Microsoft Security Programs Create Risk
Plus: Fixes for Internet Explorer and Office, and changes to Windows support.
Stuart J. Johnston, PC World

This critical hole appears in Microsoft's Malware Protection Engine, a part of Windows Defender and Windows Live OneCare, as well as of the Microsoft Antigen and Microsoft Forefront Security business programs. Through it, attackers could take over a vulnerable PC running the security software on any supported version of Windows, including Vista, if one of the affected programs scans a doctored PDF file sent as an e-mail attachment or downloaded from the Web.
No active attacks against this hole are known to exist, but if you haven't already received the fix through Automatic Updates, get it now.
Microsoft also patched a fistful of critical holes affecting Internet Explorer 6. Some of the flaws actually reside in Windows, but all create the risk of drive-by downloads if you browse a poisoned site with IE 6 on Windows 2000 SP4 through XP SP2. Vista is not affected, and IE 7 offers additional protection by requiring multiple confirmations to run ActiveX. All the patches have been distributed via Automatic Updates; the fixes appear to have come out before any known attacks.
The first two fixes close holes in two different ActiveX controls used by Windows (and loadable by IE) for HTML Help and Microsoft Data Access Components. The second two repair flaws involving IE's handling of COM objects.
At Microsoft's site you can get details on the COM flaws, along with info on the final hole, which can be targeted if you click a poisoned FTP (file transfer protocol) link in an e-mail or on a hacked site.
Office Attacks
Just as Microsoft thought it had fixed the last of a string of exploited holes in its Office applications, another one popped up. The fixed portions (distributed via Automatic Updates) close vulnerabilities considered critical in Word 2000 and rated important in Works and in other Word versions. The new, as-yet-unpatched bug is rated the same, and involves the usual tainted e-mail attachments or downloaded file.
- Page 1 of 2
- Next ยป
With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.
Laptop Showcase
Windows Vista FAQ
Related Security Articles
- Mac Security Focus: Antivirus Although Apple computers are not somehow magically immune to viruses and other malware, they've been remarkably free of such...
- Unscramble This Encrypting data can save you lots of heartache. How should you do it?
- 5 Ways to Foil Hackers Are you the only you out there? When it comes to protecting your identity, a bit of prevention is worth a megabyte of cure.
- On The Defensive Lock up employee data, or face the consequences.
- Mac Security Focus: Firewalls Firewalls monitor and regulate the data moving on and off your computer or network. They can keep criminals out while allowing...
Best Prices on Security Software
Norton Internet Security 2008Price: $13.98
Internet Security 2008 - 3-User (Full Product, PC)Price: $11.49
Norton 360 2.0 ( PC)Price: $45.77
Kaspersky Internet Security 2009Price: $25.95
Norton Internet Security 2009Price: $59.00
Internet Security Suite 2008 - 3-UserPrice: $14.95
- CDW Security Center Is your data protected? Visit the CDW Security Center Learn where you may be vulnerable and how to address those risks.
- Asus Laptop Showcase Ultra-fashionable thin and light notebooks with SmartLogon Face Recognition. Find out more...
- HP Ink Center Bring improved color and brilliance to your printed material. Visit the Resource Center for more info...








"Microsoft Security Programs Create Risk" Comments