Stories
Slash Boxes
Comments

SoylentNews is people

SoylentNews is powered by your submissions, so send in your scoop. Only 12 submissions in the queue.

Submission Preview

Link to Story

Microsoft Closes Word/Wordpad Hole—6 Months after Report

Accepted submission by butthurt at 2017-04-29 06:58:38
Security

It's reported that, as of 11 April, patches are available for a security bug in Microsoft Office and in Wordpad which was disclosed to the company in October. The flaw was widely exploited after McAfee [wikipedia.org] blogged about it. It affects Microsoft Office 2007 SP3 and Windows Vista SP2; the latter was released in May 2009 [engadget.com] and the former in October 2011 [neowin.net].

In related news, The Register [theregister.co.uk] (nonCloud-flare link [webcitation.org]) says that

[...] CVE-2017-0210 [microsoft.com] in Internet Explorer, and CVE-2017-2605 [microsoft.com] in Office – are being actively attacked in the wild by miscreants and the Dridex malware. That latter bug has no patch, by the way: Microsoft just switched off an exploited PostScript filter by default.

further information: CVE-2017-0199 [mitre.org]

coverage:

related story:
After Microsoft Delays Patch Tuesday, Google Discloses Windows Bug [soylentnews.org]


Original Submission