<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: New MS Office Zero-Days</title>
	<atom:link href="http://www.avertlabs.com/research/blog/index.php/2007/04/10/new-ms-office-zero-days/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.avertlabs.com/research/blog/index.php/2007/04/10/new-ms-office-zero-days/</link>
	<description>Cutting edge security research as it happens.......</description>
	<lastBuildDate>Fri, 12 Mar 2010 09:55:48 -0600</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.3</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Alex Krenvalk</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/04/10/new-ms-office-zero-days/comment-page-1/#comment-726727</link>
		<dc:creator>Alex Krenvalk</dc:creator>
		<pubDate>Thu, 29 Jan 2009 02:35:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=253#comment-726727</guid>
		<description>Know tool better-&lt;a href=&quot;http://www.recoverytoolbox.com/forgot_pst_password.html&quot; rel=&quot;nofollow&quot;&gt;forgot .pst password&lt;/a&gt;,it also free,but program has many features,it retrieve forgotten or lost passwords for Microsoft Outlook email client or for files with *.pst extension,can work not only with mail accounts, but also with password protected *.pst files,rogram is very easy, its simple interface can be used by anyone: from beginners to professionals,tool quickly sorts all characters, including multilingual ones and composes another password for you,can accept millions of different password, that differ from the original one, that was forgot pst 2003 password,provides a legal possibility to recover, when your forgot the pst password for Office 2003.</description>
		<content:encoded><![CDATA[<p>Know tool better-<a href="http://www.recoverytoolbox.com/forgot_pst_password.html" rel="nofollow">forgot .pst password</a>,it also free,but program has many features,it retrieve forgotten or lost passwords for Microsoft Outlook email client or for files with *.pst extension,can work not only with mail accounts, but also with password protected *.pst files,rogram is very easy, its simple interface can be used by anyone: from beginners to professionals,tool quickly sorts all characters, including multilingual ones and composes another password for you,can accept millions of different password, that differ from the original one, that was forgot pst 2003 password,provides a legal possibility to recover, when your forgot the pst password for Office 2003.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: More Office Zero Day Vulnerabilities ~ usrbingeek&#8217;s musings</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/04/10/new-ms-office-zero-days/comment-page-1/#comment-464051</link>
		<dc:creator>More Office Zero Day Vulnerabilities ~ usrbingeek&#8217;s musings</dc:creator>
		<pubDate>Thu, 22 May 2008 03:10:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=253#comment-464051</guid>
		<description>[...] [New MS Office Zero-Days] [...]</description>
		<content:encoded><![CDATA[<p>[...] [New MS Office Zero-Days] [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dreifacher Bug-Alarm an Microsofts Patch-Day - News &#124; ZDNet.de Security - Sicherheit</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/04/10/new-ms-office-zero-days/comment-page-1/#comment-220563</link>
		<dc:creator>Dreifacher Bug-Alarm an Microsofts Patch-Day - News &#124; ZDNet.de Security - Sicherheit</dc:creator>
		<pubDate>Tue, 04 Dec 2007 04:34:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=253#comment-220563</guid>
		<description></description>
		<content:encoded><![CDATA[<p>[...] Laut dem McAfee Avert Labs Blog haben Experten drei neue Fehler in Microsoft Office entdeckt. Zwei der drei Sicherheitslücken können dem Blog zufolge durch Denial-of-Service-Attacken ausgenutzt werden, sodass das betroffene Programm abstürzt. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Microsoft SÄ±fÄ±r GÃ¼nleri Devam Ediyor, Hedef: Office ve Windows &#124; TanSu@doctus</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/04/10/new-ms-office-zero-days/comment-page-1/#comment-74379</link>
