After a heavy April release, Microsoft issued just two security bulletins for May’s Patch Tuesday. The bulletins address vulnerabilities in Office and mail products.
MS10-031 addresses a flaw in the Visual Basic environment associated with Visual Basic for Applications (VBA). It is rated “critical” for Microsoft VBA SDK 6.0, and third-party applications that use Microsoft VBA. For Office XP, Office 2003, and Office 2007, MS10-031 is rated as “important.”
Although there are several available patches to fix the VBA flaw, the Microsoft patches released Tuesday may not solve the problem in third-party applications if the vendor didn’t follow best practices. In some cases, then, the vendor may have to serve up its own patch.
Joshua Talbot, security intelligence manager for Symantec Security Response, put the Visual Basic for Applications vulnerability first on his list this month.
“Both vulnerabilities require social engineering to exploit, but the VBA vulnerability requires less action from a user,” Talbot said. “For instance, an attacker would simply have to convince a user to open a maliciously crafted file — likely an Office document — which supports VBA and the user’s machine would be compromised. I can see this being used in targeted attacks, which are on the rise.”
Mail Vulnerabilities Fixed
The second security bulletin is MS10-030. The vulnerability, which is caused when a malicious response is received from a POP3 or IMPAP server, could allow an attacker to execute malicious code remotely. For Windows Mail and Windows Live Mail, Windows 2000, XP, Vista, Server 2003, and Server 2008, the flaw carries a “critical” rating. The impact is lessened for Windows 7 and Windows Server 2008 R2, where it carries an “important” rating.
“It is important to note that neither has a mail client installed by default,” said Paul Henry, a security and forensic analyst at Lumension. “Deployment of the patch…