04.05.09

Gemini version available ♊︎

There is Life After Conficker: Critical Microsoft Office Vulnerabilities

Posted in GNU/Linux, Microsoft, Office Suites, Security, Windows at 12:47 pm by Dr. Roy Schestowitz

Expensive office suites leave one’s bank account exposed to malice

Cash grab

Summary: Microsoft Office users are left critically vulnerable and no solution exists to prevent attacks

Conficker is far from gone, but the ‘vulnerabilities treadmill’ marches on. Another unpatched Microsoft Office vulnerability is already being exploited and Microsoft admits this. It is the same old and familiar routine, but Microsoft brought this vulnerability even to Apple Macs.

Microsoft has warned of a vulnerability in their PowerPoint application that can be exploited with a specially crafted presentation file to allow remote execution of code. According to the report, the vulnerability is caused by an invalid object in memory and affects Microsoft Office PowerPoint 2000 Service Pack 3, 2002 Service Pack 3, 2003 Service Pack 3 and Microsoft Office 2004 for Mac. Other versions are reportedly not affected.

More coverage in:

It would probably be more forgivable had it been patched on time, not been such a frequent occurrence, and Windows leadership not said that Microsoft products “just aren’t engineered for security.”

For a secure, free, and standards-compliant office suite, GNU/Linux is recommended because it comes preloaded with one (or several).

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

Decor ᶃ Gemini Space

Below is a Web proxy. We recommend getting a Gemini client/browser.

Black/white/grey bullet button This post is also available in Gemini over at this address (requires a Gemini client/browser to open).

Decor ✐ Cross-references

Black/white/grey bullet button Pages that cross-reference this one, if any exist, are listed below or will be listed below over time.

Decor ▢ Respond and Discuss

Black/white/grey bullet button If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

A Single Comment

  1. Yggdrasil said,

    April 5, 2009 at 7:42 pm

    Gravatar

    It’s important for readers to note that the first article link provided is already old. April 1st, 5 days old now. But why did Roy use this? Because the article paints a very bad picture. It’s got a scary headline, “It’s worse than we thought!” and uses a large, though unproven number of 10 million. It’s not uncommon for news media to try and scare readers. After all, playing on fears is a great way to ensure people read the articles and advertisers get the viewers.

    It would have been better to use something more recent, like this: http://www.theregister.co.uk/2009/04/03/conficker_zombie_count/

    “Conficker zombie botnet drops to 3.5 million” – amazing what a difference a few days makes when it comes to more accurate news reporting.

    However, this article doesn’t make Microsoft look as bad, so Roy will quickly dismiss this article. It’s not fit for BoycottNovell. He is only interested in the worst of the worst. Readers however, would be interested in being given more recent and accurate information.

DecorWhat Else is New


  1. IRC Proceedings: Friday, January 21, 2022

    IRC logs for Friday, January 21, 2022



  2. Peak Code — Part II: Lost Source

    "Debian and Mozilla played along. They were made “Yeoman Freeholders” in return for rewriting their charters to “work closely with the new Ministry in the interests of all stakeholders” – or some-such vacuous spout… because no one remembers… after that it started."



  3. Links 22/1/2022: Ubuntu MATE 21.10 for GPD Pocket 3, MINISFORUM Preloads GNU/Linux

    Links for the day



  4. Computer Users Should be Operators, But Instead They're Being Operated by Vendors and Governments

    Computers have been turned into hostile black boxes (unlike Blackbox) that distrust the person who purchased them; moreover, from a legislative point of view, encryption (i.e. computer security) is perceived and treated by governments like a threat instead of something imperative — a necessity for society’s empowerment (privacy is about control and people in positions of unjust power want total and complete control)



  5. Peak Code — Part I: Before the Wars

    Article/series by Dr. Andy Farnell: "in the period between 1960 and 2060 people had mistaken what they called "The Internet" for a communications system, when it had in fact been an Ideal and a Battleground all along - the site of the 100 years info-war."



  6. Links 21/1/2022: RISC-V Development Board and Rust 1.58.1

    Links for the day



  7. IRC Proceedings: Thursday, January 20, 2022

    IRC logs for Thursday, January 20, 2022



  8. Gemini Lets You Control the Presentation Layer to Suit Your Own Needs

    In Gemini (or the Web as seen through Gemini clients such as Kristall) the user comes first; it's not sites/capsules that tell the user how pages are presented/rendered, as they decide only on structural/semantic aspects



  9. The Future of Techrights

    Futures are difficult to predict, but our general vision for the years ahead revolves around more community involvement and less (none or decreased) reliance on third parties, especially monopolistic corporations, mostly because they oppress the population via the network and via electronic devices



  10. [Meme] UPC for CJEU

    When you do illegal things and knowingly break the law to get started with a “legal” system you know it’ll end up in tears… or the CJEU



  11. Links 20/1/2022: 'Pluton' Pushback and Red Hat Satellite 6.10.2

    Links for the day



  12. The Web is a Corporate Misinformation/Disinformation Platform, Biased Against Communities, Facts, and Science

    Misinformation/disinformation in so-called 'news' sites is a pandemic which spreads; in the process, the founder of GNU/Linux gets defamed and GNU/Linux itself is described as the problem, not the solution to the actual problems



  13. Links 20/1/2022: McKinsey Openwashing and Stable Kernels

    Links for the day



  14. IRC Proceedings: Wednesday, January 19, 2022

    IRC logs for Wednesday, January 19, 2022



  15. Links 20/1/2022: Linuxfx 11.1 WxDesktop 11.0.3 and FreeIPMI 1.6.9 Released

    Links for the day



  16. Links 19/1/2022: XWayland 22.1 RC1 and OnlyOffice 7.0 Release

    Links for the day



  17. Links 19/1/2022: ArchLabs 2022.01.18 and KDE's 15-Minute Bug Initiative

    Links for the day



  18. When Twitter Protects Abusers and Abuse (and Twitter's Sponsors)

    Twitter is an out-of-control censorship machine and it should be treated accordingly even by those who merely "read" or "follow" Twitter accounts; Twitter is a filter, not a news/media platform or even means of communication



  19. IRC Proceedings: Tuesday, January 18, 2022

    IRC logs for Tuesday, January 18, 2022



  20. Links 19/1/2022: Wine 7.x Era Begins and Istio 1.12.2 is Out

    Links for the day



  21. Another Video IBM Does Not Want You to Watch

    It seems very much possible that IBM (or someone close to IBM) is trying to purge me from Twitter, so let’s examine what they may be trying to distract from. As we put it 2 years ago, "Watson" is a lot more offensive than those supposedly offensive words IBM is working to purge; think about those hundreds of Red Hat workers who are black and were never told about ethnic purges of blacks facilitated by IBM (their new boss).



  22. What IBM Does Not Want You to Watch

    Let's 'Streisand it'...



  23. Good News, Bad News (and Back to Normal)

    When many services are reliant on the integrity of a single, very tiny MicroSD card you're only moments away from 2 days of intensive labour (recovery, investigation, migration, and further coding); we've learned our lessons and took advantage of this incident to upgrade the operating system, double the storage space, even improve the code slightly (for compatibility with newer systems)



  24. Someone Is Very Desperate to Knock My Account Off Twitter

    Many reports against me — some successful — are putting my free speech (and factual statements) at risk



  25. Links 18/1/2022: Deepin 20.4 and Qubes OS 4.1.0 RC4

    Links for the day



  26. Links 18/1/2022: GNOME 42 Alpha and KStars 3.5.7

    Links for the day



  27. IRC Proceedings: Monday, January 17, 2022

    IRC logs for Monday, January 17, 2022



  28. Links 17/1/2022: More Microsoft-Connected FUD Against Linux as Its Share Continues to Fall

    Links for the day



  29. The GUI Challenge

    The latest article from Andy concerns the Command Line Challenge



  30. Links 17/1/2022: digiKam 7.5.0 and GhostBSD 22.01.12 Released

    Links for the day


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts