Microsoft
Microsoft has revealed more details about the Office Jet attack

Microsoft updates Office Jet attack advisory

Company provides background on new Office attack

Written by Shaun Nichols in California

Everything changed with the discovery of this new attack vector

Mike Reavey Microsoft Security Response Center manager

Microsoft has shed further light on last week's attacks on the Office Jet database component.

The company issued an update to its original security advisory, in which Microsoft Security Response Center manager Mike Reavey provided more information about the attack and how it differs from previous threats.

Security researchers had noticed that the attack exploits MDB files which Microsoft had previously deemed "unsafe" and attempts to shield itself from discovery.

Reavey explained that the attackers had found a new way to access the files, allowing them to hide the threat in a Word file.

"Everything changed with the discovery of this new attack vector that allowed an attacker to load an MDB file via opening a Microsoft Word document," wrote Reavey. "The previous guidance does not work against this new attack."

Reavey claimed that Microsoft has developed a new version of the MS Jet component which is protected from the attacks.

The updated component is already in use by Windows Vista and Server 2003. Windows XP SP3 will also contain a fix when it ships later this year. Office 2003 SP2 is also protected.

Reavey said that Microsoft is considering including a fix in a later security update. He also offered a couple of security tips.

"Enterprise administrators can block Jet files, even those renamed from MDB, at the gateway," he said.

"For end-users, we will continue to recommend that you never, ever open atta chments received unexpectedly."

Further reading

Microsoft warns of new Office attack

Attackers take aim at database component   More...

Microsoft snaps up Komoku

Redmond buys in more security expertise   More...

PCs take centre stage in home cinemas

ABI predicts bright future for PCs at the heart of connected homes   More...

Windows Vista SP1 causing PC glitches

Users complain of service pack gremlins   More...

Related articles

Microsoft warns of new Office attack

Attackers take aim at database component   More...

Attack exploits 'unsafe' Windows files

Access Database files used for attacks   More...

Hackers unleash 'insidious' crimeware attack

Trusted websites turned into traps   More...

Google warns of web malware epidemic

One in ten sites hosting code that attacks browsers   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

09 May 2008

2.51 MBWiMax muddle, Google tactics and asteroid bunkum More...

08 May 2008

3.26 MBBroadband Anywhere, phone-free transport and Web 3.0 More...

07 May 2008

3.19 MBUK success, a paucity of IT women and robot wars More...

Poll

DATA ENCRYPTION

DATA ENCRYPTION

Should encryption be mandatory for all personal data held by companies and governments?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Ofcom

Ofcom outlines future wireless vision

Wi-Fi healthcare and intelligent car brakes in the pipeline   More...

HP

HP Labs opens doors to academia

Innovation Research Program invites proposals related to current research   More...

Advertisement

Asteroid

Nasa plans manned mission to asteroid

Bruce Willis thankfully not going   More...

MySpace

MySpace offers opt-in data sharing

Deals signed with Photobucket, Twitter, eBay and Yahoo   More...

Advertisement