Microsoft fixes DNS flaw but warns of Word attacks

Microsoft is warning that a Word flaw is being used for targeted attacks, and has also issued four 'important' patches, including one for a potentially serious DNS flaw in the latest Patch Tuesday bulletin.

Users of an older version of Microsoft Word could have their computers compromised after downloading and opening a specially crafted .doc file, according to an advisory issued late Tuesday.

"Microsoft is investigating the public reports and customer impact," Microsoft said in its Security Advisory 953635.

Microsoft claims only targeted attacks have so far attempted to use this vulnerability against systems running Microsoft Word 2002 SP3. Only users of Microsoft Office Word 2002 SP3 are affected.

To become infected, a vulnerable user would have to open a specially crafted .doc document. An attacker using this vulnerability would then have the same user rights as the victim. If a victim were running as administrator, the attacker would gain full access to the compromised PC.

Microsoft's security response communications manager Bill Sisk said Microsoft could issue an update as part of its monthly Patch Tuesday program or it could issue an out-of-cycle update if required. Microsoft is still investigating the matter.

Workarounds Microsoft recommends include using Office Word 2003 Viewer or Office Word 2003 Viewer Service Pack 3 to open and view Microsoft Word files.

Microsoft encouraged customers who believe they may have been attacked to contact the "national law-enforcement agency in their country".

Patch Tuesday

The updates linked to in Tuesday's bulletins include a patch for a potentially serious underlying DNS flaw.

The flaw, which was discovered by security researcher Dan Kaminsky, affects multiple vendors, including Cisco. The Microsoft products affected by the flaw are detailed in Microsoft Security Bulletin MS08-037. DNS spoofing involves making a DNS entry point to a different IP address.

The spoofing vulnerability exists in Windows DNS clients and Windows DNS servers, and could allow an attacker to "quickly and reliably spoof responses and insert records into the DNS server or client cache, thereby redirecting internet traffic", Microsoft warned.

All supported versions of Microsoft Windows 2000, Windows XP, Windows Server 2003 and Windows Server 2008 are affected by the flaw. Microsoft claims its security update addresses the vulnerabilities by using "strongly random" DNS transaction IDs, using random sockets for UDP queries, and updating the logic used to manage the DNS cache.

However, this flaw affects many more vendors. According to US-CERT vulnerability note 800113, vendors known to be vulnerable to this flaw include Cisco, the Internet Software Consortium, Juniper Networks, Microsoft, Nominum, Red Hat and Sun. Other potentially affected vendors include Akamai, Apple, Debian/GNU Linux, Fedora, FreeBSD, Gentoo, HP, IBM, Motorola, Nokia and Ubuntu.

Microsoft's July Patch Tuesday also included bulletin MS08-040, which addresses vulnerabilities in Microsoft SQL server. The flaws are page reuse, buffer overflow and memory corruption vulnerabilities, and affect SQL Server 7.0, SQL Server 2000, SQL Server 2005, Microsoft Data Engine (MSDE) 1.0, Microsoft SQL Server 2000 Desktop Engine (MSDE 2000), Microsoft SQL Server 2005 Express Edition, Microsoft SQL Server 2000 Desktop Engine (WMSDE) and Windows Internal Database (WYukon).

Patch Tuesday also saw the release of bulletin MS08-038, which gave details of a saved-search vulnerability in Windows Explorer that affects multiple operating systems including Vista. Bulletin MS08-039 also gave details of cross-site scripting vulnerabilities in Outlook Web Access.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

JobWatch: where the ICT jobs are http://t.co/e6gQvhxz via @zdnetaustralia #ICT #recruitment

The rural Silicon Valley: What happened in Senate Estimates this week? What's the issue with tech company taxes?... http://t.co/Umoa7CHX

Sweet: "Customers are picking the top fibre plan that is available on the #NBN more than any other plan" http://t.co/yUFHdYFc

RT @CorrieB: An iPad for every child: Inevitable or impossible? http://t.co/I7uS8l9s Thx to @timbuckteeth for this; http://t.co/jxkqIRIp

Interesting tech analysis podcast re: phone cloning and Craig Thomson from zdnet http://t.co/p8jlCvvG

@zdnetaustralia Thoughtful piece to end the week on. Thanks @joshgnosis

Triple J's Spotify conundrum http://t.co/iy1e2DRp via @zdnetaustralia

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

BYOD for iOS devices is not a big deal, provided a passcode is enforced and jailbroken devices are excluded. But if Google can sort out ...

34 minutes ago by umbria on BYOD too immature for us: Human Services

Triple J not bound to advertising rules like its broadcast. No diff to ABC online or magazines though... http://t.co/JPUr7Fv4

Triple J's Spotify conundrum: Has Triple J managed to find the balance between meeting editorial policy and keep... http://t.co/8UYsHZ6D

Thank you, Tasmania, for helping NBNCo get the design optimised. Heard a great anecdote this week. Four kids at a little school in one of...

40 minutes ago by umbria on NBN's Tassie upgrade to cost $1.3 million

RT @joshgnosis: Listening to Triple J on Spotify has ads for Commonwealth Bank. But that's okay apparently. http://t.co/O7zmcpvT

Listening to Triple J on Spotify has ads for Commonwealth Bank. But that's okay apparently. http://t.co/O7zmcpvT

How does Triple J find the balance with meeting editorial policy and keeping up with the latest technology? http://t.co/qdWgybfm ^jt

Agree AWY

Early days but the take-up rate for the fastest speed tier needs to accelerate to justify the huge Cap-ex.

