Please wait while the page is being loaded Skip this advertisement >
Sunday | 23 November, 2008
ARN

Microsoft fixes critical Windows, Word flaws

Patch Jet Database bug pronto, say researchers; exploits in circulation
Gregg Keizer (Computerworld) 14 May, 2008 07:56:07

Microsoft Tuesday patched six vulnerabilities, most marked "critical," in Windows, Word, Publisher and its anti-virus software.

The most important patch to apply, said analysts, is MS08-028, a critical fix that updates the Jet Database Engine in Windows 2000, Windows XP SP2 and Windows Server SP1. "We have to address this first," said Andrew Storms, director of security operations at nCircle. "There are public exploits out for this."

"Jet Database should be done first," agreed Amol Sarwate, the manager of Qualys' vulnerability research lab. "This is a zero-day that Microsoft themselves acknowledged as having seen not only proof-of-concept code, but also public exploits."

Two months ago, Microsoft confirmed critical vulnerabilities in Jet Database Engine, a Windows component that provides data access to applications such as Microsoft Access and Visual Basic, and posted a security advisory that acknowledged "limited, targeted attacks" using Word documents to trigger the Jet Database bug.

Microsoft knew of the Jet Database bugs for more than two years, but had not patched the problems because it thought it had blocked the obvious attack vectors, a manager in the Microsoft Security Response Center (MSRC) said several days later. Mike Reavey, the group's operations manager, said Microsoft might replace the version of Jet in Windows 2000, XP and Server 2003 SP1 to fix the flaws. According to MS08-028, Microsoft is doing just that.

The company also reiterated that attacks have been spotted in the wild exploiting the vulnerability. "Microsoft had received information that this vulnerability was being exploited," the company said in the security bulletin issued Tuesday.

The Jet Database Engine included in Windows Vista, Windows Server 2003 SP2 and the just-released Windows XP SP3 is not vulnerable to the attacks, and doesn't require replacement.

What is less clear, however, is how Microsoft patched Word and Outlook to shut down the attack vectors that the public exploits have used to leverage the Jet Database problem.

Storms wasn't sure exactly what Microsoft fixed in MS08-026, the security bulletin it released Tuesday for Word. "We're all kind of asking 'huh?' about that," Storms said. "My guess is that we're not the only ones asking what's been fixed."

In late March, when Reavey admitted that Microsoft had not conceived of Jet Database exploits that used Word to trick users into opening malformed .mdb files, he also said that the MSRC was considering a patch to "prevent Word documents from loading MDB files without prompting."

Tuesday, it sounded like Microsoft had taken that route. "In addition to the changes that are listed in the 'Vulnerability Details' section of this bulletin, this update includes logic enhancements to security warnings that mitigate Word as an attack vector used to exploit vulnerabilities in Microsoft Jet Database Engine," the MS08-026 bulletin said. "Word was vulnerable to attacks when opening a specially crafted Word document containing a malicious Jet database file. After applying this update, Word will prompt a user for confirmation before running SQL commands or queries when opening Word documents."

However, Microsoft did not spell out the changes to Word in a separate CVE (Common Vulnerabilities and Exposures) listing, as is its usual habit. At times, the company has been criticized for bundling multiple fixes in a single bulletin without detailing each.

Related Stories
  • +

    Microsoft ends year by patching 11 bugs 13 December, 2007 08:40:19

    Critical fixes for Media Player and Internet Explorer
    Microsoft released seven security bulletins this week that patch 11 vulnerabilities in Windows, Internet Explorer, Windows Media Player and other parts of the operating system. Two of the bugs are currently being exploited by attackers, Microsoft confirmed.
  • +

    Microsoft starts '08 by patching 3 bugs 09 January, 2008 10:38:52

    Slow start for 2008 but plenty more exploits expected
    Microsoft released just two security updates this week that patch three vulnerabilities in Windows, marking the beginning of the bug year with a relatively slow start, said researchers.
  • +

    New QuickTime bug opens XP, Vista to attack 27 November, 2007 06:22:35

    Apple forgot to turn on Vista security feature, claims researcher
    Security researchers warn that attack code targeting an unpatched bug in Apple's QuickTime has gone public, and added that in-the-wild attacks against systems running Windows XP and Vista are probably not far behind.
  • +

    Apple fixes more QuickTime media flaws 17 December, 2007 07:00:17

    With the patch, Apple disables most Flash-handling functionality
    Apple Inc. patched several bugs in QuickTime on Thursday, including a three-week-old streaming media vulnerability for which exploit code has been in circulation since the end of November.
  • +

    New attack proves critical Windows bug 'highly exploitable' 31 January, 2008 08:54:07

    Vista kernel protections no help here, say researchers
    Security researchers Tuesday said they'd discredited Microsoft's claim that the year's first critical Windows vulnerability would be "difficult and unlikely" to be exploited by attackers.
Additional Resources
ARN Library
Newsletter Subscription
Sign up for our ARN newsletters!
RSS Feeds
Market Place
 
Panel Sessions
  • ARN Panel Sessions: Day 3

    The last of our panel sessions recorded live at CeBIT 2008. Today, the topic is storage. Data is growing at an enormous rate, so what does the future hold?

Play
ARN news
Play
Channel Watch
Play
Business Continuity & Disaster Recovery Zone

When an IT disaster occurs, how handy it would be to push a button and start again as if nothing had happened.
Discover and learn more about CA XOSoft today.
ARN Vendor Directory
ARN Library

NAB works with Avanade® to leverage Microsoft® Windows Server® 2008 for its branch offices

In 2007, Avanade helped the National Australia Bank use Windows Server 2008 to simplify deployment, maximise the efficiency of their low-bandwidth wide area network and consolidate its IT infrastructure.

Sponsored Links