Microsoft targets Office with four patches next Tuesday
By Miya Knights,
Microsoft said late yesterday it was readying four patches for every supported version of the company's Office business suite next week.
The patches have been given the company's highest 'critical' security rating in its 'Patch Tuesday' preview notice, addressing vulnerabilities in Office 2000, Office XP, Office 2003, Office 2007, Office 2004 for Mac and Office 2008 for Mac.
It is the first time the software vendor has released a set of bulletins related to Office that are all rated critical. But it was also the target of four out of the eleven updates from last month's bumper set of patches.
Microsoft is traditionally very guarded about releasing vulnerability details before the monthly patch cycle and security analysts have been reluctant to speculate over which Office flaws may be behind each update or whether they are already publicly known.
From the notice, it is known that one of the updates affects all currently supported versions of the Office email client, Outlook. Andrew Storms, director of security operations at nCircle Network Security said in a blog that this probably rules out a format parsing problem with Office file formats, which have proved an ongoing fertile source of vulnerabilities for malware writers.
"It looks to me like it's a problem more inherent to Outlook [itself], something deeper in the code," he said.
The other three deal with flaws in the ActiveX controls Microsoft Office Web Components 2000 used for publishing Office 2000 documents on the web, an Excel file format and the Office spreadsheet application.
Microsoft also said it would issue three high priority, non-security related updates with the critical patches at 1 pm Eastern US time (6pm GMT), next Tuesday 11 March.
advertisement
Latest Security Features
Top 10 security predictions for 2009
What will next year hold in the ever-changing world of IT security?
- Top 10 reviews of 2008
- The year in IT news
- Top 10 security stories of 2008
- PCI's Bob Russo: Data loss hurts brand more than a fine
- How to be a successful online fraudster
- What you need to know about ID cards
- Lessons to learn from a year of data breaches
- Q&A: DNS inventor Paul Mockapetris
- Is the password ill-equipped for the modern world?
Latest Security Reviews
EXCLUSIVE - eSoft ThreatWall 250
Rating: ![]()
advertisement
Latest News Videos in Security
Video: Mobile security threats and Mac complacency
Part two: Eugene Kaspersky, chief executive and founder of Kaspersky Lab, talks about the increasing security threats mobile users are facing.
White papers
Want more background on today's hottest IT trends?
Visit IT PRO's white paper library for more on virtualisation, encryption and other topics.
Register for IT PRO
You'll get exclusive member benefits including free white papers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.



Social Bookmark this article: What is this?