Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

Another Microsoft bug revealed on huge patch day

By Jeremy Kirk , IDG News Service , 12/10/2008
  • Share/Email
  • Tweet This
  • Comment
  • Print

Along with its biggest patch release in five years, Microsoft warned on Tuesday of another potentially dangerous vulnerability in its software.

The problem lies within the WordPad Text Converter for Word 97 files, Microsoft said in an advisory.

The systems affected include Windows 2000 Service Pack 4, Windows XP Service Pack 2, Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2, Microsoft said. XP Service Pack 3 and the Vista operating systems are not affected. (Read related story of the slew of patches released by Microsoft.)

The company said it has seen limited, targeted attacks. If exploited, a hacker could gain the same rights on a PC as a local user and could remotely execute code.

Microsoft is investigating the problem. Microsoft typically releases patches on the second Tuesday of the month. If Microsoft sticks to its schedule, the earliest a patch could be released would be Jan. 13. However, Microsoft has deviated from its patching cycle when a vulnerability is considered particularly dangerous.

The vulnerability can't be exploited by simply opening an e-mail, Microsoft said. The victim would have to open an attachment containing a malicious file designed to exploit the problem.

Microsoft said Word 97 documents are opened by default with Office Word if a user has that application installed. Word is not affected by the problem, but attackers could try to rename the malicious file with a Windows Write (.wri) extension, which would cause WordPad to try to open it. The company advised that ".wri" attachments could be blocked at the network gateway, reducing the risk a user would open a harmful file.

Microsoft released on Tuesday eight patches covering 28 vulnerabilities within applications including Internet Explorer, SharePoint, Office, Windows Media Player and its Vista OS. Six of those patches were classified as "critical."

  • Share/Email
  • Tweet This
  • Comment
  • Print

Comments (2)
Login
Forgot your account info?

AmazingBy 3tpro on December 10, 2008, 9:22 amWe have blocked these types of attachments on our systems at [url=http://3tpro.com] Dallas Computer Service[/url]. Its amazing the number of issues they have with...

Reply | Read entire comment

We'll be blocking these extensions also, thanks.By Anonymous on December 10, 2008, 7:21 pmWe'll be blocking these extensions also, thanks.

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed