Office Zero-Day Bugs Spoil Patch Tuesday

Topics Office on April 11th, 2007

trio of what appear to be new, yet-to-be-patched flaws in Microsoft has surfaced, according to security researchers at McAfee. The vulnerabilities were reported in online security forums on Monday, according to a posting on the McAfee Avert Labs blog on Tuesday.

All but one of the flaws results in denial of service, meaning the application would crash, according to the blog post. “There is one heap-overflow flaw that might be exploited for code execution,” Karthik Raman, a McAfee researcher wrote on the blog on Tuesday. Typically such flaws are exploited by tricking a targeted victim into opening a rigged document.

Microsoft is investigating the bug reports as well, a company representative said in an e-mailed statement. Microsoft is not aware of any attacks that exploit any of the issues at this time, the representative said. Word of the flaws comes on the day that Microsoft issued five security bulletins as part of its monthly patch cycle.

The company is still dealing with the aftermath of an emergency patch released last week “This is yet another time that zero-day flaws have been published around a Patch Tuesday, possibly to maximize the exposure to these flaws until the next month’s Patch Tuesday,” Raman wrote.

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • del.icio.us
  • StumbleUpon
  • Facebook
  • Google
  • Furl
  • Live
  • MisterWong.DE
  • NewsVine
  • Reddit
  • Slashdot
  • Technorati
  • YahooMyWeb
  • BlinkList
  • description
  • Fark
  • Netvouz
  • Spurl
  • MisterWong
  • Webnews.de
  • E-mail this story to a friend!

Tags:, ,

Related posts

Leave a Reply