News & Information for Technology Purchasers
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Enterprise I.T. Hardware Software Communications More Topics...
Microsoft/Windows
Average Rating:
Rate this article:  
Patch Tuesday Addresses PowerPoint Vulnerabilities Patch Tuesday Addresses PowerPoint Vulnerabilities
By Jennifer LeClaire
May 13, 2009 9:05AM

    Bookmark and Share
For Patch Tuesday, Microsoft has issued a single bulletin with 14 vulnerabilities, all of them focused on Microsoft PowerPoint. The Microsoft patches address problems with opening older PowerPoint file formats. Attacks on PowerPoint would most likely be launched by e-mail or malicious downloads. The PowerPoint vulnerabilities are rated as easy to exploit.
 



In a notable Patch Tuesday, Microsoft Relevant Products/Services issued a single security bulletin to address 14 vulnerabilities, 11 of them rated critical. All of this month's patches relate to various versions of Microsoft PowerPoint.

May's Patch Tuesday is only the fourth time in four years Microsoft has issued just one security bulletin, but that one bulletin addresses the most vulnerabilities of any release in Microsoft history.

Most of this month's fixes have to do with opening older, or legacy, PowerPoint file formats. However, security research firm Symantec pointed to exploit code for CVE-2009-0556 publicly available that could give attackers remote access to the machine. At this stage, only a limited number of exploits have been seen in the wild, but the zero-day vulnerability is cause for concern among security researchers.

A Forty-Day Fix

"Because taking advantage of these vulnerabilities requires a user to open a maliciously crafted PowerPoint file, e-mail is likely the most probable method attackers would use to try and exploit these," said Alfred Huger, vice president of Symantec Security Response. "Another possibility is for an attacker to lure a victim into downloading the file from a misleading or compromised Web site. At that point, the attacker would then have complete control over everything the user's account has permission to do on the system Relevant Products/Services."

Given the large amount of bugs Microsoft and Oracle fixed last month, this light Microsoft release will give enterprises a much-needed opportunity to catch up, noted Andrew Storms, director of security operations for nCircle.

"For the last two months users have been battling Microsoft Office zero-day attacks. The first set in February was in Microsoft Excel. The second set, announced on April 2nd, made users afraid of opening PowerPoint files," Storms said. "Forty days from bug to bug fix is a decent turnaround for Microsoft, given the vast number of Microsoft Office permutations that need to be quality tested."

Is MOICE the Answer?

While some of the PowerPoint vulnerabilities rank only as "important" on most versions of Microsoft Office, they are all categorized as "remote code execution" and have a low exploitability index. That means exploits are relatively easy to write, and Wolfgang Kandek, CTO of Qualys, expects to see attackers begin using them soon.

One of the workarounds for CVE-2009-0556, the zero-day vulnerability patched in this advisory, is MOICE. An acronym for Microsoft Office Isolated Conversion Environment, MOICE is a tool set that sanitizes Office documents when users open them through browsing and e-mail. MOICE removes potentially dangerous code, has been available since May 2007, and was cited as a workaround in eight of Microsoft's 78 advisories in 2008.

"MOICE is an interesting tool, used to reduce the risk produced by the increasing number of file-format vulnerabilities," Kandek said. "Its limitation is that it only works with Office 2003 and 2007. Office 2000 and Office XP are not supported."
 

Tell Us What You Think
Your Comment:



Advertisement


 Microsoft/Windows
1.   MS: Windows 7 Doesn't Hurt Battery
2.   Tips for More Windows 7 Productivity
3.   MS: Russian Pirates Scamming Us
4.   Patch Tuesday Will Tie MS Record
5.   Battery Drains Linked To Windows 7


advertisement
Tips for More Windows 7 ProductivityTips for More Windows 7 Productivity
Win 7 is chock-full of unsung features.
Average Rating:
Is Bill Gates Batting for Team China?Is Bill Gates Batting for Team China?
He implies Google is overreacting.
Average Rating:
Rush IE Patch Coming Says MicrosoftRush IE Patch Coming Says Microsoft
Exploit testing tools are being updated.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware Spotlight
Nvidia Auto-Switches Notebook GPU To Save Battery Life
Nvidia has taken the wraps off a notebook technology that chooses the best graphics processor for any given application and automatically routes the workload to Nvidia or Intel processors.
 
Microsoft Says Battery Woes Not Caused By Windows 7
Battery problems on Windows 7 machines are not caused by the operating system. That's the position of Stephen Sinofsky, head of the Windows division, in a long posting on the Windows engineering blog.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Enterprise Technology Spotlight
Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 
IBM Opens Eco-Friendly, Cloud-Focused Data Center
IBM has opened its latest data center in North Carolina. Big Blue said the $362 million facility in Research Triangle Park is designed to support cloud computing and other new computing models.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Hardware | Software | Communications | Network Security | Wireless Tech | Linux/Open Source
Apple/Macintosh | Microsoft/Windows | World Wide Web | Data Storage | E-Commerce | Personal Tech | Tech Trends | Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.