Friday, November 08, 2013

New Microsoft Office Web App Features



OfficeThe Microsoft Office team has been busy adding new features and improvements to the Microsoft Office Web Apps.  Listed below are the changes being made to the Office Web Apps since my April 2013 article, Using Microsoft Office Web Apps

Word App
:
 
A significant improvement is the added ability to find and replace words and phrases.  You will now also be able to apply styles and formatting to tables and insert headers and footers. 
Excel Web App: 
Additions to the Excel Web App include the new ability to drag and drop cells and reorder sheets.   A quick analysis of a range of data in the status bar (including sum, count, and average of a selected range of cells) has been added.  In addition, there is support for more workbook types online. 
PowerPoint Web App:
New picture cropping functionality has been added to the PowerPoint Web App and the name of your files can now be changed not only within the editing window of the PowerPoint Web App but also across the other Office Web Apps.  
Home
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Thursday, November 07, 2013

Security Bulletin Advance Notice for November 2013

Security Bulletin
On Tuesday, November 12, 2013, Microsoft is planning to release eight (8) bulletins.  Three of the bulletins are identified as Critical with the remaining five bulletins rated Important.

The Critical updates address vulnerabilities in Internet Explorer and Microsoft Windows. The Important updates will be directed to issues in Windows and Office and most of the updates will require a restart.

Security Advisory 2896666

The issues in Security Advisory 2896666 will not be included in the scheduled updates.  Although Microsoft has only detected only aware of targeted attacks against Office 2007 on Windows XP, the following additional guidance was provided regarding the affected installations by Dustin Childs in the below-linked MSRC post:

"For Office:
  • Office 2003 and Office 2007 are affected regardless of the installed operating system. Currently, we are only aware of targeted attacks against Office 2007 users.
  • Office 2010 is affected only if installed on Windows XP or Windows Server 2003.  Office 2010 is not affected when installed on Windows Vista or newer systems.
  • Office 2013 is not affected, regardless of OS platform.
For Windows:
  • Supported versions of Windows Vista and Windows Server 2008 ship with the affected component but are not known to be under active attack.
  • Other versions of Windows are not directly impacted. Customers who use these systems are only impacted if they have an affected version of Office or Lync.
For Lync clients:
  • All supported versions of Lync client are affected but are not known to be under active attack."
Users of Windows Vista, Windows Server 2008, Lync or the above-described installations of Office are advised to enable the Fix it solution, available from my post here

Reminder

Users of Windows XP are reminded that support ends for Windows XP on April 8, 2014.  See Tim Rains article, The Risk of Running Windows XP After Support Ends April 2014.

As happens each month, Microsoft will also release an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.

References




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Tuesday, November 05, 2013

Microsoft Security Advisory 2896666 with Fix it

Security Advisory
Microsoft released Security Advisory 2896666 which relates to a vulnerability in the Microsoft Graphics component that affects Microsoft Windows Vista and Windows Server 2008, Microsoft Office 2003 through 2010, and all supported versions of Microsoft Lync.

Microsoft is aware of targeted attacks primarily in the Middle East and South Asia that attempt to exploit this vulnerability in Microsoft Office products.  

The vulnerability is a remote code execution vulnerability that exists in the way affected components handle specially crafted TIFF images.  The vulnerability is exploited either through previewing or opening a specially crafted email message or file.  It is also exploited by browsing similarly web content.  The attacker could gain the same user rights as the current user.

Recommendations

Microsoft has made available a Fix it solution which will disable the TIFF codec. Below are the links to both enable and disable the Fix it solution. 
 
Enable Fix itDisable Fix it


Another option is to install the Enhanced Mitigation Experience Toolkit (EMET), described in the "workarounds" section of the Tech Net Advisory.

References:




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...