All the latest UK technology news, reviews and analysis

Microsoft patches 'critical' Office flaw

by Nick Farrell

17 Apr 2002

Be the first to comment

  • Tweet this

Microsoft has finally admitted that the Mac version of Office has a critical security flaw and has released a patch.

The problem, discovered by Josha Bronson at AngryPacket Security in January, happens because Office incorrectly handles an HTML feature.

By using a link on a web page or in an HTML-enabled email, an attacker could cause a program to crash a Macintosh or run arbitrary commands.

All Mac Office programs are affected by the bug, but Microsoft admitted that it is critical on Internet Explorer for Mac OS 8, 9 and X, Outlook Express 5.0.2 and Entourage 2001 and v. X.

The software giant failed to respond to Bronson's warnings about the flaw and he approached security group w00w00. The group got Microsoft to listen, but it took three months to release a patch.

w00w00 said that a failure by Microsoft to respond immediately to a potential security problem ran counter to its highly touted 'Trustworthy Computing' initiative.

But Microsoft blamed the delay on Bronson for sending his report to the wrong person in the company.

A spokesman also said that a three-month response time was understandable, as there was a huge amount of work that had to be done to fix the bug.

"This is the most complex patch that I've seen us deliver in a while in terms of the number of patches that we had to do and the number of products," he explained.

"If you look at the number of products we are addressing we have 11, each of which localises in 12 languages. That's 110 or so patches that we had to do."

Microsoft's advisory and patches can be found on the software giant's website here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

35%

0%

11%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Lead PHP Developer - Technical Architect - Ecommerce Manager

Lead PHP Developer - Technical Architect - Ecommerce...

C# / .NET Software Engineers – Leeds City Centre – C# (£30-50k)

C# Software Engineers required to join rapidly expanding...

Java / J2EE Developers – Leeds City Centre – Java / J2EE (£30-50k)

Java / J2EE Software Engineers required to join rapidly...

Developer (MIS - SQL / T-SQL, HTML, CSS or Javascript)

Developer (MIS / Business Systems - SQL / T-SQL, HTML...

To send to more than one email address, simply separate each address with a comma.