Quantcast
Bugs and Fixes
Bugs and Fixes
Contributing Editor Stuart J. Johnston advises you on how to fix the latest problems affecting your operating system, your browser, your other software, and your hardware.
Show article:

Microsoft Security Programs Create Risk

Plus: Fixes for Internet Explorer and Office, and changes to Windows support.

Stuart J. Johnston, PC World

  • 0 Yes
  • 0 No

Illustration: Headcase Design
A new flaw in Microsoft security software turns the software that's supposed to be protecting you into a threat.

This critical hole appears in Microsoft's Malware Protection Engine, a part of Windows Defender and Windows Live OneCare, as well as of the Microsoft Antigen and Microsoft Forefront Security business programs. Through it, attackers could take over a vulnerable PC running the security software on any supported version of Windows, including Vista, if one of the affected programs scans a doctored PDF file sent as an e-mail attachment or downloaded from the Web.

No active attacks against this hole are known to exist, but if you haven't already received the fix through Automatic Updates, get it now.

Microsoft also patched a fistful of critical holes affecting Internet Explorer 6. Some of the flaws actually reside in Windows, but all create the risk of drive-by downloads if you browse a poisoned site with IE 6 on Windows 2000 SP4 through XP SP2. Vista is not affected, and IE 7 offers additional protection by requiring multiple confirmations to run ActiveX. All the patches have been distributed via Automatic Updates; the fixes appear to have come out before any known attacks.

The first two fixes close holes in two different ActiveX controls used by Windows (and loadable by IE) for HTML Help and Microsoft Data Access Components. The second two repair flaws involving IE's handling of COM objects.

At Microsoft's site you can get details on the COM flaws, along with info on the final hole, which can be targeted if you click a poisoned FTP (file transfer protocol) link in an e-mail or on a hacked site.

Office Attacks

Just as Microsoft thought it had fixed the last of a string of exploited holes in its Office applications, another one popped up. The fixed portions (distributed via Automatic Updates) close vulnerabilities considered critical in Word 2000 and rated important in Works and in other Word versions. The new, as-yet-unpatched bug is rated the same, and involves the usual tainted e-mail attachments or downloaded file.

  • Recommend this story?
  • 0 Yes
    0 No

"Microsoft Security Programs Create Risk" Comments

With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.

Related Security Articles

  • Mac Security Focus: Antivirus Although Apple computers are not somehow magically immune to viruses and other malware, they've been remarkably free of such...
  • Unscramble This Encrypting data can save you lots of heartache. How should you do it?
  • 5 Ways to Foil Hackers Are you the only you out there? When it comes to protecting your identity, a bit of prevention is worth a megabyte of cure.
  • On The Defensive Lock up employee data, or face the consequences.
  • Mac Security Focus: Firewalls Firewalls monitor and regulate the data moving on and off your computer or network. They can keep criminals out while allowing...
  • CDW Security Center Is your data protected? Visit the CDW Security Center Learn where you may be vulnerable and how to address those risks.
  • Asus Laptop Showcase Ultra-fashionable thin and light notebooks with SmartLogon Face Recognition. Find out more...
  • HP Ink Center Bring improved color and brilliance to your printed material. Visit the Resource Center for more info...

PC World's Marketplace

PC World's Free Whitepapers

Name City
Address 1 State Zip
Address 2 E-mail (optional)