September 04, 2003

Microsoft issues Office security warnings

'Critical' flaw in VBA potentially allows attackers to run code on a victim's computer

Microsoft Corp. on Wednesday warned of several flaws in its ubiquitous Office products, the most serious of which could allow an attacker to take control of a user's computer.

Deemed "critical" is a flaw in Visual Basic for Applications (VBA), a technology that is part of Microsoft Office products and used to run customized applications on top of Office. A flaw exists in the way VBA checks the properties of a document when it is opened in an Office application, potentially allowing an attacker to run code on a victim's computer, Microsoft said in security bulletin MS03-037. (See http://www.microsoft.com/technet/security/bulletin/MS03-037.asp)

To exploit the flaw, an attacker would have to get a victim to open a specially crafted document. This could be any document type that supports VBA, including Word, Excel, or PowerPoint documents, Microsoft said. Also, if Word is used as the e-mail editor for Outlook, the default setting in Office XP/2002, an attacker could strike via e-mail. The attack would only be successful if the recipient forwards or replies to the e-mail message, Microsoft said.

The VBA flaw affects Access, Excel, PowerPoint and Word in Microsoft Office 97, 2000 and XP/2002 as well as Word 98, Project 2000 and 2002, Publisher 2002, Visio 2000 and 2002, Works Suite 2001, 2002 and 2003 plus several Microsoft Business Solutions products that also include VBA, Microsoft said.

Microsoft urges users of the affected products to patch at their earliest available opportunity. Users of more than one affected product may have to apply multiple software fixes, Microsoft said.

In addition to the VBA flaw, Microsoft also warned of three more security vulnerabilities in Office products, two carrying an "important" severity rating and one "moderate."

Rated important is a flaw in Word that could result in macros running automatically, instead of asking the user first or going by the level of macro security a user has set, Microsoft said in Security Bulletin MS03-035. (See http://www.microsoft.com/technet/security/bulletin/MS03-035.asp)

Macros are executable code meant to automate commonly-performed tasks and can perform any action a user can on a PC. An attacker could create a malicious document that automatically runs a macro when opened, Microsoft said.

The flaw affects Word versions 97, 98, 2000, and XP/2002 as well as the Works Suite versions 2001, 2002, and 2003, Microsoft said.

Also important is a buffer overrun vulnerability in the WordPerfect Converter that is part of Office 97, 2000 and XP/2002 as well as Word 98, FrontPage 2000 and 2002, Publisher 2000 and 2002 and the Works Suite versions 2001, 2002 and 2003, Microsoft said in Security Bulletin MS03-036. (See http://www.microsoft.com/technet/security/bulletin/MS03-036.asp)

The converter does not correctly validate certain parameters when opening a WordPerfect document. As a result, an attacker could craft a special WordPerfect document that would allow code to run on a computer when opened with an application that uses the converter, Microsoft said.

The last of the four flaws detailed Wednesday is rated moderate and affects the Access Snapshot Viewer, a tool used to view Access databases without Access installed on a computer, Microsoft said in Security Bulletin MS03-038. (See http://www.microsoft.com/technet/security/bulletin/MS03-038.asp)

Access Snapshot Viewer comes as part of all versions of Office, but is not installed by default. It is also offered online so users who do not have Access can still view Access databases, Microsoft said.

The flaw lies in an ActiveX control used by the viewer. To exploit the flaw, an attacker would have to lure a user to a Web page containing special code, Microsoft said.

Microsoft has a four-tiered system for rating security issues. Vulnerabilities that could be exploited to allow malicious Internet worms to spread without user action are rated critical. Issues that are rated important could still expose user data or threaten system resources. Vulnerabilities rated moderate are hard to exploit because of factors such as default configuration or auditing, or difficulty of exploitation, according to Microsoft.

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

additional resources
White Paper - How to Improve Delivery of Advanced Web Applications

White Paper

Virtual Workforce: The Key to Expanding The Business While Cutting Costs

Get the independent advice and expertise you need to support a virtual workforce.

Go inside:
The three-step approach to making a virtual workforce a reality.
The four flavors of client virtualization technologies.
The three key initiatives that solve IT challenges.
Download now »
White Paper: Successfully Secure Your Wireless LAN With Wi-Fi firewalls.

White Paper

Addressing Linux Threats Leveraging Fewer Resources

The increase in Linux popularity has increased the frequency and sophistication of malware attacks. Read this 2 page white paper now to learn how you can protect your Linux environment with real-time protection that is certified by all major Linux vendors.

Download now »
White Paper - The 2009 Handbook of Application Delivery

White Paper

The 2009 Handbook of Application Delivery

Ensuring acceptable application delivery will become even more difficult over the next few years. As a result, IT organizations need to ensure that the approach that they take to resolving the current application delivery challenges can scale to support the emerging challenges. This handbook elaborates on the key tasks associated with planning, optimization, management and control and provides decision criteria to help IT organizations choose appropriate solutions.

Download now »
White Paper - Is Your Backup System Outdated?

White Paper

Mid-range Storage Considerations

A common misconception is that mid-range storage requirements are dramatically different than that of a larger enterprise. Mid-range storage users may require less capacity, but they have similar functionality and management requirements. This ESG paper examines mid-range storage needs and reviews a new solution that adjusts size while retaining value, performance and functionality.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2010 Infoworld, Inc.