Security risk management vs. software development 12 Feb 2008 12:10 GMTGeorge Ou highlights problems with Vista's speech recognition software and wonders why the issue hasn't been fixed for more than a year. The reason: Risk management. Here's George's description of what he calls a flaw in Vista's speech recognition--some folks debate whether it's a flaw or not....
Source: ZDNet Note to readers: Security content moved to Zero Day blog 12 Feb 2008 09:43 GMTThis is a note to all my readers. All of my future security-related content will be appearing on the ZDNet Zero Day blog instead of here in "Real World IT". Some of you may have wondered why I haven't posted any security-related content in a while because I've been posting on Zero Day for quite...
Source: ZDNet MS08-013 – Critical: Vulnerability in Microsoft Office Could Allow Remote Code Execution (947108) 12 Feb 2008 08:00 GMTBulletin Severity Rating:Critical - This critical security update resolves a privately reported vulnerability in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Office file with a malformed object inserted into the document. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Source: TechNet MS08-012 - Critical: Vulnerabilities in Microsoft Office Publisher Could Allow Remote Code Execution (947085) 12 Feb 2008 08:00 GMTBulletin Severity Rating:Critical - This critical security update resolves two privately reported vulnerabilities in Microsoft Office Publisher that could allow remote code execution if a user opens a specially crafted Publisher file. An attacker who successfully exploited these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Source: TechNet MS08-011 – Important: Vulnerabilities in Microsoft Works File Converter Could Allow Remote Code Execution (947081) 12 Feb 2008 08:00 GMTBulletin Severity Rating:Important - This important security update resolves three privately reported vulnerabilities in the Microsoft Works File Converter. These vulnerabilities could allow remote code execution if a user opens a specially crafted Works (.wps) file with an affected version of Microsoft Office, Microsoft Works, or Microsoft Works Suite. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
Source: TechNet MS08-010 - Critical: Cumulative Security Update for Internet Explorer (944533) 12 Feb 2008 08:00 GMTBulletin Severity Rating:Critical - This critical security update resolves three privately reported and one publicly reported vulnerabilities. The most serious of the vulnerabilities could allow remote code execution if a user viewed a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights
Source: TechNet MS08-009 - Critical: Vulnerability in Microsoft Word Could Allow Remote Code Execution (947077) 12 Feb 2008 08:00 GMTBulletin Severity Rating:Critical - This critical security update resolves one privately reported vulnerability in Microsoft Word that could allow remote code execution if a user opens a specially crafted Word file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Source: TechNet MS08-008 – Critical: Vulnerability in OLE Automation Could Allow Remote Code Execution (947890) 12 Feb 2008 08:00 GMTBulletin Severity Rating:Critical - This critical security update resolves a privately reported vulnerability. This vulnerability could allow remote code execution if a user viewed a specially crafted Web page. The vulnerability could be exploited through attacks on Object Linking and Embedding (OLE) Automation. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Source: TechNet