Wednesday, November 11, 2009

Vulnerabilities Discovered in Microsoft Word and Excel

Microsoft issued two security bulletins yesterday concerning vulnerabilities in Microsoft Office’s Word and Excel programs for Windows and Mac. Attackers exploit these vulnerabilities by enticing a user to open a maliciously-crafted Word or Excel document. Once opened, the document enables the attacker to inherit the user’s permissions and ultimately gain full control over the user’s machine.

Microsoft Office users should beware of all unexpected Word (.doc) and Excel (.xls) documents and immediately install the appropriate Office patches created by Microsoft to fix the vulnerabilities. Further information and instructions for patch installation can be found in the following security bulletins on Microsoft’s Website: Microsoft Security Bulletin MS09-067 (Excel); Microsoft Security Bulletin MS09-068 (Word).

Office users can also let Microsoft’s Update utility install the appropriate patches automatically.

To learn how 3D’s network management solutions protect businesses from threats like these, visit our website at www.3dcorp.us.

References: WatchGuard's LiveSecurity Service Update "Microsoft's Office Patches Fix Word and Excel," Microsoft Security Bulletin MS09-067, Microsoft Security Bulletin MS09-068

0 comments:

Post a Comment