The Register® — Biting the hand that feeds IT

Feeds

MS to 'backport' Office 2007 security improvements

Papering over the cracks

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

Microsoft plans to push security improvements made in Office 2007 down the food chain with the next major update for Office 2003.

Service Pack 3 (SP3) for Office 2003 will "backport" some (but not all) of the security improvements built into Office 2007. "We're trying to take what we learned from building Office 2007 and bring as much as we can to Office 2003," Joshua Edwards, a technical product manager for Office at Microsoft, told News.com. "We're not going to take everything, but we will take as much as we can," he added.

Redmond is yet to say when SP3 for Office 2003 will be available, much less outline what features it will have. But Edwards suggested that hardening applications and file parsers against attacks are among the improvements.

Customised attacks targeting vulnerabilities in Word and PowerPoint are on the rise, according to net security firms such as MessageLabs, so Redmond's work on making these applications less of a soft target for hackers is welcome.

Office 2003 SP2, released in September 2005, also focused on security. Sadly, it didn't do much to stem the usual tide of security bugs.

Office 2007 has proved more robust, resisted a flaw dating from February 2007 that was used to compromise Office 2003 systems, for example. Mind you, Office 2007 has only been around since January so describing it as battle-hardened would be a little premature. ®

Agentless Backup is Not a Myth

Latest Comments

All suites are like this

Nathan's comment about multiple apps cobbled together applies to most productivity suites.

People want the ability to move data between applications without having to first save them to a file. Open Office is much the same.

Much of the weakness is just how powerful Microsoft made the macro and data access functionality. Power users can get a lot out of these features, but they are a risk to those who don't use them.

0
0

Slim and none...

[QUOTE]

Anyone out there knows whether MS will ship some security service pack for Office 2000? I mean... the sole reason why I would want to upgrade would be the security holes reported against it (mostly the same ones that haunt 2003 and 2007).

[/QUOTE]

...And the question is: What are the odds of Microsoft supporting older software instead of forcing customers to "buy a patch"...?

[QUOTE]

Otherwise I am perfectly happy with office 2000. Especially Frontpage 2000.

[/QUOTE]

...And it's exactly that sort of thinking that has kept them from their rightful place as overlords of the universe...!

0
0
Anonymous Coward

Office 2000?

Anyone out there knows whether MS will ship some security service pack for Office 2000? I mean... the sole reason why I would want to upgrade would be the security holes reported against it (mostly the same ones that haunt 2003 and 2007).

Otherwise I am perfectly happy with office 2000. Especially Frontpage 2000.

0
0

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
 breaking news
Yahoo! joins! rivals! in! PRISM! data! request! admission!
Keep calm and carry on using American tech firms, folks
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?
 breaking news
'BadNews is malware' says outfit that found it
Google says code harmless but Lookout says code base is evolving