Antipiracy tool leads to DoS in Office for Mac

A security vulnerability in an antipiracy tool included in Microsoft Corp.'s Office v. X for the Macintosh can allow an attacker to crash applications in Office, Microsoft said in a bug alert Thursday. The company has released a patch to fix the problem.

The vulnerability is in the Network Product Identification Checker component of Office v. X, a tool which checks the local network that the copy of Office is running on for other copies using the same Product Identifier (PID), a number similar to a serial number, Microsoft said. Each copy of Office v. X periodically "announces" its PID to the network and if two copies of Office v. X on a single network share the same PID, the application shuts down.

When a specially formulated announcement is sent to a machine or over the network, the Network PID Check component incorrectly handles it and can cause Office v. X to crash, the company said. When such a specially formulated packet is sent, only the first application opened after Office is launched will crash, though unsaved data could be lost, Microsoft said. The attack could be directed against a single machine, using its IP (Internet Protocol) address, or against an entire local network, the company added.

The attack can be blocked, Microsoft said, by stopping certain kinds of traffic at the firewall and applying the patch. The attack has no further impact beyond crashing Office, Microsoft said.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Sam Costello

PC World
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?