Microsoft explains missing Mac Office patches
Defends move, but won't say when it will fix Office for Mac 2004, 2008
Computerworld - Microsoft today explained why it has not patched older versions of its Office for Mac, but would not disclose a release schedule for doing so.
"We cannot give an exact date, but we expect to provide these updates during one of our normal monthly update cycles very soon," said Jerry Bryant, a group manager in the Microsoft Security Response Center (MSRC).
Bryant was responding to questions raised Tuesday when Microsoft issued a multi-patch update for all versions of Office on Windows, including Office XP, 2003, 2007 and 2010, and Office for Mac 2011.
However, Microsoft did not deliver patches for the vulnerabilities in Office for Mac 2004 and Office for Mac 2008.
"The updates for Mac Office 2004 and 2008 were not ready for broad distribution at the same time as the updates for the affected products used by the vast majority of our customers," said Bryant in an e-mail reply to Computerworld queries.
The majority of Office users run the Windows editions of the suite, which greatly outsells the same software for Mac OS X.
According to the MS10-087 security bulletin associated with the Office updates, Office 2007 and Office 2010 users are most at risk because attackers can hijack their machines simply by getting them to view a specially-crafted message in the Outlook preview pane.
In a second e-mail Wednesday, Bryant said that Office for Mac users were not vulnerable to the same types of attacks, although hackers could try to dupe them into opening malicious RTF (rich text format) documents attached to e-mail messages.
Microsoft has delayed security updates for the Mac version of Office before.
In May 2009, Microsoft shipped patches for the Windows version of PowerPoint -- Office's presentation maker -- but delayed fixes for the same flaws in its Mac software until the following month.
At the time, Microsoft's security team defended the decision by saying that fixes for Windows were finished, but were still being tested on the Mac.
Today, Bryant said it was a matter of priorities, both in the number of users running Windows software compared to the Mac, and in the threat posed to each group. "Normally, we release updates for all affected products at the same time, [but] in cases where the vast majority of our customers are at potential risk and we can provide protections, we may decide to release updates for those products, if ready, ahead of products where the risk is very low," he said.
Last year, Microsoft took heat over the PowerPoint patch delay, with one security expert saying it put Mac users at risk. Others agreed with Microsoft's decision at the time.
- 15 Non-Certified IT Skills Growing in Demand
- How 19 Tech Titans Target Healthcare
- Twitter Suffering From Growing Pains (and Facebook Comparisons)
- Agile Comes to Data Integration
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- The 12 PCI DSS 3.0 requirements addressed by Peer 1 Hosting This handy quick reference outlines the 12 PCI DSS 3.0 requirements, who needs to be compliant and how Alert Logic solutions address the...
- Defense Throughout the Vulnerability Life Cycle This whitepaper provides insight into how to leverage threat and log management technologies to protect your IT assets throughout their vulnerability life cycle.
- Mobile Policy Checklist Here's what to consider when putting together a mobile policy designed to support a highly productive workforce.
- Securing BYOD Mobile computing is becoming so ubiquitous that people no longer bat an eye seeing someone working two devices simultaneously. Individuals and organizations are...
- Live Webcast On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy...
- Live Webcast Endpoint Backup & Restore: Protect Everyone, Everywhere Arek Sokol from the bleeding-edge IT team at Genentech/Roche explains how he leverages cross-platform enterprise endpoint backup in the public cloud as part...
- Streamline Software Asset Management, Compose a software Management Symphony Keeping track of your organization's software is easy with effective software management solutions from CDW. View the videos in our software solutions channel
- Druva inSync: Endpoint Data Protection & Governance CLICK HERE to watch this video about protecting corporate data on laptops and mobile devices, sponsored by Druva. All Security White Papers | Webcasts