This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

New Ms Office Zero-days

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.avertlabs.com/research/blog/?p=253
April 10, 2007 ~ "Some of these flaws may allow for remote code execution. McAfee Avert Labs is investigating all these zero-days. Today is Patch Tuesday for April. So, yes: this is yet another time that zero-day flaws have been published around a Patch Tuesday, possibly to maximize the public’s exposure to these flaws until the next month’s Patch Tuesday.
Update, 2pm PST
Further research by Avert Labs indicates that all but one of the Office zero-days reported yesterday result in denial of service. There is one heap-overflow flaw that might be exploited for code execution. We’ll keep you updated.
Update, 5pm PST
Avert Labs has been analyzing proof-of-concept code for a zero-day vulnerability in Microsoft Windows’s handling of HLP files. This is another heap-overflow flaw that might be exploited for code execution. Stay tuned."

- http://news.com.com/2102-1002_3-6175011.ht…g=st.util.print
Apr 10 2007 ~ "… McAfee is still investigating the security vulnerabilities. They may not actually all be new, said Dave Marcus, security research and communications manager at (McAfee). "Sometimes what people claim to be zero-days may in fact be related to something that's already known," he said. Should the three Office bugs be new, the tally of zero-day vulnerabilities in the productivity suite waiting for a fix would jump to five. Microsoft did not deliver any patches for Office on Tuesday*…"

* See: http://forums.tomcoyote.org/index.php?s=&a;…st&p=367363

:ph34r:
FYI…

- http://www.theregister.com/2007/04/11/new_…osoft_zerodays/
11th April 2007 ~ "…Microsoft says it is investigating the reports and isn't aware of any customers being targeted by the flaws. It also reiterated an advisory* deeming .HLP files as unsafe unless the user is assured they are not malicious…"

Overview of unsafe file types in Microsoft products
* http://support.microsoft.com/kb/925330/en-us

- http://support.microsoft.com/kb/883260

.
FYI…

- http://isc.sans.org/diary.html?storyid=2688
Last Updated: 2007-04-24 16:18:55 UTC ~ "On Monday in an article* in USA Today the title reads “Cyberspies exploit Microsoft Office”. The article states that the CyberSpies have tainted Microsoft Office files and are emailing them to specific organizations in hopes that the unsuspecting employee will open the attachment, infect their computer thus opening a hole which the attacker can then use to explore in the infected network and look for trade secrets, military secrets, passwords, etc. MessageLabs in an interview with USA Today said that it has intercepted assaults coming from Taiwan and China since November 2006. It appears that the targets are Federal Agencies, Defense and Nuclear contractors. In a quote from the article, our own Alan Paller at Sans Institute says:
“Assaults are coming from China and perhaps other countries in the hunt for military, trade and infrastructure intelligence, says Alan Paller, research director at The SANS Institute, a security think tank. The goal: strategic advantage over the USA. "The attacks are working," says Paller. "Penetrations are deep and broad"…"
* http://www.usatoday.com/tech/news/computer…ft-office_N.htm

.