On TV.com: TOP 10 Shows CANCELED Too Soon
BNET Business Network:
BNET
TechRepublic
ZDNet

December 11th, 2006

Is MS Office becoming a zero-day liability all year long?

Posted by George Ou @ 12:36 am

Categories: Desktop, Security, Vista

Tags:

MS Office is nearly continuously vulnerable to zero-day attacks most months out of the year

A really critical vulnerability in Microsoft Word 2000, 2002, 2003, Mac 2004, and Viewer will not make Microsoft's patch Tuesday this week and a newly found critical vulnerability in Windows Media Player playlists will also miss the boat.  The exploit code for both vulnerabilities are out in the wild and there have been attacks on the Word exploit seen in the wild.  Unfortunately we most likely won't see a patch until the January patch Tuesday which is nearly 5 weeks away and Microsoft rarely issues out of cycle patches unless there is an overwhelming amount of negative press such as the WMF issue in early January of this year.

Microsoft gave the typical useless workaround asking people to avoid opening dangerous Word documents from known and unknown sources which doesn't exactly do anyone any good short of them dumping Microsoft Office.  While these sorts of vulnerabilities are not exclusive to Microsoft, Microsoft is the biggest target because of the ubiquitous nature of Microsoft Office and this may eventually threaten Microsoft's reign on office suites if people are concerned with Office security.

We have almost seen an even trickle of zero-day exploits every other month in 2006 for MS office that remain unpatched for 1 month or more.  As soon as one zero-day office flaw gets patched on a Tuesday, a new zero-day Office flaw pops up on Wednesday.  Now the attackers are getting even bolder to release these exploits one or two weeks in advance of patch Tuesday knowing that Microsoft probably won't catch it in their next cycle which causes the vulnerability to go unpatched for 6 weeks.  An attacker might have multiple exploits but they only need one at a time to break in to computer systems.  This means they'll only release one vulnerability at a time and not release the next one until the previous one is patched.  This means MS Office is nearly continuously vulnerable to zero-day attacks most months out of the year.  In fairness, the newly released Microsoft Office 2007 which went through the new SDL (Security Development Lifecycle) was not vulnerable to this latest zero-day exploit.

While Vista may mitigate some of these attacks that try to take over the computer because of UAC, it doesn't protect the user's data from theft, deletion, or ransomware where the user's data gets encrypted for ransom.  I spoke with Microsoft about this and they admitted would be the next phase of the war in a Vista security environment.  I recommended an application protected mode that engages whenever MS Office is opening an unknown Document that has an unfamiliar checksum because it wasn't locally generated or marked as safe.  The same type of protected mode should apply to any application that needs to process externally generated data since no application is perfect.

This application protected mode would give MS Office zero network access and zero file access other than the actual file it's opening.  This way, the only damage that can be done is the infected file itself.  No software application vendor has gotten to this stage yet but that's where they need to go.  With Vista's new security model, user data will be the next battle ground since the system will mostly be off limits.  Malware will most likely not even try to get system access since it risks detection by triggering a UAC privilege escalation prompt.  It will have to go straight for the user data and the most likely attack vector will be ransomware.  With Office attacks on the increase in the last year, Microsoft may be forced to adopt a more aggressive stance on application security or risk their biggest cash cow.

