Commentary

Dave Methvin
 

Office 2003 File Formats Go Away, Then Come Back

Not too long after Microsoft released Office 2003 Service Pack 3, users started reporting a disturbing message when opening older documents. Or rather, when trying to open older documents.

Not too long after Microsoft released Office 2003 Service Pack 3, users started reporting a disturbing message when opening older documents. Or rather, when trying to open older documents.Due to a security improvement in Office 2003 SP3, those older documents could not be opened. To re-enable them, you must add new entries to the registry saying that you really, really do want to use them. On Friday, Microsoft fessed up about the mess they had made, and provided a few workarounds.

Microsoft is in a tough situation here. Many of these document converters were written more than a decade ago, before the Internet made it easy to spread infected files. It would be a massive effort to review all of them to eliminate security problems. Security experts call removing these converters reducing attack surfaces and it's been done with many other Microsoft products in this decade. For example, Windows 2000 Server used to enable the Web and FTP services by default, but Windows 2003 disables them unless you specifically ask for them.


More Windows Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

If you need an example of the worst-case scenario, think back to the Windows Metafile security problem that happened two years ago. Browsers, mail clients, and all sorts of other applications became vulnerable to an attack merely by processing a ".WMF" file using the standard Windows API. Although Microsoft moved quickly to patch the hole, there was a dicey two-week period when several exploits began to circulate.

Viewed in that light, every creaky old document converter shipped with Office is a juicy attack surface just waiting for a hacker to exploit. For that reason alone, companies shouldn't want to have these converters active on every user's system. The problem is that removing them is destroying functionality. Nobody expected a service pack to remove the ability to process these file formats without some high-profile advance notice. Customers deserved to get advance warning on this, and be offered some reasonable alternatives. Microsoft fell down on that job.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links