• On MovieTome: See the villain of IRON MAN 2!
May 13, 2008 11:59 AM PDT

Microsoft fixes critical holes in Windows, Word, Publisher

by Elinor Mills

Microsoft on Tuesday issued security patches that plug critical holes in Microsoft Word and Publisher and a vulnerability in Windows for which a zero-day exploit has been available for weeks.

Zero-day exploits are considered particularly dangerous. While most security holes are plugged before an exploit is released, computers running vulnerable software for which there is a zero-day exploit already released are open to attack until the patch is available.

The critical Windows vulnerability was discovered in Microsoft Jet Database Engine 4.0. It allows an attacker to take complete control of an affected system, including installing malicious programs and modifying data.

Microsoft has acknowledged that people have been taking advantage of this vulnerability to compromise machines, said Amol Sarwate, manager of the vulnerability research lab at Qualys, which offers security as a service to corporations.

The other critical patches Microsoft released plug a hole in Microsoft Word and two holes in Microsoft Publisher that could allow attackers to remotely run code on an affected machine if the user were to open a specially crafted Word or Publisher file.

And Microsoft also fixed two holes rated "moderate" that would allow an attacker to shut down and restart the Microsoft Malware Protection Engine used in the company's security products including Windows Live OneCare and Windows Defender.

Missing from the patches was a fix for a vulnerability in the core Windows operating system for which there has been a zero-day exploit available for nearly a month, said Sarwate.

That unpatched vulnerability allows local users to escalate their privileges on a system and gain more access to resources and data. "It may look harmless," Sarwate says, but it not only gives insiders more control than they should have, but could enable outsiders to use the insider's escalated privileges to do damage.

"We were hoping to see a fix for that zero-day as well," he said.

More information about this month's Patch Tuesday patches is available here.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
Recent posts from News Blog
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
Was InfoWorld's CTO of the Year award a year late?
VMWare VI4 renamed to vSphere
Add a Comment (Log in or register)
by The_happy_switcher May 13, 2008 1:56 PM PDT
3 down and only 4,555,555,666,777,888 to go.
Reply to this comment
advertisement

Making sense of Windows 7 upgrades

faq The basics and the fine print on Microsoft's options for those eyeing the next operating system from Redmond.
• Full Windows 7 coverage

Road Trip 2009: Big Sky Country

CNET News reporter Daniel Terdiman takes his car full of gadgets to the Rockies and the Great Plains in search of tech, science, nature, and more.
• America's Fortress: Cheyenne Mountain

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement
Click Here

Inside CNET News

Scroll Left Scroll Right