Microsoft has only partly fixed a flaw involving malicious script execution involving Office, according to veteran bug hunter Georgi Guninski.
Last week Microsoft issued a patch which meant users who use Word as an email editor in Outlook 2000 or 2002 could fall victim to script execution when a malicious memo is replied to or forwarded.
Outlook blocks scripts when an HTML email is viewed; but when Word is the editor, replying or forwarding calls it in an unprotected mode, and it then allows the script to run. The consequences of exploitation are running arbitrary code (potentially malware) on a local machine with the user's level of privilege.
Microsoft's patch fixes only the Outlook and Word issues and does not fix "at least the exploit path" through Excel, according to Guninski.
|