Two Office 2010 vulnerabilities leaked, Microsoft furious
Microsoft is furious with Vupen Security after it leaked information about two security vulnerabilities in Microsoft Office 2010, even though the software package has only been out a few weeks.
Vupen has identified 130 security flaws in 2010 alone, with most of them being in Microsoft products, which means that either Microsoft software is really insecure or Vupen does not like the company all that much. TechEye's gamblers, which means all of us, are pretty divided on this one.
The technical details of the flaw were not revealed in order to ensure hackers cannot use that information to exploit the bug, but Vupen did say that the flaw is a memory corruption which affects Excel. It said it was not easy to exploit, but that it had developed a specially crafted Excel document which could achieve reliable code activation.