Another Microsoft bug revealed on huge patch day

By Jeremy Kirk, IDG News Service |  Windows, Microsoft, vulnerability Add a new comment

 Along with its biggest patch release in five years, Microsoft warned on Tuesday of another potentially dangerous vulnerability in its software.

The problem lies within the WordPad Text Converter for Word 97 files, Microsoft said in an advisory.

The systems affected include Windows 2000 Service Pack 4, Windows XP Service Pack 2, Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2, Microsoft said. XP Service Pack 3 and the Vista operating systems are not affected.

The company said it has seen limited, targeted attacks. If exploited, a hacker could gain the same rights on a PC as a local user and could remotely execute code.

Microsoft is investigating the problem. Microsoft typically releases patches on the second Tuesday of the month. If Microsoft sticks to its schedule, the earliest a patch could be released would be Jan. 13. However, Microsoft has deviated from its patching cycle when a vulnerability is considered particularly dangerous.

The vulnerability can't be exploited by simply opening an e-mail, Microsoft said. The victim would have to open an attachment containing a malicious file designed to exploit the problem.

Microsoft said Word 97 documents are opened by default with Office Word if a user has that application installed. Word is not affected by the problem, but attackers could try to rename the malicious file with a Windows Write (.wri) extension, which would be cause WordPad to try to open it. The company advised that ".wri" attachments could be blocked at the network gateway, reducing the risk a user would open a harmful file.

Microsoft released on Tuesday eight patches covering 28 vulnerabilities within applications including Internet Explorer, Sharepoint, Office, Windows Media Player and its Vista OS. Six of those patches were classified as "critical."

    Add a comment

    Post a comment using one of these accounts
    Or join now
    At least 6 characters

    Note: Comment will appear soon after you have activated your account.
    Obscene/spam comments will be removed and accounts suspended.
    The information you submit is subject to our Privacy Policy and Terms of Service.

    ITworld LIVE

    WindowsWhite Papers & Webcasts

    White Paper

    Microsoft Volume Licensing Reference Guide

    This guide provides an overview of the key features of Microsoft Volume Licensing programs. The information is presented by organizational type and size-two of the most important keys to determining your best Volume Licensing option.

    White Paper

    HP Software Licensing & Management Solutions for Microsoft

    See how HP Software Licensing & Management Solutions (SLMS) can help you identify the best Microsoft licensing program for your needs, get the most from your licensing agreement, and maximize your Microsoft software investment.

    White Paper

    Microsoft Open Value Program Guide

    In this overview, see how Microsoft Open Value provides a flexible, affordable way for small to midsize organizations (i.e. those with five or more desktop PCs) to use and manage all their Microsoft licensed products under a single agreement.

    White Paper

    Microsoft Volume Licensing Comparison - Enterprise

    With this quick-reference document, you can easily compare the available Microsoft Volume Licensing programs for enterprise organizations with 250+ devices, and tailor a program to help save costs, manage multiple licenses, and keep software up-to-date.

    White Paper

    Microsoft Enterprise Agreement Program Brief

    This white paper provides an in-depth look into how the Microsoft Enterprise Agreement Program provides with flexibility to choose among on-premises software and cloud services to best suit your user needs, and helps you optimize your technology spend as business priorities change.

    See more White Papers | Webcasts

    Ask a question

    Ask a Question