Two new Security Advisories

I just want to make sure you have seen it:

  • There were some reports in the last day or two about targeted attacks on Excel. We are aware of these reports and are looking into this. In order to give you our assessment of the situation, we published Microsoft Security Advisory (968272)
    • From what we know so far, an attacker who could exploit this vulnerability could get the privileges of the logged on user. So, if you are not Admin, this would lower the risk.
    • This attack goes after the binary version of Excel files. So, if you are saving the file with the Office 2007 format (.xlsx) the attack does not work.
    • You should definitely look into the workarounds mentioned in the Advisory.
  • The second advisory is about an update for Windows AutoRun (Microsoft Security Advisory (967940))

Roger

Related posts:

  1. Two Important Changes Today to Our Bulletin Process
  2. New Information on SQL Injection Attacks
  3. Microsoft Advisory for Safari Flaw
  4. Two Important Whitepaper on Windows Server 2008
  5. 0-Day-Patch – An new Metric for Security?

Leave a Reply

  

  

  

You can use these HTML tags

<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Calendar

February 2009
M T W T F S S
« Jan   Mar »
 1
2345678
9101112131415
16171819202122
232425262728