		<dc:creator>Microsoft SÄ±fÄ±r GÃ¼nleri Devam Ediyor, Hedef: Office ve Windows &#124; TanSu@doctus</dc:creator>
		<pubDate>Wed, 06 Jun 2007 07:59:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=253#comment-74379</guid>
		<description>[...] DÃ¼n yayÄ±nlanan beÅŸ kiritik aÃ§Ä±ÄŸÄ±n yamalarÄ± soÄŸumadan yeni sÄ±fÄ±r gÃ¼nÃ¼ aÃ§Ä±klarÄ±nÄ±n haberleri geliyor. McAfee Avert Labs blogâ€™unda yazÄ±lan bir rapora gÃ¶re, Officeâ€™in bazÄ± zayÄ±flÄ±klarÄ±nÄ± suistimal eden bazÄ± saldÄ±rÄ± kodlarÄ± yayÄ±nlanmÄ±ÅŸ durumda. AynÄ± zamanda Windowsâ€™da bu kodlarÄ±n tehditi altÄ±nda. [...]</description>
		<content:encoded><![CDATA[<p>[...] DÃ¼n yayÄ±nlanan beÅŸ kiritik aÃ§Ä±ÄŸÄ±n yamalarÄ± soÄŸumadan yeni sÄ±fÄ±r gÃ¼nÃ¼ aÃ§Ä±klarÄ±nÄ±n haberleri geliyor. McAfee Avert Labs blogâ€™unda yazÄ±lan bir rapora gÃ¶re, Officeâ€™in bazÄ± zayÄ±flÄ±klarÄ±nÄ± suistimal eden bazÄ± saldÄ±rÄ± kodlarÄ± yayÄ±nlanmÄ±ÅŸ durumda. AynÄ± zamanda Windowsâ€™da bu kodlarÄ±n tehditi altÄ±nda. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Is DoS a vulnerability? &#171; The Ramblings of a Security Professional</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/04/10/new-ms-office-zero-days/comment-page-1/#comment-51275</link>
		<dc:creator>Is DoS a vulnerability? &#171; The Ramblings of a Security Professional</dc:creator>
		<pubDate>Sun, 15 Apr 2007 17:11:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=253#comment-51275</guid>
		<description>[...] Now, back to the Word 2007 DoS 0day claims. The so-called MS security-guru David LeBlanc touts these claims as &#8220;security features&#8221;. Word crashed due to a protection mechanism that causes a crash instead of allowing for a possible exploit. Nobody is going to argue that a crash is much preferred over an exploit, but people, such as myself and ComputerWorld&#8217;s Frank Hayes, will argue that DoS should be classified as a security concern. [...]</description>
		<content:encoded><![CDATA[<p>[...] Now, back to the Word 2007 DoS 0day claims. The so-called MS security-guru David LeBlanc touts these claims as &#8220;security features&#8221;. Word crashed due to a protection mechanism that causes a crash instead of allowing for a possible exploit. Nobody is going to argue that a crash is much preferred over an exploit, but people, such as myself and ComputerWorld&#8217;s Frank Hayes, will argue that DoS should be classified as a security concern. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Il blog di Guido Arata: diffusione-del-sapere-informatico: news-exploit-bug-sicurezza-informatica-programmazione</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/04/10/new-ms-office-zero-days/comment-page-1/#comment-50180</link>
		<dc:creator>Il blog di Guido Arata: diffusione-del-sapere-informatico: news-exploit-bug-sicurezza-informatica-programmazione</dc:creator>
		<pubDate>Thu, 12 Apr 2007 14:04:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=253#comment-50180</guid>
		<description></description>
		<content:encoded><![CDATA[<p>[...] Tutto ciÃ² mentre in rete giÃ appaiono notizie riguardanti nuovi bug con exploit scovati in Office (anche in Office 2007) . Microsoft perÃ² smentisce prontamente: gli esperti hanno indagato, e non Ã¨ saltato fuori nulla di nuovo, ne in relazione ai piÃ¹ anziani Office ne tantomento nella nuova suite Office 2007. Allarme rientrato dunque? Segnala su Technotizie [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DLL Soluzioni Informatiche &#187; 2007 &#187; Aprile &#187; 12</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/04/10/new-ms-office-zero-days/comment-page-1/#comment-50086</link>
		<dc:creator>DLL Soluzioni Informatiche &#187; 2007 &#187; Aprile &#187; 12</dc:creator>
		<pubDate>Thu, 12 Apr 2007 08:48:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=253#comment-50086</guid>
