
Internet Explorer, Office and Exchange all get fixed...
By Joris Evers
Published: 9 May 2007 11:59 BST
Microsoft has released fixes for 19 security flaws in several of its products, including Internet Explorer 7, Office 2007 and Exchange 2007.
The company published seven security bulletins as part of its monthly patch cycle. All are tagged "critical", its highest rating. Critical vulnerabilities typically allow an attacker to gain full control of an affected system with very little, if any, action by the user.
Most of the vulnerabilities addressed by the fixes can only be exploited after someone visits a rigged website or opens a malicious file - attack approaches that are increasingly popular among cyber crooks.
Microsoft's MS07-027 update fixes six flaws in Internet Explorer that could be exploited through malicious websites. Three Microsoft updates deal with flaws in Office applications, including Office 2007. Most of these bugs exist because of errors in the way the applications handle certain files and could be exploited through a rigged Office file.
Exchange is flawed in a way that could allow a system running the email server software to be fully compromised without any special user action. There are four vulnerabilities in Exchange, including Exchange 2007, addressed by Microsoft's MS07-026 fix. The most serious bug exists in the way Exchange encodes email messages.
The fact several of the newly reported vulnerabilities critically affect Internet Explorer 7, Office 2007 and Exchange 2007, hurts Microsoft's security message, said Amol Sarwate, manager of the vulnerability research lab at Qualys. Microsoft has marketed these programs as secure, citing its security development process.
Sarwate said: "Microsoft 2007 software, including Exchange and Office, continues to come up vulnerable, demonstrating that the security development lifecycle is not infallible." Last month's Microsoft patches included a fix for a zero-day flaw in Windows that also affected Vista.
Another vulnerability that may affect many users lies in "Capicom", a component to add cryptography to applications. It is flawed in the way it handles specific data, a bug that could let an attacker commandeer a computer running the component, Microsoft said in bulletin MS07-028.
Among Microsoft's updates are fixes for a trio of zero-day vulnerabilities. This includes an expected patch for a flaw in the Windows domain name system, or DNS. The vulnerability affects Windows 2000 Server and Windows Server 2003. Microsoft warned of the problem last month and has said it was being used in "limited" attacks.
The remaining zero-day vulnerabilities for which fixes are now available are in Internet Explorer and Word, Microsoft said. The Word flaw had also been used in cyber attacks, it said.
Microsoft's fixes will be made available to Windows users via the Automatic Updates feature and are also available for download from Microsoft Update and Windows Update.
Joris Evers writes for CNET News.com
It is essential that you have a good technical background in FIX Protocol, Unix, Windows and SQL. Leading Financial Software House is seeking a Front ...
Key skills: - Experience of Break/fix - Microsoft Office -Windows XP - Dell -Good people skills, articulate. My client based in Manchester urgently ...
FIX Software Support Engineer required to join a leading financial traders based across the globe. You will support over 100 clients on the ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Martin Brampton Brampton Factor: Open source stands up for its rights Copyright can keep the movement alive...
Bob Tarzey The rise and rise of Infor Quocirca's Straight Talking: Where next for the apps giant?