Showing posts with label Microsoft Office. Show all posts
Showing posts with label Microsoft Office. Show all posts

Microsoft to open its 'Apple-style' Retail Stores later this year

Microsoft will follow the the path blazed by Apple and open its first two bricks and mortar retail stores in the US later this year.

The software maker said on Tuesday it signed leases at shopping centres in Mission Viejo, California and Scottsdale, Arizona.

The Shops at Mission Viejo is already home to an Apple store. The other location, Scottsdale Fashion Square, does not have a competing Apple shop.

Microsoft maker picked those areas because they're "hot markets", with the right demographics, said Kim Stocks, a corporate communications director at the company.

She said the stores will sell laptops in addition to Microsoft and third-party software, Zunes, and Xbox 360 games and consoles.

News of the store strategy was leaked earlier this week on the Gizmodo technology news site. Gizmodo obtained a detailed Powerpoint presentation showing a fit out bearing a striking resemblance to the Apple Store look.

"Essentially, Microsoft is taking the best elements from the Apple Store, Sony Style and other "flagship" stores," Gizmodo said.

The Microsoft stores will feature a "Guru Bar" where customers can ask for technical advice. Apple Stores feature a service area known as the Genius Bar.

Apple, however, is not the only source of inspiration. The leaked Powerpoint document also says that the Microsoft stores will be available to host birthday parties - a service which has a long association with that other chain that specialises in (Big) Macs.

Sphere: Related Content

Microsoft Releases Six Security Updates

Gregg Keizer


Microsoft this week released six security bulletins that patched nine vulnerabilities in Windows, Internet Explorer (IE), Microsoft Word, Outlook Express and SharePoint. But for the second time in two months, it yanked an update at the last minute.

Four of the six updates were rated critical, Microsoft's highest threat warning, while the remaining two were judged important, the next-lowest notch in the company's four-step scoring system.

MS07-057, the critical update to IE, should be patched first, said Andrew Storms, director of security operations at nCircle Network Security. "It's an update for every version of IE, and for every supported version of Windows, so its impact is across the board," he said. Of the four vulnerabilities patched by the update, three are related to address bar spoofing, the practice of disguising the URL shown by a browser to trick users into thinking they're visiting a safe or legitimate site. Two of those three were publicly disclosed in February and July, the first by Polish researcher Michal Zalewski and Danish researcher Jakob Balle of Secunia, the second by Zalewski alone.

Although Microsoft said it had no information to indicate that any of the IE vulnerabilities, the address spoofing bugs included, had been exploited, Storms wasn't so sure. "The address bar spoofs would be perfect for the quintessential phishing campaign," he said. Exploits, he continued, would mask the URL of bogus sites with fake addresses of legitimate sites, and could trick even those users who paid attention to what's in their browser's address bar when they head to important pages, such as those where they log-in to online banking accounts.

"Nobody can keep a secret like this for eight months, so one has to assume that the bug [disclosed in February] has been in use for some time," said Storms.

For the most part, however, the updates were a yawner for Tom Cross, a researcher with IBM Internet Security Systems' X-Force. "There's nothing here that is a huge, huge concern," said Cross. "They're just not that different from the things security professionals see every day. But that's good news, isn't it?"

Microsoft also patched critical vulnerabilities in Outlook Express on Windows XP and 2000, and Windows Mail on Vista; in Microsoft Word 2000 and XP on Windows and Word 2004 on the Mac; and in all supported versions of Windows except Vista. That third critical bulletin, MS07-055, details a flaw in the Windows image viewer that parses Kodak formatted photos. The vulnerability resembles other image file bugs, such as the one in Windows Metafile that caused a ruckus in late 2005 and early 2006, but more importantly, hints that attackers are still looking for such flaws. "The new vulnerability shows that there's an active research effort," said Storms, "primarily because of the vectors. You can host the image [on a malicious site] or send it [via an e-mail attachment."

Of the two patch updates pegged as important, MS07-059 fixes an elevation of privilege flaw in SharePoint Services 3.0 and Office SharePoint Server 2007, while MS07-058 plugs yet another hole in Windows' RPC (remote procedure call) component. Exploits could crash the system and force it to reboot, said Microsoft, which led it to classify the vulnerability as a denial-of-service bug.

"There have been endless RPC issues with Windows," Storms noted. The most infamous RPC bug was the one patched in August 2003 that was quickly exploited by the Blaster worm in massive attacks that caused considerable damage to computers worldwide.

But Storms thought this week's vulnerability interesting more because of how Microsoft rated its threat than for the bug itself. "This illustrates that Microsoft has changed their rating of denial-of-service so that it's no longer considered critical," he said. "But I don't agree. Uptime is just as important as information confidentiality and integrity. If a system is unusable it means it's been compromised."

Also of interest, said Storms, was what wasn't released this week.

For the second consecutive month, Microsoft pulled an update from the list it had released just five days before. This cycle it dropped an update that was to have patched Windows 2000 SP4 and all versions of Windows Server 2003. Last week, Storms speculated that the patch targets may indicate a vulnerability in a service run only on servers. "If that is in fact the case," he said, "then the fix is probably much more complicated and the vulnerability impacts more core code. That means Microsoft would expend much more quality assurance around it, which might explain the delay."

Although Microsoft did not notify users of its decision to yank a bulletin -- something it's done in the past, either by posting on the Microsoft Security Response Center blog or by revising the advance notification alert -- Symantec knew one was going to be spiked. In an alert issued last week to customers of its DeepSight threat network, Symantec said only six updates would be released this week.

Symantec declined to say how it knew of the decision, or whether it was given prior notice by Microsoft. Cross also had no comment when asked if IBM's X-Force knew beforehand that the seventh update had been withdrawn.

In a statement attributed to Mark Miller, director of security response communications at Microsoft, and forwarded to Computerworld by the company's public relations team, Microsoft said its policy is not to revise the advance notification when minor changes are involved. "When significant changes are made to the release, Microsoft will normally notify customers through a re-release of the [advanced notification] and all accompanying communications," Miller said.

Microsoft's monthly updates are available via the Microsoft Update and Windows Update services, as well as through Windows Server Update Services (WSUS).

Sphere: Related Content

Microsoft Office For Mac To Be Released In January 2008

Microsoft said it will release three versions of its Office 2008 for Mac suite in January, with the most expensive of the bunch aimed at creative professionals overwhelmed by the task of organising their digital media files.

Office 2008 for Mac Home and Student Edition, which includes three licenses for Word, Excel, PowerPoint and Entourage, an email/calendar/contacts program, will cost $US150, Microsoft said.

A $US400 version aimed at professionals who use Apple computers, simply called Office 2008 for Mac, includes the same programs as Home and Student, plus the ability to connect to a Windows Exchange server.

A third version, the $US500 Special Media Edition, adds features to the $US400 configuration, including Expression Media, a program that helps computer users organize and manipulate digital photos, video and other files.

Microsoft sells Expression Media, one of several new tools for graphic designers and other creative professionals, for $US299.

All three versions work on Intel-based Macs and older PowerPC machines. The software maker planned to announce the lineup and pricing Tuesday at Apple Expo in Paris, France.

Apple announced in August that it added a spreadsheet program to iWork, the company's own productivity software suite. Apple sells individual licenses for $US80 and family packs, which allow users to install the programs on five different computers, for $US100.

Amanda Lefebvre, marketing manager for Microsoft's Macintosh business unit, said Microsoft's offering is "a really robust suite compared to iWork."

For Apple users who don't want to wait until next year for Office, Microsoft is offering an upgrade program. For the price of shipping, handling and taxes - an estimated $US10 in the U.S. - the company will send a comparable 2008 suite to people who buy the Standard Edition or the Student and Teacher Edition of Office 2004 for Mac through to March 14.

