • Mac Forums

Learn more about
advertising opportunities across the iNET Interactive Network.

LiquidWeb