Latest Comments
"No Comment"
by Phillip Vachon | Jul 21, 2008 4:13 AM
 
"thankx dear ihave my massege"
by muhammad shehzad ashraf | Jul 20, 2008 1:05 AM
 
"kdjfkjasd"
by fdsf | Jul 19, 2008 10:19 PM
 
"Hacked? No, it was not hacked. Lots of people were told to search for it. That's all."
by kgh0st | Jul 19, 2008 3:33 PM
 
""..but experts are poring over the site's logs to find the vulnerability that allowed the ..."
by J | Jul 18, 2008 9:54 PM

Microsoft to push out four patches in May

  • Email a Friend
  • Print Page
By Dan Kaplan
May 12, 2008 10:09 AM
Tags: "patch | tuesday" | "microsoft | may | patch" |
The three critical fixes address holes in Word, Publisher and the Jet Database Engine, according to Microsoft's advance notification. All of these flaws can be exploited to execute remote code.

The Word and Jet patches likely are related to a known zero-day vulnerability, Andrew Storms, director of security operations at network security firm nCircle, told SCMagazineUS.com on Friday.

In March, Microsoft warned of a Jet Database exploit that was spreading through Word in "limited, targeted attacks."

Jet Database files are referenced by the .mdb (Microsoft Access Database) file extension, which are considered unsafe and users are normally blocked from opening them in Outlook or Internet Explorer, according to Microsoft. However, attackers have discovered a way to evade the built-in restrictions.

"It looks like what we're seeing here is a fix for the same bug," Storms said of the Word and Jet patches. "Essentially both attack vectors are going to be repaired in this update."

He said he was not sure if the Publisher fix was related.

Microsoft is also planning a patch for its security software -- Windows Live OneCare, Antigen, Windows Defender and Forefront -- for a moderate vulnerability that could permit a denial-of-service attack.

Storms said the bug likely could allow an attacker to send a maliciously crafted file that would stall an an anti-virus scan.

"If you're scanning engine goes down, it's a big deal," he said.

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below: