Skip the navigation
)
News

Microsoft Update keeps Office secure, says researcher

56% of Office attacks in second half of 2009 hit copies last updated in 2003

April 27, 2010 12:05 PM ET

Computerworld - A move Microsoft made nearly five years ago has kept users of the company's Office suite safer, a security researcher contended today.

Richie Lai, director of vulnerability research at security company Qualys, credited Microsoft's creation of the optional Microsoft Update service in June 2005 for making sure that more Office users keep their applications up-to-date.

"There was a time when Microsoft had only Office Update," Lai said, referring to Microsoft Update's predecessor. "Then, older versions [of Office] needed to be updated separately from Windows."

Lai was reacting to Microsoft's newest "Security Intelligence Report", published yesterday. In the report, Microsoft cited the growth in Microsoft Update use, a service that combines automatic updates for Windows -- which can also be obtained through the better-known Windows Update service -- with fixes, patches and service pack updates for Office. Microsoft Update use increased 16% in the second half of 2009 compared to the first six months of the year, the company said.

Before mid-2005 and Microsoft Update, Office users needed to run two update services -- one for Windows, another for Office -- to keep their operating systems and applications up-to-date. (Microsoft retired Office Update in July 2009 as part of an effort to streamline its patching programs.) The dual -- and dueling -- services were also responsible for many older editions of Office left unpatched, Lai argued, a fact that Microsoft also promoted as it made a case for keeping the suite updated.

"People who haven't updated their [copies of Office] are the most at risk, obviously," said Lai. "Older editions of Office did without the automatic updates of Microsoft Update." Office 2003 Service Pack 2 (SP2), which launched in September 2005, was the first major upgrade that allowed users to access Microsoft Update rather than the Office-only update service, he noted.

Lai attributed the vulnerability of older versions of Office, particularly Office 2003, to the lack of a combined Windows-Office update service when the suite debuted in late 2003. "That shipped without a way to do automatic updates alongside Windows," he said.

Microsoft's own data supported Lai's contention that Office Update was ignored by some users. According to the company, 56% of all attacks in a sample of successful Office hacks during the second half of 2009 affected copies that had last been updated in 2003. "Most of these attacks involved Office 2003 users who had not applied a single service pack or other security update since the original release of Office 2003," the report stated.

By comparison, just 2.3% of the attacks in the sample set involved copies of Office that had been updated at some point in the last four years.



What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Applications White Papers
Establishing a Strategy for Database Security is No Longer Optional
The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three...
Driving Secure Enterprise File Sharing and Syncing in the Enterprise
GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
The Enterprise File Sharing Option
Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
Activities Streams Base An Integrated Social Layer
The enterprise social software market is exploding thanks to converging trends of consumerization, cloud, and mobile. In this must-read report, "The Forrester Wave:...
Converged Infrastructure for Dummies
As you know, everything is mobile, connected, interactive, and immediate. This is exactly why organizations need a highly agile IT infrastructure in order...
All Applications White Papers
Applications Webcasts
Delivery Management -- Extending Lifecycle Management
Date: Wednesday, June 20, 2012, 1:00 PM EDT

Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,...
Leverage automation today to reduce IT complexity
Date: Tuesday, June 5, 2012, 2:00 PM EDT

Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific...
BMC Control-M - Single Point of Control Demo
With BMC Control-M, you schedule and manage everything - down to the very last platform and application - from one simple interface. It's...
Operational Analytics - Changing the Competitive Dynamics of the Business
Date/Time: June 5, 2012, 11:00 a.m., EDT, 4:00 p.m. BST / 3:00 p.m. UTC

Please join us for this webcast, as Dr. Barry...
Oracle Database Appliance Best Practices
Business users increasingly demand 24x7 availability of their data while IT departments face the challenge of ensuring maximum availability while operating with limited...
All Applications Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs