Header Ziff Davis Enterprise
Advertisement
Advertisement
Monday, December 01, 2008 7:19 AM/EST

Vulnerabilities and Office Versions

Most of the ink on Microsoft vulnerability coverage goes to browsers and operating systems, but in a way the best progress vulnerabilities have made has been in Microsoft Office. Some of the great attacks of all time (remember LoveLetter?) have been through Office bugs, and I believe most targeted attacks over the last few years have utilized vulnerabilities in Office document parsers.

That's why it's encouraging that Microsoft has done a much better job in making current versions of Office secure, as David LeBlanc's recent blog shows. He claims that the company has really stepped up the security testing for Office 2003 SP3 and Office 2007, and that it shows up in the number of reported vulnerabilities. The trend is clear: There are about half as many vulnerabilities as for earlier versions.

There may be a little flaw in the analysis in that LeBlanc studied reports during the period from 9/18/2007 to 11/17/2008. By that time earlier Office versions had been around for a long time and many vulnerabilities had already been reported on them. But even so, it makes the numbers all the more impressive for the new versions; the older ones had already had the low-hanging fruit picked clean and yet they still had CVE numbers in excess of the new ones. It seems there is no low-hanging vulnerability fruit in new versions of Office.

Are you running an old version of Office? Are you running Office 2003 SP2, which reached the end of support life in October? If so, you are exposing yourself to more known threats than you may think.

Office versions are not plug-and-play interchangeable. It's unfortunate that Microsoft saw fit to accompany Office 2007's security enhancements with a radical user interface change. I personally have gotten used to it, but I can see an enterprise being intimidated by the training it would necessitate.

If you feel you're stuck in Office 2003, at the very least it's irresponsible to linger on in an old service pack. Do what you can to move on to SP3.

TrackBack

TrackBack

http://blogs.eweek.com/cgi-bin/mte/mt-tb.cgi/15869

Listed below are links to weblogs that reference Vulnerabilities and Office Versions:

CVE Count and Statistics from David LeBlanc's Web Log
Larry Seltzer had some interesting comments on my post about the rate of Office vulnerabilities at Vulnerabilities [Read More]

Post a Comment

 
 
Advertisement
Advertisement