February 23, 2007 1:17 PM PST
Flaw found in Office 2007
- Related Stories
-
Microsoft to deliver patches by the dozen
February 8, 2007 -
Windows, Office to get 'critical' fixes
January 4, 2007 -
Office hit by another security problem
June 22, 2006
The consumer version of Office 2007, which launched only four weeks ago, is designed to withstand higher scrutiny by malicious code writers, as Microsoft subjected the software to code auditors as part of its security development lifecycle.
But researchers at eEye Digital Security found a file format vulnerability in Microsoft Office Publisher 2007, which could be exploited to let an outsider run code on a compromised PC.
"We were surprised we could find a flaw so quickly (after Office 2007 launched) and one that was part of their core products," said Ross Brown, eEye's chief executive.
An attacker could create a malicious publisher file, he said. Once the recipient opens the file, he or she could find the system infected and susceptible to a remote attack.
Researchers at eEye used a standard process of code auditing in discovering the vulnerabilities, Brown added. He noted that Microsoft either did not do a "good job" with its code auditing, or it may not have had enough people working on such a task.
Microsoft, meanwhile, said it is investigating eEye's report of a possible vulnerability in Publisher 2007 and will provide users with additional guidance if necessary.
Executives at the software giant have recently said they expect security challenges to keep emerging, as an increasing number of devices connect to the Internet.
No public exploits have been reported in circulation for Publisher 2007 and, given Office 2007's recent release, the flaw may hold little attraction for attackers who may wish to concentrate on software that is in greater distribution, eEye said.
See more CNET content tagged:
eEye Digital Security, Microsoft Office 2007, auditing, flaw, researcher
17 comments
Join the conversation! Add your comment
P.S. For those who may say I haven't experienced the other OS's/companies. I run a Unix server and manage two applications running Oracle database. I did my first programing on a Apple II. I'm here to tell you no one does it better than MS.
And yes, it needs one gig because you simply can do more things and do them better with more memory, and since RAM is cheap it would be foolish to restrict the capabilities to suit some users that want to run it on 64KB. Move on.
You do have choices. You might write your own software, then you could blame yourself for the holes you say are in MS Office 2007.
The flaw here is Microsoft's monopoly on Office products has been allowed to continue, costing society at large severe harm.
There have been *MANY* macro flaws in non-MS products complete with "proof-of-concept" code. o
If you want a better perspective I suggest you pull you pull your head out of that warm but smelly receptacle you placed in it because it's obviously given you "tunnel" vision.