Update: Microsoft admits it knew about, didn't patch, bugs
It thought users were safe, but is now scrambling for a solution
Active Comments
The Security Zone
With the mobility of employees and the ease with which external devices can be brought in and out of a network, continuing to build your security plan for network servers and clients is a must. Fortunately, there is much that organizations can do to protect themselves from attacks - internal and external. Having the right policies, procedures and server configurations is critical... Learn more in The Security Zone See All Zones
|
March 25, 2008 (Computerworld) Microsoft Corp.'s security team today acknowledged that it knew of bugs in its Jet Database Engine as far back as 2005 but did not patch the problems because it thought it had blocked the obvious attack vectors.
A researcher at Symantec Corp. said Microsoft should have fixed the flaws years ago.
In a post to the Microsoft Security Research Center (MSRC) blog late Monday afternoon, Mike Reavey, the MSRC's operations manager, admitted that outside researchers had notified Microsoft in 2005 and 2007 of separate bugs in Jet, a Windows component that provides data access to applications such as Microsoft Access and Visual Basic.
In both cases, Microsoft told the researchers that it would not fix the flaw because it considered users safe. Outlook blocked the .mdb file format from being opened, Exchange servers stripped them from incoming messages and Internet Explorer issued warnings when users clicked on such files, said Reavey as he explained Microsoft's decision.
But the company hadn't thought of the attack strategy now being used by hackers. "Everything changed with the discovery of this new attack vector that allowed an attacker to load an .mdb file via opening a Microsoft Word document," he said. "The previous guidance does not work against this new attack. So that's why we alerted customers to these attacks and are re-investigating Jet parsing flaws -- this is a new attack vector discovered that we didn't know about."
Attackers are, in fact, doing an end run around Outlook, researchers at Symantec said last week. That finding prompted Microsoft to issue a security advisory warning users running Word on Windows 2000, XP and Server 2003 SP1 to take defensive steps.
One researcher said today that Microsoft could have done more -- and done something earlier -- to prevent the sudden scramble for a fix.
"I can't count the number of times we've seen this in the past with a Microsoft product," said Oliver Friedrichs, a director with Symantec's security response team. "Clearly, there should have been more concern from Microsoft in the first place. There have been two vulnerabilities, one in 2005 and another in 2007, and both were left unpatched.
"It does draw some concern," Friedrichs said.
The MSRC is still working out how it wants to patch the vulnerability or whether it can put up more barriers to the now-known Word attack. It may block Word documents from automatically loading .mdb files, Reavey said, or it may replace the version of Jet in Windows 2000, XP and Server 2003 SP1 with a newer edition that doesn't contain the bug. The new Jet Database Engine is part of Windows Vista and Windows Server 2003 SP2, and it is slated for inclusion in Windows XP SP3, making those operating systems immune to attacks.
Today's Top Stories
Resource Alerts
Webcasts
Web Threats Don't Discriminate
The Secure Web Gateway. Mission Critical For Business
Dynamic Data Center and Virtualization Drives Operational Excellence at Emory Healthcare
Editor's Picks
Virtually every Windows PC at risk, says Secunia
Moving to a start-up? Fasten your seatbelt
License server glitch exposes SonicWall users to e-mail security threats
In high-tech schools of the future, Facebook in class is boosted -- not banned
Fired up about IT? Join Sharkbait and share your true tales of IT. SharkBait is the place for you to sound off about everything IT the good, the bad, and the rest of the weird stuff you deal with every day.New baits |
|
![]() |
|
Today's Internet has been brought to you by porn YouTube and Ning are trying to shed adult-oriented content to appeal to mainstream advertisers. Will it work? ... [more] |
|
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
|
||||||
|




Subscribe to
Computerworld 







Read up on the latest ideas and technologies from companies that sell hardware, software and services.


