News

Microsoft May Release Out-of-Cycle Patch for Word Flaw

Microsoft confirmed "very limited, targeted" attacks on an open Word security flaw. The company is researching a patch.

Late Friday, Microsoft confirmed "very limited, targeted" attacks on an open Microsoft Word security flaw. The company is currently researching a patch -- one that it may not wait for its regular Patch Tuesday to release.

The flaw affects most versions of Word that are not running on Windows Server 2003 SP2, Vista or Vista SP1. Hackers can execute buffer overrun attacks by taking advantage of a flaw in Microsoft's Jet Database Engine (Jet) in Word that can allow the remote execution of code, according to Microsoft's security advisory on the issue. Windows Server 2003 and Vista are not vulnerable as they use a different version of Jet.

Microsoft is also investigating whether other products that use Jet may be vulnerable.

"Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs," the company said.

For now, Redmond has posted a workaround for the flaw in the security advisory that shows administrators how to restrict Jet from running as well as block .MDB attachments through Microsoft Exchange or other mail systems.

Customers could also be infected via the Web if they are lured into visiting a Web site that "contains a specially crafted Word file that is used to attempt to exploit this vulnerability."

Microsoft said that because successfully exploiting the flaw requires "customers to take multiple steps" in order to be affected, the risk is "very limited." A successful attack would mean that the hacker would gain the same rights as the user of the machine.

About the Author

Becky Nagel serves as vice president of AI for 1105 Media specializing in developing media, events and training for companies around AI and generative AI technology. She also regularly writes and reports on AI news, and is the founding editor of PureAI.com. She's the author of "ChatGPT Prompt 101 Guide for Business Users" and other popular AI resources with a real-world business perspective. She regularly speaks, writes and develops content around AI, generative AI and other business tech. She has a background in Web technology and B2B enterprise technology journalism.

comments powered by Disqus

Featured

  • Hands On: New VS Code Insiders Build Creates Web Page from Image in Seconds

    New Vision support with GitHub Copilot in the latest Visual Studio Code Insiders build takes a user-supplied mockup image and creates a web page from it in seconds, handling all the HTML and CSS.

  • Naive Bayes Regression Using C#

    Dr. James McCaffrey from Microsoft Research presents a complete end-to-end demonstration of the naive Bayes regression technique, where the goal is to predict a single numeric value. Compared to other machine learning regression techniques, naive Bayes regression is usually less accurate, but is simple, easy to implement and customize, works on both large and small datasets, is highly interpretable, and doesn't require tuning any hyperparameters.

  • VS Code Copilot Previews New GPT-4o AI Code Completion Model

    The 4o upgrade includes additional training on more than 275,000 high-quality public repositories in over 30 popular programming languages, said Microsoft-owned GitHub, which created the original "AI pair programmer" years ago.

  • Microsoft's Rust Embrace Continues with Azure SDK Beta

    "Rust's strong type system and ownership model help prevent common programming errors such as null pointer dereferencing and buffer overflows, leading to more secure and stable code."

  • Xcode IDE from Microsoft Archrival Apple Gets Copilot AI

    Just after expanding the reach of its Copilot AI coding assistant to the open-source Eclipse IDE, Microsoft showcased how it's going even further, providing details about a preview version for the Xcode IDE from archrival Apple.

Subscribe on YouTube

Upcoming Training Events