Advertisement
Promo

Security threats Toolkit

Story: Microsoft to issue patch for critical PowerPoint hole

  • Previous comment

Posted by: lumension (Friday 8 May 2009, 11:22 AM)

  • Reply

Other enterprise software patches expected for next week.....

Other than the Microsoft PowerPoint patch we were waiting for, Adobe is releasing additional patches to address the current Adobe Reader issues across multiple versions next week which will also have an impact on IT.

Since the beginning of the year, we’ve been worrying about Adobe vulnerabilities (see recent blog post). It’s important to remember that historically, files like Adobe PDF files, Word, Excel or PowerPoint files have been ideal vehicles for targeted attacks because these attachments are socially acceptable and expected attachments within corporate email. The use of a file like a PDF as a vehicle for the delivery of malware gives the hacker an added advantage. It’s anticipated that AV vendors will create better signatures from the information contained within the patch to identify infected files. However, the bad guys will simply start obfuscating the current exploit to try to capture more unpatched users once the patch goes out on Tuesday. Earlier this month, we found at least half a dozen Chinese web sites that were hosting malicious PDF files using the most current vulnerability. After Tuesday, they’ll simply do a better job of hiding their malware.

We now live in an environment where compromised applications have now become a delivery mechanism for additional downloaded and executed malware such as key-loggers and rootkits. The most effective risk mitigation therefore, continues to be lumension application control to prevent a compromised application from downloading and running any unauthorised software (including malware) on a user’s PC.

While there is a relatively small number of patches from Microsoft this month, IT departments will clearly have plenty to keep them busy as other popular enterprise software, besides Microsoft, will also require installation.

Private message disabled

lumension

lumension
LONDON, UK
Member since: October 2008

Site Activity Rating:

3

This member is ranked #84 in our top 100


  • Previous comment

  • Reply to this comment
  • Return to story
  • Report this as offensive


Full Talkback thread

Sentry Posts Blog

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters