Welcome | Sign In
ECommerceTimes.com
Exploits & Vulnerabilities

Database Engine Flaw Makes Word Attachments Dangerous

Print Version
E-Mail Article
Reprints
Database Engine Flaw Makes Word Attachments Dangerous

Microsoft believes the risk from a vulnerability in its database engine to be limited "because customers have to take several steps in order for the attacks to be successful." For example, one attack uses a safe Word file and a malicious Access file sent together as e-mail attachments. The victim must save both files in one folder and open the Word file first; this contains code that will open the malicious Access file.


eMarketer Whitepaper: Optimizing the E-Commerce Experience
From the Web to the Contact Center, are you prepared to proactively engage and keep your savvy customers? Read how e-commerce leaders are optimizing their sites with ratings, reviews, live help, Web analytics, mobile and more.

Don't open that Word file attached to your e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse; it might contain malware.

And don't click on that e-mail or Web site links from strangers. Heck, don't even open Word e-mail attachments from trusted sources unless you're expecting them.

Attackers are embedding malware in Word documents that causes a buffer overflow in their victims' computers, letting them take over the computers.

Data is stored in fixed-length buffers, and a buffer overflow causes applications to try to store data beyond the boundaries of those buffers.

This could create a system crash or, as in this case, software vulnerabilities that let an attacker take over your computer.

Where You're Safe -- and Unsafe

Computers running Windows Server 2003 Service Pack (SP) 2, Windows Vista, and Windows Vista SP 1 are not vulnerable to the buffer overrun, Microsoft (Nasdaq: MSFT) told TechNewsWorld.

However, those running Microsoft Word 2000 SP 3, Microsoft Word 2002 SP 3, Microsoft Word 2003 SP 2, Microsoft Word 2003 SP 3, Microsoft Word 2007, and Microsoft Word 2007 SP 1 on Microsoft Windows 2000, Windows XP, or Windows Server 2003 SP 1 are open to attack.

The vulnerable software uses an older version of Microsoft's Jet Database Engine -- which shares data between Microsoft Office products and other applications -- that is open to this sort of attack. Ironically, the much-maligned Windows Vista is not vulnerable to the attack because it uses an updated version of the Jet Database Engine.

Just Another Microsoft Flaw

This particular flaw was first reported in November of 2007 on Bugtraq by Frank Ruder.

At that time, he said Access 2003 SP 3 on the Chinese-language version of Windows XP SP 2 was affected, but warned other versions of Windows could also be affected.

He quoted Microsoft as saying that Microsoft considers the MDB file type unsafe and that Internet Explorer and Outlook will automatically block these files.

In December 2007, the US-CERT Computer Emergency Readiness Team warned about the same problem. Don't open attachments from unsolicited e-mail messages; and block high-risk file attachments at e-mail gateways, it said.

If Microsoft itself considers the MDB file format unsafe, why doesn't it re-engineer the silly thing?

Because it's not all that simple. "Changing the file format would entail many other changes," Dr. Chenxi Wang, principal analyst of security and risk management at Forrester Research, told TechNewsWorld. "There are applications written using this, there are driver files written using this, so it's not so easy a change as the click of a button."

Precautions to Take

"Enable a firewall, apply all software updates and install anti-virus and anti-spyware software," Microsoft said.

You can find additional information here.

Microsoft believes the risk from these attacks to be limited "because customers have to take several steps in order for the attacks to be successful."

For example, one attack uses a safe Word file and a malicious Access file sent together as e-mail attachments. The victim must save both files in one folder and open the Word file first; this contains code that will look for the malicious Access file and open it.

Few people will actually be impacted by these attacks. For one thing, "there are some very specific conditions" that must be met for this type of attack to succeed," Wang said.

And it's not really Microsoft's fault, either. "Writing these database engines is incredibly complex, and when an error combination arises where a very specific set of conditions has to be met, it's easy to miss because there are so many possible scenarios," Wang said.

Having studied Microsoft's internal software security practices in depth, "there isn't another company that has such comprehensive and in-depth software security practices," Wang added.

Your best bet is to never open e-mail attachments, especially if you don't know the sender.

Remember what Mom said about not taking candy from strangers?


Print Version E-Mail Article Reprints More by Richard Adhikari


Related News Alerts

Microsoft Activate Alert | Search Archives

More by Richard Adhikari

New Pogoplug Brings Mobile Devices Into the Cloud
November 20, 2009
The Pogoplug allows a user to run a personal cloud server from a home network. The data resides on hard drives and thumb drives that plug directly into the Pogoplug device; from there, the data can be accessed from anywhere via the Internet. Keep in mind that some ISPs forbid customers from hooking servers up to residential connections, though those rules are rarely enforced.
Google Spills Chrome OS' Guts
November 19, 2009
Google has made public the source code for its upcoming Chrome operating system. The OS will begin appearing on consumer-targeted netbooks next year. Chrome is built to live completely on the Web -- very little data is stored directly on the user's hard drive. This could make for much faster boot times and enhance security.
Cyberfraud Arrests Unlikely to Stem ZeuS Rampage
November 18, 2009
Two alleged cybercrooks have been nabbed in the UK on suspicion of using a well-know Trojan to commit banking fraud. The malware in question in known as "ZeuS" or "Zbot," and althought it's quite common, it's also sometimes difficult for antivirus applications to nail. Simple software kits exist online for relatively inexperienced hackers to create unique malware for the purpose of fraud.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network