07/13/2009

new windows Office zeroday making the rounds (with fix-it link)

Microsoft is investigating a privately reported vulnerability in Microsoft Office Web Components. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. When using Internet Explorer, code execution is remote and may not require any user intervention

Affected Software

Microsoft Office XP Service Pack 3

Microsoft Office 2003 Service Pack 3

Microsoft Office XP Web Components Service Pack 3

Microsoft Office 2003 Web Components Service Pack 3

Microsoft Office 2003 Web Components for the 2007 Microsoft Office system Service Pack 1

Microsoft Internet Security and Acceleration Server 2004 Standard Edition Service Pack 3

Microsoft Internet Security and Acceleration Server 2004 Enterprise Edition Service Pack 3

Microsoft Internet Security and Acceleration Server 2006

Internet Security and Acceleration Server 2006 Supportability Update

Microsoft Internet Security and Acceleration Server 2006 Service Pack 1

Microsoft Office Small Business Accounting 2006

Non-Affected Software

Microsoft Office 2000 Service Pack 3

2007 Microsoft Office Suite Service Pack 1 and 2007 Microsoft Office Suite Service Pack 2

http://www.microsoft.com/technet/security/advisory/973472...

You can fix it with a click here

http://support.microsoft.com/kb/973472

There is talk that the patch for the activex is expected for tomorrow - or maybe even today somewhere else in the world (we don't live in countries anymore on the web but in timezones)

15:44 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

Post a comment