" />

Tech Geek and More

Technology Explained for All

AD IDrive Remote Backup

Alert: You need to make sure your Windows/Office software is up to date. Targeted attacks against recently addressed Microsoft Office vulnerability is now out

Last November, Microsoft released security bulletin MS10-087 (http://www NULL.microsoft NULL.com/technet/security/Bulletin/MS10-087 NULL.mspx), which addresses a number of critical vulnerabilities in how Microsoft Office parses various office file formats. One of them is CVE-2010-3333 (http://cve NULL.mitre NULL.org/cgi-bin/cvename NULL.cgi?name=CVE-2010-3333), “RTF Stack Buffer Overflow Vulnerability,” which could lead to remote code execution via specially crafted RTF data. A few days before Christmas, we received a new sample (sha1: cc47a73118c51b0d32fd88d48863afb1af7b2578) that reliably exploits this vulnerability and is able to execute malicious shellcode which downloads other malware.

The notice that was posted on the Microsoft Protection Center blog ( http://blogs.technet.com/b/mmpc/archive/2010/12/29/targeted-attacks-against-recently-addressed-microsoft-office-vulnerability-cve-2010-3333-ms10-087.aspx (http://blogs NULL.technet NULL.com/b/mmpc/archive/2010/12/29/targeted-attacks-against-recently-addressed-microsoft-office-vulnerability-cve-2010-3333-ms10-087 NULL.aspx) ) concerns a flaw in the Microsoft Office program that was fixed in November. The bad guys have now found a way to exploit the flaw on computers that do NOT have the updated software. This affects you no matter which version of Office or Windows you are running.

Symantec underlined the seriousness of the flaw to CNET’s Elinor Mills in November:

“One of the most dangerous aspects of this vulnerability is that a user doesn’t have to open a malicious e-mail to be infected,” Joshua Talbot, security intelligence manager at Symantec Security Response, said at the time. “All that is required is for the content of the e-mail to appear in Outlook’s Reading Pane. If a user highlights a malicious e-mail to preview it in the Reading Pane, their machine is immediately infected. The same holds true if a user opens Outlook and a malicious e-mail is the most recently received in their in-box; that e-mail will appear in the Reading Pane by default and the computer will be infected.”

image

So what does this mean to you…….It means that if you receive an email, even if its obvious that the email is bad and you don’t click on it, just by it appearing in the reading pane section, will cause your computer to get infected with malware.

How do you make sure you are protected?

Windows Vista / Windows 7

If you are running Windows Vista or Windows 7 go to start –> Control Panel –> Windows Update

Once in Windows Update –>  click on Check for updates –> Once the scan is complete –> system will tell you how many updates you need –> now click on Install updates.

image

Once you have successfully updated all Windows / Office software your Windows update should look like this.

image

Windows XP

In Windows XP –> Using Internet Explorer –> Visit the Microsoft Update website (LINK) http://www.update.microsoft.com/microsoftupdate/v6/default.aspx?ln=en-us (http://www NULL.update NULL.microsoft NULL.com/microsoftupdate/v6/default NULL.aspx?ln=en-us)

(IMPORTANT NOTE: In XP – Microsoft has 2 websites for updates. One is called Windows Updates and one is called Microsoft Updates. You want to make sure that you are on the one that says Microsoft Updates as the Windows Updates site does NOT give you Office updates)

image

Once you are on the site –> Click on Custom and let it scan your pc.  (Note you may be asked to run an ActiveX file if this is the 1st time you have been to the site. Just make sure you say you in this case specifically)

image

You may also get a message about a needed download –> if you do just click on “Download and Install Now”

image

Once Microsoft Update completes its scan it will show you what updates you are missing

image

Look under the “High Priority” updates and make sure that you have selected them all

image

Followed up clicking on “Review and install updates”

image

This will bring you to the confirmation page.  Make sure you have all missing updates selected. You will see 1 final “Install Updates”. Click on it –>

image

Followed by “I Accept” under the agreements area –> and then watch your updates download and install.

After the updates install –> Reboot pc –> and visit site again to see if you have any remaining updates.  Continue the steps until you get 0 (zero) remaining “High Priority” updates.

image

Once you are at 0 (Zero) now your Windows / Office software is up to date.

(FINAL NOTE: This does NOT mean you are free and clear, as always you need to take care of precautions when surfing the Internet.  There are still many other ways you can have your computer compromised)

Software: Error "The operation failed. An object could not be found" when you click Send and Receive in Outlook

microsoft  This one was just brought to my attention today by one of my customers.  They recently went thru an upgrade from Office 2003 to Office 2007.  Now when they attempt to send/receive an email they get the error “The operation failed. An object could not be found” (Shown Below).

image

 

It appears that the issue involves your profile in Outlook. The follow steps should correct the issue.

Steps are from Microsoft Support Article #312354 (LINK) http://support.microsoft.com/kb/312354 (http://support NULL.microsoft NULL.com/kb/312354)

- To resolve this behavior, create a new profile. To do this, follow these steps:

  1. Click Start, point to Settings, and then click Control Panel.
  2. Double-click the Mail icon.
  3. In the Mail Setup dialog box, click Show Profiles.
    If you want to be able to select a specific profile each time you start Outlook, click the General tab, click Prompt for a profile to be used, and then click Add.
  4. In the New Profile dialog box, under Profile Name, type a descriptive name for the new profile, and then click OK.
  5. In the E-mail Accounts dialog box, select Add a new e-mail account in the e-mail options, and then click Next.
  6. Click the type of server that your e-mail account works with, and then click Next.
  7. Complete all of the required fields, including those that are on the tabs that appear after you click More Settings.
  8. When you finish providing the required information, click Finish

Ads by Google

View in: Mobile | Standard