Security feature in Office 2010 will soon be added to older versions

Analysis
Dec 15, 20103 mins

File Validation will be available in Q1 of 2011

Microsoft says it will make updates available to users of Office 2007 and Office 2003 that will help make them as secure as Office 2010. And for Office 2010, that’s pretty secure as the software suite went six months without a security bulletin until this week, when two bulletins affecting it were released on Patch Tuesday.

“A lot of the good work in Office 2010 was possible because that was work planned for and completed as part of the product’s lifecycle,” wrote Bob Fruth, security program manager in the Microsoft Security Response Center, in a Tuesday blog post. “[And] we have found a way to bring some of these protections to older versions of Office.”

Some time in the first quarter of next year, Microsoft will port the File Validation functionality to Office 2007 and Office 2003, Fruth stated. File Validation will verify the contents of Word, Excel, PowerPoint and Publisher files, and if it detects an issue, will display a warning message. In addition, Microsoft plans to issue signature files for versions 2007 and 2003 that provide new information for use by File Validation, which can detect previously unknown vulnerabilities in files and warn the user. Fruth said Microsoft believes that installing a signature update will be less disruptive than deploying a security bulletin, which can be an issue in large deployments of Office.

File Validation is an important security breakthrough in Office 2010 because it checks files before they are opened, which is how many viruses or malware are activated, said Andrew Storms, director of security operations at nCircle, a security vendor based in San Francisco.

“Before Office actually opens the file, there’s a program ahead of it that happens automatically — the user doesn’t even notice it’s happening — and it checks the format of the file to ensure that everything is okay,” Storms said. “What this [announcement] means is that the users of the older versions are now going to be protected by this validation sequence.”

But adding an Office 2010 security feature to older versions begs at least one question: Won’t that give enterprises one more reason NOT to migrate to Office 2010? As this blog has reported previously a sizable number of enterprises are reluctant to upgrade to Office 2010 because of migration issues. IT administrators can look at this news and decide they can stay on Office 2007 or 2003 and gain the security benefits of 2010 without the expense and hassle of an upgrade. I suspect Microsoft’s answer would be that security upgrades are important enough to share with all users while feature upgrades — and there are many — are something they’ll have to pay for.

The latest security bulletins affecting all versions of Office identify a vulnerability to remote code execution. Bulletin MS10-105 pertains to the risk associated with using image files in Office. While the bulletin says the risk is associated with older versions of Office, not Office 2010, Microsoft advises Office 2010 users to apply the patch anyway just for good measure. MS10-103, meanwhile, pertains to a vulnerability in Publisher, versions 2002 through 2010. “If a user opens a specially crafted Publisher file, an attacker could take complete control of an affected system,” according to the bulletin, which describes the risk as “important.” None of the latest bulletins affecting Office were described as “critical,” the highest level of urgency.