[11315] in bugtraq

home help back first fref pref prev next nref lref last post

Status of Excel97 ODBC Security Vulnerability

daemon@ATHENA.MIT.EDU (Microsoft Product Security Respons)
Mon Aug 9 18:19:48 1999

Message-Id:  <D1A11CCE78ADD111A35500805FD43F5801979335@RED-MSG-04>
Date:         Fri, 6 Aug 1999 14:52:44 -0700
Reply-To: Microsoft Product Security Response Team <secure@MICROSOFT.COM>
From: Microsoft Product Security Response Team <secure@MICROSOFT.COM>
X-To:         "ntbugtraq@listserv.ntbugtraq.com"
              <ntbugtraq@listserv.ntbugtraq.com>,
              "bugtraq@securityfocus.com" <bugtraq@securityfocus.com>
To: BUGTRAQ@SECURITYFOCUS.COM

Hi All -
I'd like to provide a quick update on the Excel 97 ODBC vulnerability issue.
We are continuing to thoroughly test the solution to ensure it is rock solid
and ready for our customers. The solution will eliminate the vulnerability
in Jet v.3.51 and will be posted on both http://officeupdate.microsoft.com/.
This patch will not require an upgrade to Jet v.4. Our developers and
testers are on track to complete work on the patch and make it available the
week of August 16th. When the patch is available, we will provide a Security
Bulletin and other information that will discuss the steps that customers
should take.  In the meantime, we'll provide updated information at
http://www.microsoft.com/security.
Also, we have just released a new tool called the Office Document Open
Confirmation Tool. By installing it, Office users are prompted for
confirmation when opening any Office document (Word, Excel, PowerPoint or
Access) launched from within Internet Explorer. The tool can be run via a
GUI or from a command line. It is not the solution to the ODBC vulnerability
issue, but can help customers protect themselves by issuing a security
warning, allowing them to choose not to open the document. It's available at
http://www.microsoft.com/security/Issues/OfficeDocOpenTool.asp.
Regards,
Secure@microsoft.com

home help back first fref pref prev next nref lref last post