Patch Office X for Network Vulnerability — Microsoft has released a Network Security Updater for Microsoft Office X that eliminates a network vulnerability made possible by a flaw in the application suite’s network-aware anti-piracy mechanism. Office X checks to make sure that every copy running on the network is using a unique product identifier (PID); if an Office application detects a duplicate, it shuts down. As discovered by Marty Schoch, the problem is that the checking code doesn’t correctly handle a malformed PID announcement, causing the first Office application launched to crash, with the possible loss of data. So although someone could cause Office applications to crash by sending malformed PID announcements, there is no possibility that data could be created, deleted, or modified. For full details, see Microsoft Security Bulletin MS01-002. [ACE]
Subscribe today so you don’t miss any TidBITS articles!
Every week you’ll get tech tips, in-depth reviews, and insightful news analysis for discerning Apple users. For 28 years, we’ve published professional, member-supported tech journalism that makes you smarter.
Registration confirmation will be emailed to you.