Their latest bundle of patches are due to be released tomorrow, meaning they almost certainly won’t be able to include a fix for this security hole in this round of fixes.įurther reading: Vanja in our labs has posted a blog entry with more information about this vulnerability.įollow on Twitter for the latest computer security news. News of this latest zero day vulnerability couldn’t have bubbled up at a worse time for Microsoft. You may use a copy of this supplement with each validly licensed copy of the software.
#Microsoft office web components 2003 how to
You can read their detailed instructions on how to “kill” OWC on their Security Research & Defense blog.īut if the thought of fiddling with the Registry brings you out in hives, you might prefer to try their “Fix It” button instead which will run the workaround. By installing the app, you agree to these terms and conditions: PLEASE NOTE: Refer to your license terms for Microsoft Office browser extension software (the 'software') to identify the entity licensing this supplement to you and for support information. The current supported version of OWC is Microsoft Office 2003 Web Components for versions 9, 10, and 2010. Microsoft has produced a workaround which involves stopping the Office Web Components library from running in Internet Explorer. Office Web components are no longer supported since Office 2007 and it is not supplied with Microsoft Office 2007 or above.
#Microsoft office web components 2003 Patch
So far, there is no patch available from Microsoft to fix the problem, but Sophos customers can be reassured that we have added detection of the exploit as Exp/OWCref-A. Microsoft says it has seen a limited number of attacks exploiting the vulnerability, which specifically lies in the Spreadsheet ActiveX control which can be embedded into webpages.Īffected products include (take a deep breath!) Microsoft Office XP Service Pack 3, Microsoft Office 2003 Service Pack 3, Microsoft Office XP Web Components Service Pack 3, Microsoft Office 2003 Web Components Service Pack 3, Microsoft Office 2003 Web Components for the 2007 Microsoft Office system Service Pack 1, Microsoft Internet Security and Acceleration Server 2004 Standard Edition Service Pack 3, Microsoft Internet Security and Acceleration Server 2004 Enterprise Edition Service Pack 3, Microsoft Internet Security and Acceleration Server 2006, Internet Security and Acceleration Server 2006 Supportability Update, Microsoft Internet Security and Acceleration Server 2006 Service Pack 1, and Microsoft Office Small Business Accounting 2006.
Microsoft has published an advisory about a serious security vulnerability in its Office Web Components (OWC) software that could allow an attacker to run malicious code on your computer.