49 minutes ago by Vasso Massonic on NBN users opt for 100Mbps

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

NBN users opt for 100Mbps http://t.co/ftKGRzye

#IT Priorities: #servers and #storage: webinar sponsored by @IBM http://t.co/BGq8LYd5 via @zdnetaustralia

Post 'social' improved speed to information and context: By Oliver Marks | May 24, 2012, 9:47pm PDT... http://t.co/VGN2hxtp #socialmedia

RT @zdnetaustralia: Should bug hunting for biometric systems be restricted to govt and industry? http://t.co/oj0oOkv7 ^ML

Exploring: http://t.co/WzikDISk

There's trouble with three major Linux desktop application developers. #Linux http://t.co/uR07K9W6

IT Priorities: servers and storage http://t.co/BGq8LYd5 via @zdnetaustralia

Couple of things: Firstly the most important one: "We expect to see that ratio shifting around a bit,"- well says it all almost. Basica...

1 hour ago by AWY on NBN users opt for 100Mbps

Exploring: NBN users opt for 100Mbps: Customers are picking the top fibre plan that is available o... http://t.co/9PwLO0NU #ICTChallenge

Exploring: NBN users opt for 100Mbps: Customers are picking the top fibre plan that is available o... http://t.co/JWTrVow1 #ICTChallenge

Exploring: http://t.co/8iFmRUbZ

NBN users opt for 100Mbps http://t.co/atP8fi1L

Can #Windows Phone bring a new challenge? http://t.co/CpTjZ2lk via @zdnetaustralia

NBN users opt for 100Mbps - ZDNet Australia http://t.co/eVVB5xyS

NBN users opt for 100Mbps - ZDNet Australia http://t.co/4oaTruaN

Where's Mathew whats-his-face complaining about how the secret nasty NBNCo plan is all about "forcing" people onto higher ARPU? Sounds l...

1 hour ago by Gwyntaglaw on NBN users opt for 100Mbps

Story filed for @zdnetaustralia. Please don't tell @engochick that I've waffled on for 1200 words. I'm exhausted now.

RT @markjohnston_au: Australian Privacy Laws catching up with the world http://t.co/OCU7uwqe but will this help change tickbox security to real protection?

Given the early priority given to Tasmania, it is around 90% likely that the entire state will receive the full NBN rollout as originally...

1 hour ago by Gwyntaglaw on NBN's Tassie upgrade to cost $1.3 million

NSW outlines datacentre migration plans - ZDNet Australia: NSW outlines datacentre migration plansZDNet Australi... http://t.co/MosIfczQ

NBN users opt for 100Mbps - ZDNet Australia: Brisbane TimesNBN users opt for 100MbpsZDNet AustraliaCustomers are... http://t.co/T5oBSVZQ

A relevant lesson for NZ - NBN users opt for 100Mbps http://t.co/KScaSdRI via @zdnetaustralia

RT @zdnetaustralia: #NBN users are opting for 100Mbps plans on fibre more than any other, according to NBN Co http://t.co/oTl5R1UY ^jt

RT @ninefold: Interesting Q&A on #cloud security, debating Patriot Act & more: ZDNet Australia http://t.co/qc933yKJ

If you’re running 1:1 then whoever it was that did the original design did not future proof. You should aim to 10:1 for small use stati...

1 hour ago by amckern on 30 servers to 7: BUPA redoes virtualisation

Yes, after all when you do your personal tax return, you don't say to your accountant: "oh, give the government a couple of thousand out...

1 hour ago by meski on Much ado about Google's tax

That would be Ayn, not Ann. And if you read Atlas Shrugged and came away with the impression of selfish, there's not much I can say to c...

2 hours ago by meski on Much ado about Google's tax

Download Angry Birds Space free

2 hours ago by EminnyAssence on iiNet undercuts Internode with NBN pricing

I think the CBA point here is fairly much moot now. There was some, limited, argument for it before the NBN began, but as many people hav...

3 hours ago by seven_tech on NBN cost-benefit analyses are so 2011

Reading this article is like stepping back in time. If I was Paul Berryman I would hang my head in shame. How embarrassing!!! I can’t b...

6 hours ago by MikeSkoey on 30 servers to 7: BUPA redoes virtualisation

The registration sticker provided a visual reminder to the driver to renew regardless of what happened to the renewal letter. The experie...

6 hours ago by dccharron on NSW ditches rego stickers for tech

"xfire: Why is telecommunications being treated different to roads, water and electricity?" Good question, my guess is AUS is far behind...

6 hours ago by ngoctranminh on Five pros and cons of the NBN

Thanks for the response Luke, Given that the quotes are accurate, then the person in charge of the Vic Health App needs to find another j...

6 hours ago by butterflyeffecs on Android fragmentation steers Vic Health

Nice analogy. Another factor is whether you can find 50 people with powerful enough weapons. Minassian's argument is essentially that the...

6 hours ago by Mukimu on National Botnet Network coming: Earthwave

It's nice to see Tas finally get some decent internet connectivity, for too long Tas has been stooged on decent internet connectivity but...

7 hours ago by Jingles on NBN's Tassie upgrade to cost $1.3 million

Who is Luke Hartsuyker? He must be the Apprentice FUDster. As PaulPC has already said regional consumers want, deserve and are entitled...

7 hours ago by dickster on Regional review highlights NBN, mobile

Its good to see the NBN keeping up with the latest equipement & letting the people benefit from it. After all thats why it was a trial, ...

7 hours ago by fibretech on NBN's Tassie upgrade to cost $1.3 million

Shadow Minister for Regional Communications Luke Hartsuyker has got it wrong. Regional consumers want improved mobile services AND the NB...

8 hours ago by PaulPC on Regional review highlights NBN, mobile

This story has been voted 12000 times in the last 24 hours!

1 day ago, Is Bill Gates a great leader?

This story has been voted 10 times in the last 24 hours!

2 days ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

2 days ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar