Microsoft accuses security companies of aiding hackers
Microsoft has slammed security researchers for publishing exploit code for a hole in MSN Messenger.
In a statement, the software giant singled out Finjan Software and Core Security Technologies for publishing code to test for vulnerabilities shortly after software patches were released to plug the holes. It claimed the tests were then used to develop working attacks. The statement then cited an increased risk to Messenger and Office XP users.
Finjan released code to test for a hole its researchers discovered in Microsoft Office XP, and that Microsoft fixed with a patch described in Security Bulletin MS05-005. Finjan discovered and then publicised code to test for the vulnerability on the same day Microsoft released its bulletin, Microsoft said.
The buffer overflow in question affects a process that passes Web URLinformation to Office XP applications and could be used by malicious hackers to hide attacks in HTML links embedded in e-mails or Web pages.