George Ou is Technical Director of ZDNet. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 94 Talkback(s)
sad but true
You're absolutely right, it's a shame people are afraid of alternatives. (Read the rest)
Posted by: sjaaxken Posted on: 12/19/06 You are currently: a Guest | | Terms of Use
Much like Windows, the vulns are forcing MS to write better code for Office  Scrat | 12/11/06
To be fair to Microsoft...  bportlock | 12/11/06
Why be fair?  jasonp@... | 12/11/06
At the same time....  bportlock | 12/11/06
No arguement there...  jasonp@... | 12/12/06
What are the rewards for hacking Office?  Too Old For IT | 12/12/06
Can't argue about the black ops  wolf_z | 12/15/06
Remember, though  Yagotta B. Kidding | 12/11/06
Microsoft Office Loads Fast?  nucrash | 12/11/06
Taking the Metro  Yagotta B. Kidding | 12/13/06
You know better than that  georgeou | 12/11/06
I'm just guessing  zkiwi | 12/11/06
He didn't have a point  georgeou | 12/11/06
I see the miscommunication  nucrash | 12/11/06
Did you even read my post?  nucrash | 12/11/06
I missed it early in the morning  georgeou | 12/11/06
Fast loading  ITGuy04 | 12/11/06
That's a myth  georgeou | 12/11/06
Yes and No  nucrash | 12/11/06
I call BS!  gigabot71 | 12/12/06
You're saying everyone DOES have equal access to APIs?  georgeou | 12/12/06
News to Me  Yagotta B. Kidding | 12/13/06
DLLs are available to everyone  georgeou | 12/14/06
Never mind OO.o  Yagotta B. Kidding | 12/13/06
Seeing Word docs in spam  Chad_z | 12/11/06
Those are probably malicious  georgeou | 12/11/06
Of course the are, you moron!  tobias.carlen@... | 12/13/06
answer = hardware  gdstark13 | 12/11/06
And you're typing on what?  jt@... | 12/11/06
RE; And you're typing on what?  gdstark13 | 12/11/06
ALL MS Software is a HUGE LIABILITY  ITGuy04 | 12/11/06
Ironic but typical of MS  MacCanuck | 12/11/06
Just like the problem apple causes for Windows with Quicktime  georgeou | 12/11/06
You mean tied to suggestions  MacCanuck | 12/12/06
And the option is... ?  jt@... | 12/11/06
PageMaker  perryroyce@... | 12/11/06
Uhm yeah, butl...  jt@... | 12/11/06
Oppsss  perryroyce@... | 12/11/06
Claim your free Word replacement here...  smdunn | 12/11/06
I use Abiword a little bit in Linux.....  mdsmedia | 12/12/06
Could you enlightent us?  Jim Blaine - Bellingham WA. | 12/12/06
I'm not sure I get your point  mdsmedia | 12/12/06
Reactionary; the terrorists win  jt@... | 12/11/06
Get behind another beast...  ImUpAbvIt | 12/11/06
Sandbox  gregzdnet | 12/11/06
Easy to do in XP  NonZealot | 12/11/06
Please  Richard Flude | 12/11/06
Clearly NZ also believes he doesn't have any  hirez | 12/12/06
Ohh for goodness sake!! Someone mentions sandbox...  mdsmedia | 12/12/06
Office warns you before opening documents from email/web  PB_z | 12/11/06
Warnings like that don't help you much  georgeou | 12/11/06
No way to tell legit from illegit  PB_z | 12/11/06
You missed the point of article  georgeou | 12/12/06
Yes it is!!!  gbaker2755 | 12/11/06
Patch Tuesday is a disaster  andy88488 | 12/11/06
It's one of their much touted TCO wins over Linux  Richard Flude | 12/11/06
I can see it  andy88488 | 12/12/06
I have a better idea...  Resuna | 12/11/06
Becoming? No... it has been for a while.  bblackmoor@... | 12/11/06
How is OpenOffice.org more secure  nucrash | 12/11/06
Exposure surface  Yagotta B. Kidding | 12/13/06
The Rain in Spain ...  dshans@... | 12/11/06
In summary  Richard Flude | 12/11/06
Don't put words in my mouth  georgeou | 12/11/06
Fair call  Richard Flude | 12/11/06
Legacies  Yagotta B. Kidding | 12/13/06
NX  Yagotta B. Kidding | 12/13/06
RE: Is MS Office becoming a zero-day liability all year long?  phrodo | 12/11/06
Good Bye XP Hello openSUSE  D. T. Schmitz | 12/11/06
Your enlightened commentary has won me over  ImUpAbvIt | 12/12/06
SLED  D. T. Schmitz | 12/12/06
LOL, he got you happy  georgeou | 12/12/06
I am glad you found that humorous  D. T. Schmitz | 12/12/06
Ubuntu / Firefox and Openoffice  loyaleagle@... | 12/13/06
Wow - I really need no apps  TonyMcS | 12/12/06
Friends Forever  D. T. Schmitz | 12/12/06
You've never run Linux then??  mdsmedia | 12/12/06
Better Still  Ole Man | 12/12/06
Why?  gigabot71 | 12/12/06
Who's trying to convince you of anything  mdsmedia | 12/12/06
Look In Your Mirror  Ole Man | 12/13/06
ummmm....deja vu.....all over again?  mdsmedia | 12/12/06
hehehe  baylors | 12/12/06
Access Access Access  corticus | 12/12/06
virus virus virus  CobraA1 | 12/12/06
How Many?  rickk@... | 12/12/06
And how many of those PCs were administered...  mdsmedia | 12/12/06
Ubuntu / Firefox and Openoffice  loyaleagle@... | 12/13/06
happy  D. T. Schmitz | 12/13/06
Simply Mepis 6.0, Opera and OpenOffice.org  I. Kidya Knott | 12/16/06
0-day  usrhlp | 12/14/06
Just gotta keep smoking that Microsoft Funny Weed...  Boomslang | 12/16/06
Microsoft  KKnutsson | 12/18/06
sad but true  sjaaxken | 12/19/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here

Recent Entries

Top Rated

    Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors

    Archives

    ZDNet Blogs

    White Papers, Webcasts, and Downloads

    • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
    • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
    • Smart People The best and worst moves in the management and strategy trenches. Learn More