Bits from Bill

Technology thoughts leaking from the brain of "Bill Pytlovany"

Monday, July 13, 2009

Microsoft Says you are Vulnerable to Attack

Another week, another security vulnerability found and exploited. I can’t stress enough how important it is to use a behavior based monitoring program like WinPatrol. These zero-day vulnerabilities can attack your computer without you doing anything you might consider dangerous. It can happen to anyone, and you can’t just blame it on your kids.


Todays’s Microsoft Security Advisory (973472) relates to components found in Microsoft Office and could allow remote code execution on your machine.

Microsoft is investigating a privately reported vulnerability in Microsoft Office Web Components. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. When using Internet Explorer, code execution is remote and may not require any user intervention.

We are aware of attacks attempting to exploit the vulnerability.

Brian Krebs at the Washington Post was quick to point out that in last weeks msvidctl.dll vulnerability Microsoft used the words “limited attacks”.

Our good friends at Microsoft have published a quick fix for this problem. If you’re using any of the applications below I recommend taking advantage of the Fix It link below and follow their instructions. If you do experience problems Microsoft does provide a “Disable Fit it” link

Microsoft FixIt
Click above to go to Microsoft Fix it page



  • Microsoft Office Small Business Accounting 2006
  • Microsoft Office 2003 Web Components for the 2007 Microsoft Office system
  • Microsoft Office 2003 Service Pack 3
  • Microsoft Office 2003 Web Components
  • Microsoft Internet Security and Acceleration Server 2004 Standard Edition

Labels: , ,

Share on Facebook


Friday, October 24, 2008

Today's a Good Day to Update

If you’re a regular BitsFromBill.com reader you know how I feel about the concept of auto updating software. I hate autoupdate programs from Apple, Google and Adobe.

Occasionally, the bad guys learn about a vulnerability and are quick to deploy dangerous attacks designed to take advantage newly discovered security holes. When this happens installing an update to protect yourself is worth any risk of updated code.

Today is one of those days. Yesterday Microsoft released security bulletin MS08–067 Vulernability in Server Service Could Allow Remove Code Execution. You might be thinking, “But I have a laptop, not a server”. Well, technically you do have a server and even your laptop is exposed if you’re connected to the internet.

So far the reported attacks seem to be targeted but it won’t be long before internet bots are scanning all IP address for this vulnerability. Microsoft has been a little vague only giving specific details to security providers. This attack can bypass firewalls and users don’t have to visit any webpages to become infected. I’ve read enough to suggest this security patch is a special exception.

So, I don’t know if this update could cause problems but I’ve updated my machines and I recommend you do the same.

http://update.microsoft.com/windowsupdate/v6/default.aspx



Labels: , ,

Share on Facebook