SeattleTechGroup: Tech news and notes

Microsoft Security Advisory Update

Microsoft is still working on a solution that is fit for wide distribution. In the meantime they still are using their workaround directions.

Also posted here is a list of products affected:

Link to Microsoft Security Advisory

Direct link to their work-around fix

“This is Dave Forstrom, group manager for our security response communications team. We have just posted Microsoft Security Advisory 973472, which highlights a vulnerability in Microsoft Office Web Components. Specifically, the vulnerability exists in the Spreadsheet ActiveX control and while we’ve only seen limited attacks, if exploited successfully, an attacker could gain the same user rights as the local user.

Products affected are:

Microsoft Office XP Service Pack 3,

Microsoft Office 2003 Service Pack 3,

Microsoft Office XP Web Components Service Pack 3,

Microsoft Office Web Components 2003 Service Pack 3,

Microsoft Office 2003 Web Components for the 2007 Microsoft Office system Service Pack 1,

Microsoft Internet Security and Acceleration Server 2004 Standard Edition Service Pack 3,

Microsoft Internet Security and Acceleration Server 2004 Enterprise Edition Service Pack 3,

Microsoft Internet Security and Acceleration Server 2006,

Internet Security and Acceleration Server 2006 Supportability Update,

Microsoft Internet Security and Acceleration Server 2006 Service Pack 1,

Microsoft Office Small Business Accounting 2006.”

You can follow any responses to this entry through the RSS 2.0 feed.