Showing posts with label Microsoft Office. Show all posts
Showing posts with label Microsoft Office. Show all posts

Thursday, February 25, 2010

Microsoft's Global Criminal Compliance Handbook

Business Insider via Gizmodo reports links to a Microsoft document describing Microsoft's contact details and processes for being served legal documents. The document sets expectations for response, enumerates the online services described, and what data the users provide to the services. An example is their XBox Live service which records Gamertag, credit card number, phone number, first and last name with zip, the serial number of devices registered online, service request numbers, email account, and the IP history for the lifetime of the gamertag.

Yes, according to this document, XBox Live tracks every IP your gamertag has logged in from. Ever. That might surprise some XBox players, but shouldn't really surprise most security analysts.

The document fully describes the information retained about each service's users, their activities, and their content. Along with these, Microsoft offers sample language describing a records request, such as this: "Any and all website information for the [group requested] including content, images, member lists, and all IIS logs" for MSN Groups.

Finally, the document describes the legal process required to acquire this information.

This is an interesting read - take a look for yourself:
Microsoft Spy

Friday, April 3, 2009

Death By Powerpoint: Microsoft Security Advisory 969136

We've all heard the joke about corporate meetings - "Death by PowerPoint". Microsoft's most recent security advisory however should make system administrators running older versions of PowerPoint 2000, 2002, 2003, and Office 2004 for MacOS sit up and take notice. Per the advisory, "Microsoft is investigating new reports of a vulnerability in Microsoft Office PowerPoint that could allow remote code execution if a user opens a specially crafted PowerPoint file.".

The good news is that newer versions of Office are not vulnerable, and that as usual, this only executes with the rights of the local user, and it requires users to open the PowerPoint file.

This is referenced as CVE-2009-0556, for those who would like to track it.