internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Adobe Flash Player

Most Popular Software Downloads
Windows Vista Service Pack 2 (Vista SP2)
Mozilla Firefox 3
QuickTime for Windows
Adobe Flash Player
Windows 7
Norton Internet Security 2010
Internet Explorer 8
CCleaner (Crap Cleaner)
Winamp
Skype

Most Popular Software Articles
Windows Vista Tips: Home Networking Setup Tutorial
10 Must-Have Apps: The Free Windows Networking Toolkit
How to Make Your Internet Connection Faster, Better


Software Reviews

Microsoft Patches PowerPoint Zero-Day
May Patch Batch Closes Critical Security Hole in PowerPoint
Stuart J Johnston

As expected, Microsoft today closed a security hole in its PowerPoint presentation software, with a fix in its latest regular monthly installment of "Patch Tuesday" updates.

The patch addresses a glitch that Microsoft ranks as "critical," the highest ranking on its four-tier severity scale.

The zero-day (define) vulnerability had first been called to Microsoft's attention in early April. Microsoft then issued a Security Advisory — an official acknowledgment that the company's security team is tracking a bug — about attacks using the vulnerability.

The zero-day hole had been discovered, and live attacks detected, just before Microsoft's April Patch Tuesday. For several years, Microsoft has been releasing almost all of its patches on the second Tuesday of each month to provide users, particularly IT shops, with predictable and regular patch drops. But the timing of the zero-day's discovery meant that it missed cut-off for inclusion in April's round of updates.

The patch fixes a total of 14 separate vulnerabilities in all supported versions of Office PowerPoint — from Office 2000 Service Pack 3 (SP3) up through Office 2007 SP2. Of those, 12 rate a critical designation.

However, the only version of PowerPoint in which Microsoft rates the bugs as "critical" is the oldest — PowerPoint 2000 SP3. For later versions, up to and including PowerPoint 2007, the bugs rate as "important" — the second-highest Microsoft threat level.

That does not mean that "important" means "not to worry," though. Often, the difference between a ratings is a question of one or two extra mouse clicks.

Several top security analysts, therefore, warned against complacency and urged users to apply the patch to all versions of PowerPoint.

"Although Microsoft only dropped one patch for PowerPoint this month, IT administrators shouldn't get the wrong impression and breathe easy given the light load," Paul Henry, security and forensic analyst for Lumension, said in an e-mail to InternetNews.com.

In fact, being too complacent could leave even a savvy user open to attacks that, once inside the firewall, could spread havoc, said another security analyst.

"A single e-mail with a malicious PowerPoint attachment exploiting these vulnerabilities could be enough to compromise the desktops of enough critical personnel to cripple even a large enterprise," Tas Giakomuniakis, CTO at Rapid7, told InternetNews.com in an e-mail.

As a key component of Office, the sheer ubiquity of PowerPoint inside corporations means that even a bug tagged as important is still a threat to be dealt with.

"We think it's very important to install the patch," Qualys' CTO Wolfgang Kandek told InternetNews.com.

With the PowerPoint vulnerabilities, all a user would need to do to trigger an attack is to open a booby-trapped PowerPoint file — delivered either in an e-mail or instant message, or through a malicious Web site.

Windows 7 RC Real and "Fake" Updates

It's the second round of patches for a major Microsoft offering in days. The company on Friday released a "hotfix" for the Windows 7 "Release Candidate" (RC), which began public testing last week.

Users testing the RC of Windows 7 — specifically, Windows 7 32-bit Ultimate — should install Friday's hotfix, but only if they are affected by the bug it's meant to fix, according to a Microsoft statement.

The Windows 7 RC of 32-bit Ultimate is missing some "security descriptors," the lack of which do not allow the user to perform some user-level functions such as deleting a folder.

"This problem occurs because the English version of Windows 7 Release Candidate 32-bit Ultimate incorrectly sets access control lists (ACLs) on the root," the company.

Additionally, beginning today, Microsoft plans to release as many as ten test updates for Windows 7. The updates — which do not actually update any system software — are meant to check to make sure that the RC properly supports Microsoft's Windows Update system.

The updates aim "to verify our ability to deliver and manage updating of Windows 7 in certain real-life scenarios. These updates do not deliver any new features or fixes," Microsoft's Brandon LeBlanc wrote in a post on the Windows 7 Team blog.

This will be the second test of the feature. Microsoft released a similar set of dummy updates for the beta of Windows 7 back in February.

News courtesy of internetnews.com

May 17, 2009

Download Microsoft Windows Malicious Software Removal Tool Now!Download

View All Microsoft Service & Security Releases

Contents:
1. May Patch Batch Closes Critical Security Hole in PowerPoint


Additional Articles:

  • Microsoft Issues Major Patch Release in Feb. Cycle
  • Mini-Patch Day for Microsoft
  • Full Plate of Microsoft Patches Expected
  • Microsoft Plugs 10 on Patch Tuesday
  • Critical Windows Patch Around the Corner
  • Warily Watching Worm Variants
  • 'Critical' Patch Released For Windows
  • Microsoft Patches Newest 'Dirty Dozen'
  • Zombies Control Half of Windows PCs
  • Six Fixes on Tap from Microsoft
  • An 'Important' Patch Tuesday
  • Patch Tuesday Targets 'Mammoth' Set of Flaws
  • Microsoft Rates Patched Flaws by Exploitability
  • Microsoft Nabs 28 Flaws in Year's Last Patch Haul
  • Microsoft Fixes IE in February Patch Update
  • Patch Tuesday Won't Fix Excel Hole
  • Microsoft Patch Tuesday Shores Up DNS
  • Microsoft Has Eight Patches on Tap For Tuesday
  • Six Critical Microsoft Patches Coming Tuesday
  • 'Patch Tuesday' Will Fix ActiveX Zero-Day
  • Microsoft Plays Catch-Up with Biggest Patch Drop
  • Microsoft's Patch Tuesday Targets Fewer Holes


  • internet.commediabistro.comJusttechjobs.comGraphics.com

    Search:

    WebMediaBrands Corporate Info

    Legal Notices, Licensing, Permissions, Privacy Policy.
    Advertise | Newsletters | Shopping | E-mail Offers | Freelance Jobs