Office Web Components vulnerability flaps in the breeze

By Angela Gunn | Published July 13, 2009, 4:03 PM

Tomorrow, Microsoft has a Patch Tuesday collection slated to include a fix for a hole known to Microsoft and outside security researchers for nearly a year and a half. Today, Redmond's got another, newly revealed, major flaw to contend with.

The vulnerability in Office Web Components' ActiveX implementation, versions 10 and 11, is currently known to be under attack, according to a post by Fermin J. Serna of Microsoft Security Response Center's Engineering team. If a user running Internet Explorer goes to a malicious Web site that hosts the exploit, the attacker could gain whatever rights the user has (translation: owned) and execute malicious code in the usual fashion.

Neither version 10 nor 11 is part of the default install for anyone's setup. But those who have installed Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components for the 2007 Microsoft Office System SP1, Internet Security and Acceleration Server 2004 Standard Edition SP3, Internet Security and Acceleration Server 2004 Enterprise Edition SP3, Internet Security and Acceleration Server 2006, Internet Security and Acceleration Server 2006, Internet Security and Acceleration Server 2006 Supportability Update, Internet Security and Acceleration Server 2006 SP1, or Office Small Business Accounting 2006 may be vulnerable. (The Serna post offers directions for figuring out if your machine is in danger.)

MS Security Advisory 973472, the official TechNet epistle, has the overview, but the associated KnowledgeBase article has something quicker: A one-click workaround that will stave off disaster until the patch is ready.

Disaster, seriously? Well, as mentioned the vulnerability is attracting 0-day attacks; according to a post by Vanja Svajcer of Sophos, that anti-malware company is already hearing of sites in China that exploit the hole as part of a larger exploit kit. Sophos's analysis rates the vuln as "critical," while Secunia gives it an "extremely critical" label.

The vulnerability lies in a spreadsheet ActiveX control. The Office Web Components allow users to see spreadsheets (or databases or charts) over the Web. The architecture of the new Web applications being built for Office 2010 will render it completely unaffected by this exploit, because they will not use the same ActiveX controls.

In terms of clear and present danger, however, that's really neither here nor there: Experts agree that if you're on a currently vulnerable installation, using the workaround and patching as soon as a patch is available are priority projects for your afternoon.

Comments

View comments by with a score of at least

So...no chance of this being patched today, eh?

Score: 0

|

Nah...

My priority project for this afternoon is cracking open a few beers.

Perhaps I'll tackle the rest tomorrow. (Or more likely get someone else to agree to do it and then later find out they did no such thing...judging by past performances...)

Score: 1

|

Google Chrome 4: Yes, it's fast, but is it usable?

As Betanews readers have responded to our stories about Chrome's JavaScript superiority...Does that mean we'd actually use this browser? Well...

Video: Netflix on PlayStation 3

Netflix has come to the PlayStation 3 via Blu-ray and BD-Live.

Verizon Wireless launches new Android, Chocolate, and ruggedized phones

The lower-priced Eris joins the Droid, while the Chocolate gets a touchscreen and more music playback.

Early sales figures for Windows 7 nicely high, but do we know why?

Fans of triple-digit surges in figures quoted by Betanews will love this one, as it appears Microsoft rediscovered how to pull off a software launch.

Myka announces its latest Linux-based 'net top box'

Myka's ION brings Boxee, XMBC, and much more to HDTVs.

What hath Mac wrought? A remembrance after a quarter-century

The reason there's a Macintosh today is not because of some brilliant flash of engineering genius, but because Apple had the audacity to learn from its mistakes.

Early build of Moblin 2.1 improves connectivity, but not device support

The Linux Foundation's Atom-centric OS yesterday received a major overhaul with the project release of Moblin 2.1 for netbooks and nettops.

The iPhone's China syndrome: Sales of 5,000 and climbing

There's actually a country where Apple's device is not a godsend, where sales can be measured in the dozens.

New European counterpart to FCC will ensure 'a more neutral net'

Late Thursday night, the ruling telecom administrators of the EU's member nations signed away their final authority to a new entity overseen by the EC.

Sophos study suggests Windows 7 UAC's default setting is self-defeating

Without any anti-virus installed, a Sophos test showed, User Account Control was only capable of thwarting just one malware package out of ten samples chosen.

Indiscreet tweet trips awareness of Web SSL vulnerability

A group of high-level security engineers had been making progress on thwarting a low-level threat to the Web, until somebody blurted it all out on Twitter.