Skip the navigation
News

Researchers warn of likely attacks against Windows, PowerPoint

Hackers will jump on several of the bugs Microsoft patched today

By Gregg Keizer
February 9, 2010 04:12 PM ET

Computerworld - Some of the bugs Microsoft patched today will be exploited by hackers almost immediately, security researchers predicted.

Microsoft's massive update -- a record-tying 13 separate security bulletins that patched 26 vulnerabilities -- gives attackers all kinds of ways to compromise machines and hijack PCs.

Even Microsoft said so: 12 of the 26 vulnerabilities, or 46% of the total, were tagged with a "1" in the company's exploitability index, meaning that Microsoft figures they will be exploited with reliable attack code in the next 30 days.

But some of the flaws will be exploited long before others, said researchers interviewed today.

"The vulnerabilities in MS10-006 and MS10-012 will probably be exploited in just a few days," said Jason Avery, manager of TippingPoint's Digital Vaccine group. "I think exploits for the PowerPoint vulnerabilities [in MS10-004] will also be disclosed within a few days, based on the information we have from ZDI and what we've heard through MAPP."

TippingPoint's Zero Day Initiative (ZDI) -- one of the two major bug bounty programs in the U.S. -- reported information about two of the six PowerPoint flaws to Microsoft. MAPP (Microsoft Active Protection Program) provides technical information about the vulnerabilities it plans to patch to vetted security software developers prior to the release of those updates.

MS10-006 and MS10-012 both involve SMB (Server Message Block), Windows file- and print-sharing protocols, but are not related. Avery based his bet of quick exploitation on the fast hacker reaction to a patch in October 2008. Then, attacks quickly used an exploit of MS08-067, a patch to Windows Server service, to hijack millions of PCs with the Conficker malware.

The PowerPoint update, MS10-004, was also pegged today by Jason Miller, security and data team manager of patch management vendor Shavlik Technologies, as one that hackers will gravitate toward.

"PowerPoint Viewer 2003 is affected, but Microsoft's not patching it," said Miller, referring to the free viewing tool that lets people who don't have the presentation maker view slideshows. "Microsoft's finally putting its foot down and saying that [Viewer 2003] is past its lifecycle, and that everyone should upgrade to PowerPoint Viewer 2007." But if word doesn't get out, users running the older version of the utility can be attacked at will, something attackers will surely use, Miller added.

Microsoft seconded Miller's concern over the PowerPoint flaws. "It should be a priority for customers who have standalone installations of the PowerPoint Viewer 2003 to migrate to supported releases to prevent potential exposure to vulnerabilities," the company's accompanying bulletin read. "PowerPoint Viewer 2007 is not affected by the vulnerabilities described in this bulletin and is available from the Microsoft Download Center.



Patch Tuesday

Additional Resources
Advancing Knowledge Sharing with Google: The LSNC Story
WEBCAST
In the modern work environment, knowledge sharing has become paramount to organizational success, given the geographic dispersion, mobility, and information overload. During this session, Legal Services of Northern California (LSNC) will discuss their recent knowledge sharing transformation. With employees across 14 offices, servicing one-third of California, and having to access information across a million documents, the challenge was daunting. To address this, LSNC tapped Google's expertise on enterprise search and cloud computing, and deployed a knowledge-content system.
Cost-Effective Virtualization Security
WHITE PAPER
Trend Micro(tm) Virtualization Security solutions deliver advanced security software to protect operating systems, applications and data on virtual and cloud servers to help ensure compliance, while allowing higher server consolidation rates, and maximizing performance and operational flexibility. With Trend Micro software deployed on your physical servers and virtual machines, your IT infrastructure receives comprehensive and integrated protection.
The Laptop Dilemma: How to Maximize Productivity and Lower the Burden on IT
WHITE PAPER
New era of mobile computing creates opportunities for remote productivity while next-generation, industry-standard technologies address management and data security. Read more in this white paper.
What People Are Saying
Security White Papers
Backup and Disaster Recovery eGuide
As the digital universe grows beyond imagination, enterprise IT executives face the daunting task of keeping their little pieces of it backed up...
Forrester Research: Know your Facts: Understanding The Realities Of Desktop And Application virtualization
Read Now.
Windows 7 Migration Made Easier with Desktop Virtualization
Read Now.
Virtualization 2.0: The Desktop Revolution
Read Now.
Securing Data in the Cloud
This document is intended to give a broad overview of our security policies, processes and practices.
All Security White Papers
Security Webcasts
Desktop virtualization keys innovation drive
View now.
Survival Guide: Overcoming the Obstacles to Effective Risk Management
This virtual meeting for IT managers and CIOs is based on a new IBM study. Senior Vice Presidents and a Chief Technology Officer...
The Evolution of Managed File Transfer
Managed file transfer has evolved greatly from its earliest meaning of scheduled FTP to today's meaning of complete file governance, including visibility, enforcement,...
How to cut software management costs and avoid over-spending in the future
View now!
Get a $20 Amazon Gift Card - Just watch a Demo
View now!
All Security Webcasts
IT Jobs