Corporate E-mail Services
NEW! Digital Subscriber Line(DSL)
Web Design and Hosting Services
Pricing | Signup
Signup For EasysoftWEB Services
Contact Easysoftweb.com
Member Services (Password Required)

EasysoftWEB Home

Today's Date
  <%Response.Write Date()%>
Islip, New York Forecast


Corporate E-mail Services

Web Design and Hosting Services
Pricing | Signup
Signup For EasysoftWEB Services
Contact Easysoftweb.com
Member Services (Password Required)
Downloads
Software Updates

 

mcsp.gif (2733 bytes)

Sign up for VeriSign Secure Services with EasysoftWEB

 


 


Microsoft Releases Two Security Patches

January 21, 1999

 

REDMOND, Wash., Jan. 21  -- Microsoft Corp. has provided patches for recently discovered security vulnerabilities in Microsoft(R) Word 97 and the Microsoft Forms version 2.0 ActiveX(R) Control, and has broadly communicated the availability of these fixes to third-party vendors and more than 1 million customers. These vulnerabilities could be misused by hackers to run malicious code on a user's machine without warning. Although there have not been any reports of customers being adversely affected by hackers through these mechanisms, Microsoft recognizes customers' concerns and has moved quickly to broadly inform them of these issues and help protect them with fixes. Information on these issues as well as the patches can be downloaded from
http://officeupdate.microsoft.com/downloaddetails/wd97sp.htm or http://officeupdate.microsoft.com/downloaddetails/fm2paste.htm.

Word 97 Template Security Patch
Word 97 will warn users when opening a document that contains macros. However, if that document does not contain macros but is linked to a template which does, no warning is issued. A hacker could exploit this vulnerability by causing malicious code to be run without warning when a user opens a Word document attached to an e-mail or on a Web site. This code could be used to damage or retrieve data on a user's system.

The Word 97 Template security patch prevents a hacker from exploiting this vulnerability. After installing the patch, users will be warned before they launch a template that contains a macro. Installing the patch will not disable use of templates or macros on templates. Microsoft recommends that all users download the patch.

Microsoft Forms 2.0 Control Security Patch
The Microsoft Forms 2.0 Control is an ActiveX Control that developers use to create custom dialog boxes. This control is a part of Visual Basic(R) for Applications (VBA) and is installed with Office 97, the Outlook(R) 98 messaging and collaboration client, Microsoft Project 98, certain optional installations of the Visual Basic development system version 5.0, and in third-party applications that license VBA. A hacker could use the Forms 2.0 Control to read or export text on a user's Clipboard when that user visits a Web site set up by the hacker or opens an HTML-based e-mail created by the hacker.

The Forms 2.0 Control security patch addresses the vulnerability that occurs when the Forms 2.0 Control is available on a user's system. The patch prevents a hacker from exploiting the identified vulnerability. Customers who install the patch will not lose functionality of the Forms 2.0 Control, and developers will continue to be able to rely on using it for legitimate functionality. If customers are unsure if this control is present on their system, they should follow the steps indicated at http://officeupdate.microsoft.com/downloaddetails/fm2paste.htm

Notifications about these issues were posted to the Microsoft Security Advisor Web site at http://www.microsoft.com/security/ and have also been sent to the Microsoft Security Notification listserve, to which anyone can subscribe (more information is available at http://www.microsoft.com/security/) as well as to the Computer Emergency Response Team (CERT), an industry security organization based at Carnegie Mellon University, which coordinates and distributes security information to corporate, academic and government users. In addition, Microsoft is informing all third-party vendors licensing VBA and more than 1 million customers who subscribe to the Office News Service.

As with all security issues, Microsoft will continue to keep its customers informed. The company continues to work closely with individuals and vendors in the software security community and recommends that customers run the latest security software available. For more information updates on security issues, customers should visit http://www.microsoft.com/security/.

Microsoft, ActiveX, Visual Basic and Outlook are either registered trademarks or trademarks of Microsoft Corp. in the United States and/or other countries. Other product and company names herein may be trademarks of their respective owners. SOURCE Microsoft Corp.

 
Send mail to webmaster@easysoftweb.com with questions or comments about this web site.rsaclabel.gif (1167 bytes)
Copyright © 1997 Easysoft Integrating Technologies, Inc.
Last modified: September 14, 2003