Microsoft fixes critical Windows, Word flaws

Patch Jet Database bug pronto, say researchers; exploits in circulation

Microsoft Tuesday patched six vulnerabilities, most marked "critical," in Windows, Word, Publisher and its anti-virus software.

The most important patch to apply, said analysts, is MS08-028, a critical fix that updates the Jet Database Engine in Windows 2000, Windows XP SP2 and Windows Server SP1. "We have to address this first," said Andrew Storms, director of security operations at nCircle. "There are public exploits out for this."

"Jet Database should be done first," agreed Amol Sarwate, the manager of Qualys' vulnerability research lab. "This is a zero-day that Microsoft themselves acknowledged as having seen not only proof-of-concept code, but also public exploits."

Two months ago, Microsoft confirmed critical vulnerabilities in Jet Database Engine, a Windows component that provides data access to applications such as Microsoft Access and Visual Basic, and posted a security advisory that acknowledged "limited, targeted attacks" using Word documents to trigger the Jet Database bug.

Microsoft knew of the Jet Database bugs for more than two years, but had not patched the problems because it thought it had blocked the obvious attack vectors, a manager in the Microsoft Security Response Center (MSRC) said several days later. Mike Reavey, the group's operations manager, said Microsoft might replace the version of Jet in Windows 2000, XP and Server 2003 SP1 to fix the flaws. According to MS08-028, Microsoft is doing just that.

The company also reiterated that attacks have been spotted in the wild exploiting the vulnerability. "Microsoft had received information that this vulnerability was being exploited," the company said in the security bulletin issued Tuesday.

The Jet Database Engine included in Windows Vista, Windows Server 2003 SP2 and the just-released Windows XP SP3 is not vulnerable to the attacks, and doesn't require replacement.

What is less clear, however, is how Microsoft patched Word and Outlook to shut down the attack vectors that the public exploits have used to leverage the Jet Database problem.

Storms wasn't sure exactly what Microsoft fixed in MS08-026, the security bulletin it released Tuesday for Word. "We're all kind of asking 'huh?' about that," Storms said. "My guess is that we're not the only ones asking what's been fixed."

In late March, when Reavey admitted that Microsoft had not conceived of Jet Database exploits that used Word to trick users into opening malformed .mdb files, he also said that the MSRC was considering a patch to "prevent Word documents from loading MDB files without prompting."

Tuesday, it sounded like Microsoft had taken that route. "In addition to the changes that are listed in the 'Vulnerability Details' section of this bulletin, this update includes logic enhancements to security warnings that mitigate Word as an attack vector used to exploit vulnerabilities in Microsoft Jet Database Engine," the MS08-026 bulletin said. "Word was vulnerable to attacks when opening a specially crafted Word document containing a malicious Jet database file. After applying this update, Word will prompt a user for confirmation before running SQL commands or queries when opening Word documents."

However, Microsoft did not spell out the changes to Word in a separate CVE (Common Vulnerabilities and Exposures) listing, as is its usual habit. At times, the company has been criticized for bundling multiple fixes in a single bulletin without detailing each.

Join the PC World newsletter!

Error: Please check your email address.

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Gregg Keizer

Computerworld
Show Comments

Essentials

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Michael Hargreaves

Windows 10 for Business / Dell XPS

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?