Microsoft has shipped a patch for to fix several critical security holes affecting its Office productivity suite and warned that hackers can use RTF (Rich Text Format) e-mails to launch code execution attacks.
The MS10-087 bulletin, which is considered a high-priority update, patches a total of 5 documented vulnerabilities affecting all currently supported Microsoft Office products.
It is rated critical for Office 2007 and Office 2010 because of a preview pane vector in Microsoft Outlook that could trigger the vulnerability when a customer views a specially crafted malicious RTF file, the company explained.
The update also patches the DLL load hijacking attack vector that haunted multiple Windows applications, including Microsoft' own Office software.
Microsoft urges Office users to consider this a "top priority bulletin" and warned that reliable exploit code is likely within the next 30 days.
As part of the November Patch Tuesday release, the company also patched a pair of security flaws in Microsoft PowerPoint and four documented flaws in Unified Access Gateway (UAG), which is a component of Microsoft Forefront.
- MS10-088 This bulletin resolves two cooperatively disclosed vulnerabilities in Microsoft PowerPoint that could allow remote code execution if a user opens a specially crafted PowerPoint file. The overall severity rating is Important due to the user interaction required to open the malicious file and we give the bulletin a rating of 2 in our deployment priority assessment.
- MS10-089 This bulletin resolves four cooperatively disclosed vulnerabilities in Unified Access Gateway (UAG), which is a component of Microsoft Forefront. The most significant of these could allow elevation of privilege if a user clicks on a malicious link on a website. This update is offered through the Microsoft Download Center and is not available through Microsoft Update at this time. With an overall severity rating of Important and user interaction required to exploit, we also give this a deployment priority of 2.
- MS Word exploit generator circulating?
- Microsoft slaps bandaid on IE, MS Word
- MS Word zero-day attack video
- A fifth MS Word zero-day?