		<description></description>
		<content:encoded><![CDATA[<p>[...] Mentre Microsoft rilasciava i suoi nuovi bollettini di sicurezza, su alcuni forum sono apparsi gli exploit di nuove falle zero-day di Office. Secondo quanto riportato in questo post da McAfee Avert Labs, almeno una delle vulnerabilitÃ Ã¨ potenzialmente utilizzabile per eseguire del codice da remoto. Tipicamente i cracker riescono a sfruttare questo tipo di bug creando dei documenti che, una volta aperti, causano il crash dell&#8217;applicazione ed eseguono del codice dannoso con gli stessi privilegi dell&#8217;utente locale. News.com sostiene che Microsoft stia attualmente investigando sul problema e che, al momento, non sia a conoscenza di alcun attacco che faccia leva su queste debolezze. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DLL Soluzioni Informatiche &#187; Blog Archive &#187; Patch per Windows XP e Vista</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/04/10/new-ms-office-zero-days/comment-page-1/#comment-50082</link>
		<dc:creator>DLL Soluzioni Informatiche &#187; Blog Archive &#187; Patch per Windows XP e Vista</dc:creator>
		<pubDate>Thu, 12 Apr 2007 08:44:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=253#comment-50082</guid>
		<description></description>
		<content:encoded><![CDATA[<p>[...] Mentre Microsoft rilasciava i suoi nuovi bollettini di sicurezza, su alcuni forum sono apparsi gli exploit di nuove falle zero-day di Office. Secondo quanto riportato in questo post da McAfee Avert Labs, almeno una delle vulnerabilitÃ Ã¨ potenzialmente utilizzabile per eseguire del codice da remoto. Tipicamente i cracker riescono a sfruttare questo tipo di bug creando dei documenti che, una volta aperti, causano il crash dell&#8217;applicazione ed eseguono del codice dannoso con gli stessi privilegi dell&#8217;utente locale. News.com sostiene che Microsoft stia attualmente investigando sul problema e che, al momento, non sia a conoscenza di alcun attacco che faccia leva su queste debolezze. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .:Computer Defense:. &#187; It Never Fails&#8230;</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/04/10/new-ms-office-zero-days/comment-page-1/#comment-49934</link>
		<dc:creator>.:Computer Defense:. &#187; It Never Fails&#8230;</dc:creator>
		<pubDate>Wed, 11 Apr 2007 22:59:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=253#comment-49934</guid>
		<description></description>
		<content:encoded><![CDATA[<p>[...] Yet again we see it happening&#8230; Patch Tuesday rolls around and suddenly we&#8217;re hit by more &#8220;0-days&#8221; for Microsoft products. This time it&#8217;s primarily Office, but a heap-overflow in .HLP files was also released. McAfee AVERT Labs have been doing some research into the vulnerabilities, however they haven&#8217;t had much to say yet. Initially they only addressed the Office flaws but came back later to include the .HLP heap-overflow. These 4 PoCs (2 DoS andÂ 2 overflows) were released to the Full Disclosure mailing list by muts (of BackTrack fame). This was also discussed over at heise Security. They have mentioned that there&#8217;s no proof yet that these are new vulnerabilities, they may actually be related to the vulnerabilities announced by eEye. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Mosby at myITforum.com : McAfee Avert Labs Blog - New MS Office Zero-Days</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/04/10/new-ms-office-zero-days/comment-page-1/#comment-49843</link>
		<dc:creator>Chris Mosby at myITforum.com : McAfee Avert Labs Blog - New MS Office Zero-Days</dc:creator>
		<pubDate>Wed, 11 Apr 2007 15:02:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=253#comment-49843</guid>
		<description>[...] Trackback [...]</description>
		<content:encoded><![CDATA[<p>[...] Trackback [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
