Warning over fake Windows update
Online April 10, 2005
Users are being warned to watch out for a fake Microsoft security update, BBC News reports.
Anti-virus firm Sophos spotted the e-mail which uses subject lines saying "Urgent Windows Update" and "Important Windows Update". In the body of the message is a web link that looks like it should link to the Windows Update website but in fact links to a site controlled by the malicious hackers.
Anyone falling victim to this could leave computer owners vulnerable to identity theft or having their computer used to send spam, attack other sites or host dubious material.
Microsoft urged users to ensure they visit legitimate sites when downloading updates.
Click here to read the full story.
outra
Office flaw exploit code published
Microsoft is investigating the report of a flaw that could open systems using its Access or Office software up to attack, ZDNet UK reports.
The vulnerability, which was not one of eight patched by Microsoft on Tuesday, could enable an intruder to remotely execute malicious code on a vulnerable PC, security company Secunia said.
Secunia rated the problem "highly critical", noting that exploit code for the flaw had been shared on a public mailing list.
"The vulnerability is caused due to a memory handling error when... parsing database files," Secunia said in its advisory. "This can be exploited to execute arbitrary code by tricking a user into opening a specially crafted '.mdb' file in Microsoft Access."
Microsoft has not confirmed the existence of the security hole.
[url=http://news.zdnet.co.uk/internet/security/0,39020375,39194879,00.htm]Click here to read the full story.
[/url]
sem+++++++++fui








