Contains vulnerability 30150

Joined
Aug 25, 2008
Messages
34
Reaction score
0
Vulnerable Applications........Please Help!!

Hi all,

I recently had Windows XP reinstalled on my PC due to a problem I had, and also had MS Office 2007 installed again.

When I did a system Scan with Kaspersky Internet Security 2009 it made detections which included the following message:

file: c:\...\microsoftoffice\office12\mspub.exe:contains vulnerability 30150

Similar detections were made for Word and Excel with different codes.

I wasn't sure what to do and wanted confirmation, and therefore in System Security Section for Kaspersky, I ran Security Analyzer which also detects vulnerable applications and again the following were highlighted: Word, Excel and Publisher.

They were all marked as very dangerous for "Criticality".

It also gave the following "solution" links for each application:


Word http://www.viruslist.com/en/advisories/30143


Excel http://www.viruslist.com/en/advisories/31454


Publisher http://www.viruslist.com/en/advisories/30150

On the same PC when I had Windows XP and Microsoft Office 2007 previously before reinstallation, Kaspersky never detected this, and my mate who I bought the PC from has assured me that everything was reinstalled safely and is free of viruses.


I'm not sure what this all means or what to do!

Can someone please explain all this to me in simple terms and what I should do??


Thank you!

Kind regards,

Jay
 
It looks like you need to patch your Office installation to the latest version - it's not a virus but a vulnerability which could be exploited.

Depending on which version of office you have, download and run the patch files suggested in the solution section on the page you linked to:


It's quite normal for things like this to be discovered every so often - it happens all the time with Adobe Flash, PDF files and other popular applications (especially IE and Firefox). :)

Your previous installation might not have this flagged as the problem might not have been discovered then, or it was patched automatically via Microsoft Update.
 
Go to "Windows Update Site" and signup for Office updates. :thumb:

Or

Go download This program and check ALL your installed programs, you may be in for a shock. ;)


:user:
 
Thank you for your advice guys.

I installed the updates for Publisher and Excel and Kaspersky no longer identifies vulnerabilites for them.:)


However, for Word 2007, I installed this update:

http://www.microsoft.com/downloads/details.aspx?FamilyId=071ceaa2-12e3-4401-9331-2a54a93e2550

yet Kaspersky still identifies it as vulnerable and marks it as very dangerous!


1) Any ideas what I should do?

2) Should it be a cause for concern or do you think I should just leave it?


Thank you!

Jay
 
Thank you muckshifter.

For reference, here is the response I got from Kaspersky on the matter after I contacted them directly:


Hello,

Essentially the vulnerabilities that you are seeing are not a direct threat to your machine. They are legitimate programs such as Java run time, Microsoft office etc. They have been flagged up as vulnerabilities as your system could be made more secure by updating these Applications. However this is not entirely necessary.

The wording "very/highly" dangerous is slightly over the top and is something we are working to rephrase. I would only be concerned if you have an item highlighted with a red exclamation mark noting "Trojan."

To remove the vulnerabilities please right click the object and "add to exclusions"

Please contact me if you have any further queries.

Best regards,

Kaspersky Lab Support Team
 
Back
Top