Patch Tuesday released two important patches this month. Plugging a total of eight voles in windows and office. Microsoft also warns of another zero-day attack in Internet Explorer.
One vulnerability in Movie maker affects Movie Maker in Vista and XP. A hacker could send a dirty movie maker or producer file to a victim via e-mail. If the file is open by the recipient, malicious code is then released onto the machine. Producer 2003 is also affected, but has not been updated as it is a free download. Microsoft say that Producer 2003 “does not offer a means for automatic update”.
The answer according to Microsft, is to uninstall Producer 2003 or disassociate the project file type from the application using a Microsoft Fix It.
Another patch fixes 7 flaws present in all versions of Excel (including Mac), supported versions of Excel viewer and Sharepoint 2007.?Same principle applies again, the attack can only be launched once an infected Excel file is opened. Microsoft has recomended these patches be applied staright away. Even though they have only been ranked as “important”.
The warning of the zero-day vulnerability affecting IE6 and IE7 is already being exploited. Versions that are vulnerable are Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4, and Internet Explorer 6 and Internet Explorer 7. Microsoft has said that IE 8 is safe, also IE 5.01 SP4 on Windows 2000 SP4. Good to know.
How it works is due to an invalid pointer reference. Hackers are able to launch malware when the pointer reference is accessed after an object has been deleted.
Microsoft believes the attacks that have occured so far to be targeted. A patch will be released for the next patch Tuesday or as a one off ?before then.



