Office Web Components vulnerability flaps in the breeze

By Angela Gunn | Published July 13, 2009, 4:03 PM

Tomorrow, Microsoft has a Patch Tuesday collection slated to include a fix for a hole known to Microsoft and outside security researchers for nearly a year and a half. Today, Redmond's got another, newly revealed, major flaw to contend with.

The vulnerability in Office Web Components' ActiveX implementation, versions 10 and 11, is currently known to be under attack, according to a post by Fermin J. Serna of Microsoft Security Response Center's Engineering team. If a user running Internet Explorer goes to a malicious Web site that hosts the exploit, the attacker could gain whatever rights the user has (translation: owned) and execute malicious code in the usual fashion.

Neither version 10 nor 11 is part of the default install for anyone's setup. But those who have installed Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components for the 2007 Microsoft Office System SP1, Internet Security and Acceleration Server 2004 Standard Edition SP3, Internet Security and Acceleration Server 2004 Enterprise Edition SP3, Internet Security and Acceleration Server 2006, Internet Security and Acceleration Server 2006, Internet Security and Acceleration Server 2006 Supportability Update, Internet Security and Acceleration Server 2006 SP1, or Office Small Business Accounting 2006 may be vulnerable. (The Serna post offers directions for figuring out if your machine is in danger.)

MS Security Advisory 973472, the official TechNet epistle, has the overview, but the associated KnowledgeBase article has something quicker: A one-click workaround that will stave off disaster until the patch is ready.

Disaster, seriously? Well, as mentioned the vulnerability is attracting 0-day attacks; according to a post by Vanja Svajcer of Sophos, that anti-malware company is already hearing of sites in China that exploit the hole as part of a larger exploit kit. Sophos's analysis rates the vuln as "critical," while Secunia gives it an "extremely critical" label.

The vulnerability lies in a spreadsheet ActiveX control. The Office Web Components allow users to see spreadsheets (or databases or charts) over the Web. The architecture of the new Web applications being built for Office 2010 will render it completely unaffected by this exploit, because they will not use the same ActiveX controls.

In terms of clear and present danger, however, that's really neither here nor there: Experts agree that if you're on a currently vulnerable installation, using the workaround and patching as soon as a patch is available are priority projects for your afternoon.

Comments

View comments by with a score of at least

So...no chance of this being patched today, eh?

Score: 0

|

Nah...

My priority project for this afternoon is cracking open a few beers.

Perhaps I'll tackle the rest tomorrow. (Or more likely get someone else to agree to do it and then later find out they did no such thing...judging by past performances...)

Score: 1

|

Microsoft's Ray Ozzie: 'Nobody's going to be 100% open'

The mobile apps ecosystems of the world may converge over time, led by apps being ported over across platforms, according to the Chief Software Architect.

Will Firefox beat IE9 to Direct2D rendering?

Just days after Microsoft executives gave conference attendees a peek at a new rendering technology, a Mozilla contributor revealed he's working on the same thing.

Where there's smoke: Apple warranty stance raises troubling questions

Carmi Levy | Wide Angle Zoom: Smoking can be dangerous not only for your lungs, it appears, but for your Apple hardware warranty.

AOL's decision to rebrand as Aol. takes a bad brand and makes it worse

The idea behind the social Web is to crowd source before bringing out something new. But not at AOL, which new logo debuted with a cry of "fail!" across the blogosphere and Twittersphere today.

Microsoft 'worked with Apple' for Silverlight on iPhone, says Goldfarb

By not making such a big deal out of trying to stream video to the iPhone, Microsoft got a big deal out of it, revealed the Silverlight product manager.

Clicker.com cuts through the Web video chaos

In a world where homemade video and Hollywood movies travel the same pipeline, it's good to have a real search engine to cut through the clutter.

A case study in improving software: What Office 2010 can learn from Notion 3

A music composition product gambles with a complete overhaul, in an effort to make headway against two well-known competitors in a tough market.

Kindle 2 update adds battery life, native PDF reader

Amazon has pushed out an update to the Kindle 2 e-reader that lengthens battery life and adds a native PDF viewer.

Safari on iPhone gets competition from a $1 browser app

Apple likes to say it gives iPhone users a full browsing experience, but a new competitor tries to incorporate more desktop browser features.

Action Replay maker sues Microsoft for Xbox 360 'predatory technological barriers'

Third-party video game accessory maker Datel has filed an antitrust lawsuit against Microsoft over the Xbox 360's recent Dashboard update.

Microsoft's Bob Muglia and Ray Ozzie on Silverlight vs. standards

Bob Muglia: "We're trying to provide people with an environment that has capabilities that you just simply can't do today in the standards-based world."