Microsoft
Microsoft has revealed more details about the Office Jet attack
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Microsoft updates Office Jet attack advisory

Company provides background on new Office attack

Shaun Nichols in California, vnunet.com 26 Mar 2008
ADVERTISEMENT

Microsoft has shed further light on last week's attacks on the Office Jet database component.

The company issued an update to its original security advisory, in which Microsoft Security Response Center manager Mike Reavey provided more information about the attack and how it differs from previous threats.

Security researchers had noticed that the attack exploits MDB files which Microsoft had previously deemed "unsafe" and attempts to shield itself from discovery.

Reavey explained that the attackers had found a new way to access the files, allowing them to hide the threat in a Word file.

"Everything changed with the discovery of this new attack vector that allowed an attacker to load an MDB file via opening a Microsoft Word document," wrote Reavey. "The previous guidance does not work against this new attack."

Reavey claimed that Microsoft has developed a new version of the MS Jet component which is protected from the attacks.

The updated component is already in use by Windows Vista and Server 2003. Windows XP SP3 will also contain a fix when it ships later this year. Office 2003 SP2 is also protected.

Reavey said that Microsoft is considering including a fix in a later security update. He also offered a couple of security tips.

"Enterprise administrators can block Jet files, even those renamed from MDB, at the gateway," he said.

"For end-users, we will continue to recommend that you never, ever open atta chments received unexpectedly."

See also:

ABI predicts bright future for PCs at the heart of connected homes  25 Mar 2008
MicrosoftRedmond buys in more security expertise  25 Mar 2008
Windows VistaUsers complain of service pack gremlins  20 Mar 2008

All Bugs & Fixes
Tags: Microsoft, Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
United Kingdom | Slough Borough Council
Information Systems and Technologies Joining our highly rated Council, you'll help shape the future of Information Systems and be involved with exciting developments across the Council such as implementing new IT systems, going LIVE with ... more >
London, United Kingdom | London School of Economics
Development Manager, London, £45,585 - £52,806 PA LSE is a cosmopolitan community in the centre of London focusing on the study of the social sciences. With a centralised delivery model IT Services provides information technology ... more >
United Kingdom | UKCRN
Technical Author, Leeds You'll be part of a team within our UKCRN Coordinating Centre, working closely with different members of staff on specific initiatives and also with core clinical and management staff. You will liaise ... more >
London, United Kingdom | ACAS
Business Applications Analyst, London, £28,683 - £38,470 The Advisory, Conciliation and Arbitration Service (ACAS)] is a publicly-funded body with over 30 years experience of working with employers, employees and trade unions to deliver better employment ... more >
More job opportunities