Sphere: Related Content

Microsoft Releases Six Security Updates

The security bulletins for July 2007 are as follows, in order of severity:

Bulletin Identifier

Microsoft Security Bulletin MS07-036

Bulletin Title

Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (936542)

Executive Summary

This critical update resolves one publicly disclosed vulnerability and two privately reported vulnerabilities in addition to other security issues identified during the course of the investigation. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Maximum Severity Rating

Critical

Impact of Vulnerability

Remote Code Execution

Detection

Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. This update does not require a restart.

Affected Software

Office, Excel. For more information, see the Affected Software and Download Locations section.

Bulletin Identifier

Microsoft Security Bulletin MS07-039

Bulletin Title

Vulnerability in Windows Active Directory Could Allow Remote Code Execution (926122)

Executive Summary

This critical security update resolves a privately reported vulnerability in implementations of Active Directory on Windows 2000 Server and Windows Server 2003 that could allow remote code execution or a denial of service condition. Attacks attempting to exploit this vulnerability would most likely result in a denial of service condition. However remote code execution could be possible. On Windows Server 2003 an attacker must have valid logon credentials to exploit this vulnerability. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts.

Maximum Severity Rating

Critical

Impact of Vulnerability

Remote Code Execution

Detection

Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update will require a restart.

Affected Software

Windows. For more information, see the Affected Software and Download Locations section.

Bulletin Identifier

Microsoft Security Bulletin MS07-040

Bulletin Title

Vulnerabilities in .NET Framework Could Allow Remote Code Execution (931212)

Executive Summary

This update resolves three privately reported vulnerabilities. Two of these vulnerabilities could allow remote code execution on client systems with .NET Framework installed, and one could allow information disclosure on Web servers running ASP.NET. In all remote code execution cases, users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Maximum Severity Rating

Critical

Impact of Vulnerability

Remote Code Execution

Detection

Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update will require a restart.

Affected Software

.NET Framework. For more information, see the Affected Software and Download Locations section.

Bulletin Identifier

Microsoft Security Bulletin MS07-037

Bulletin Title

Vulnerability in Microsoft Office Publisher Could Allow Remote Code Execution (936548)

Executive Summary

This important security update resolves one publicly disclosed vulnerability. This vulnerability could allow remote code execution if a user viewed a specially crafted Microsoft Office Publisher file. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. User interaction is required to exploit this vulnerability.

Maximum Severity Rating

Important

Impact of Vulnerability

Remote Code Execution

Detection

Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update does not require a restart.

Affected Software

Office, Publisher. For more information, see the Affected Software and Download Locations section.

Bulletin Identifier

Microsoft Security Bulletin MS07-041

Bulletin Title

Vulnerability in Microsoft Internet Information Services Could Allow Remote Code Execution (939373)

Executive Summary

This important security update resolves a privately reported vulnerability. This vulnerability could allow remote code execution if an attacker sent specially crafted URL requests to a Web page hosted by Internet Information Services (IIS) 5.1 on Windows XP Professional Service Pack 2. IIS 5.1 is not part of a default install of Windows XP Professional Service Pack 2. An attacker who successfully exploited this vulnerability could take complete control of the affected system.

Maximum Severity Rating

Important

Impact of Vulnerability

Remote Code Execution

Detection

Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update will require a restart.

Affected Software

Windows XP Professional. For more information, see the Affected Software and Download Locations section.

Bulletin Identifier

Microsoft Security Bulletin MS07-038

Bulletin Title

Vulnerability in Windows Vista Firewall Could Allow Information Disclosure (935807)

Executive Summary

This moderate security update resolves a privately reported vulnerability. This vulnerability could allow incoming unsolicited network traffic to access a network interface. An attacker could potentially gather information about the affected host.

Maximum Severity Rating

Moderate

Impact of Vulnerability

Information Disclosure

Detection

Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update will require a restart.

Affected Software

Windows Vista. For more information, see the Affected Software and Download Locations section.

More updates In August 2007

Sphere: Related Content