bk99.de entertain the web since 1997

Microsoft plugs security holes in Office Web Components

Summary

In August 2002 Microsoft reported three critical holes in Office Web Components 2000 and 2002, which were part of Office, Money, Project and several server products. Via the Host() function, a prepared web page could start Office programs and execute arbitrary commands, and two further holes exposed the clipboard and local files. The patch was already included in Service Pack 2 for Office XP.

Ideas

  • A reused component carries its holes into many products.
  • A web page could start local programs through an Office component.
  • The clipboard and local files could be read from within the browser.

Insights

  • Shared libraries enlarge the attack surface across product boundaries.
  • The boundary between browser and desktop application was a central point of entry at the time.

Facts

  • Among others, Office 2000, Office XP, Money 2002 and 2003 and Project 2002 were affected.
  • Service Pack 2 for Office XP already contained the patch.

References

Critique

  • The report lists affected products but does not explain how administrators can find all installations of the component.

Recommendations

  • Take inventory of which products bring shared components with them in order to patch completely.
  • Disable browser extensions and ActiveX-like interfaces that are not needed.

Read the original article

Search the Web Archive