Ahmed Mahdy

Developers & IT Pros Blogs

Ahmed Mahdy Tweets

Recent posts

Tags

Categories

Navigation

Archive

Translator


Visitors Map

Locations of visitors to this page

MVP Nominee


Windows Professional


Microsoft Student Partner

Microsoft Student Partner

MCPD/MCITP Qualified


Microsoft Registered Partner

Microsoft Partner

CCNA Qualified

CCNA

Flaw found in Office 2007

ImageResearchers have discovered a "highly critical" security flaw in newly released Office 2007, despite Microsoft's efforts to deliver its most secure version yet of the productivity software.

The consumer version of Office 2007, which launched only four weeks ago, is designed to withstand higher scrutiny by malicious code writers, as Microsoft subjected the software to code auditors as part of its security development lifecycle. But researchers at eEye Digital Security found a file format vulnerability in Microsoft Office Publisher 2007, which could be exploited to let an outsider run code on a compromised PC. "We were surprised we could find a flaw so quickly (after Office 2007 launched) and one that was part of their core products," said Ross Brown, eEye's chief executive.

 

An attacker could create a malicious publisher file, he said. Once the recipient opens the file, he or she could find the system infected and susceptible to a remote attack. Researchers at eEye used a standard process of code auditing in discovering the vulnerabilities, Brown added. He noted that Microsoft either did not do a "good job" with its code auditing, or it may not have had enough people working on such a task. Microsoft, meanwhile, said it is investigating eEye's report of a possible vulnerability in Publisher 2007 and will provide users with additional guidance if necessary.

 

ImageFull story: c|net



Posted: Feb 26 2007, 02:02 by Ahmed Mahdy | Comments (0) RSS comment feed |
  • Currently 0/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5
Filed under:

Add comment


(Will show your Gravatar icon)

  Country flag

biuquote
  • Comment
  • Preview
Loading