Security

Flaw in Microsoft Office Web Components could allow remote compromise

by Steve Ragan - Jul 13 2009, 21:35

Share


Share

Interested in a more interactive TTH? Join our Facebook Group
Want regular updates from The Tech Herald? Follow us on Twitter

Comment on this Story

Note our older Talkback system is still running below. We hope to import existing comments into the new system shortly. Guest posting is still allowed, however, you can now login with any number of social network accounts.

Talkback

Add your comment (no registration required)

page: 1 

MajJul 16th, 2009 - 20:18:05

I wasn't able to find in the Microsoft Security Advisory where they described the problem as 'Browse and get owned.'

Perhaps you could help me find it?

Report this comment

SteveR-TTHJul 16th, 2009 - 20:34:09

@Maj

'This vulnerability could be used for remote code execution in a 'browse and get owned' scenario. User interaction is required since a user needs to go to a malicious website that hosts the exploit.' - Fermin J. Serna, MSRC Engineering (SRD Blog 7-13-09, Microsoft Office Web Components vulnerability)


Also, an earlier SRD post, 'A browse-and-get-owned attack vector exists. A user needs to be lured to navigate to a malicious website or a compromised legitimate website to be affected. No further user interaction is needed.' - Chengyun Chu, MSRC Engineering (SRD Blog 7-6-09, MPEG2TuneRequest vulnerability)

Best,
Steve

Report this comment

page: 1 

Add your comment (no registration required)

AddThis Social Bookmark Button

Advertising

Advertising

Advertising

Latest

Review: Motorola Droid
Facebook settlement means little in the long run
Naked Windows 7 vulnerable to Malware if left in default state
Adobe patches Shockwave Player
SSL flaw allows man-in-the-middle attacks

Latest Articles on Monsters&Critics

Nine-man Deportivo move up to fourth by winning in Getafe
Storm Chasers 'Inside the Tornado' Sunday, Nov. 8
Napoli lose momentum against lowly Catania
In Pictures: 'USA Fort Hood Shootings'
In Pictures: 'Mexico Floods'
Dirty Jobs' Mike Rowe covers glassmaking and Dung beetles this week
Bitterness of war hits home, adds to Obama's dilemma
40 years on, Sesame Street still takes the high road
Djokovic, Federer to face off for fifth time this season (Roundup)
International prosecutor targets Kenya election violence suspects

Notice: Undefined index: continent in /home/thetechh/public_html/class/class.slot.php on line 173

Notice: Undefined index: continent in /home/thetechh/public_html/class/class.slot.php on line 173

Notice: Undefined index: continent in /home/thetechh/public_html/class/class.slot.php on line 173

Notice: Undefined index: continent in /home/thetechh/public_html/class/class.slot.php on line 173