Microsoft da len tieng phu nhan 3 loi bao mat zero-day moi
trong bo ung dung Office dong thoi mot lan nua len an cach cong bo thong tin ve
cac loi bao mat.
Dung ngay Microsoft cho phat hanh ban cap nhat dinh ky hang thang hom thu 3 vua
qua mot loat website cua cac hang bao mat deu len tieng canh bao ve 4 loi bao
mat moi trong cac san pham cua Microsoft. Trong so nay co
3 loi duoc xem la loi zero-day trong Word 2007.
Trong tuyen bo phat di ngay hom qua (11/4) Microsoft khang dinh Office 2007
khong he mac nhung loi tren.
Hang phan mem so mot the gioi cung cho biet ho khong he nhan duoc thong bao nao
truoc khi thong tin ve nhung loi do duoc tiet lo. Khong chi Microsoft ma ca
nganh cong nghiep bao mat thuong len an phuong thuc cung cap thong tin kieu nay.
Chuyen
gia tu van cong nghe cao cap cua Sophos Graham Cluley cho biet da co it nhat 2
website phat tan ma khai thac truoc khi nhung thong tin ve loi duoc gui toi cho
Microsoft.
Thong tin dang tai tren website Security Vulnerabilities cho biet hai trong so 3
loi duoc gan cho Word 2007 co the gay ra tinh trang muc do su dung CPU vot len
100% tao dieu kien tan cong tu choi dich vu. Loi con lai co the tao dieu kien
cho phep ke tan cong tu xa thuc thi ma doc tren he thong mac loi.
Loi bao mat thu 4 duoc phat hien trong dot nay thuoc ve dinh dang tep tin "hlp"
trong Windows. Loi nay co the gay ra tinh trang tran bo nho dem. Microsoft xac
nhan loi nay va cho biet them chuan "hlp" la mot chuan dinh dang khong an toan
co the bi loi dung de van hanh ma.
Microsoft khuyen cao nguoi dung khong nen mo cac tep tin ".hlp" duoc gui den tu
cac email co nguon goc khong ro rang.
Cac chuyen gia nghien cuu bao mat cho rang hien so luong cac loi bao mat trong
he dieu hanh Windows dang ngay mot it di thi hacker se chuyen sang khai thac cac
loi bao mat trong cac san pham khac cua Microsoft.
Theo PC World, VnMedia
Article source http://w4rum.com/1279.t
|