Windows Vista new security threat

Windows_Dec17_BMicrosoft develops many of the business world’s most popular software. From operating systems to document production, the company offers numerous versions of popular software. This often leads to security issues with one version or another, and in early November the company announced that they had found a threat affecting Vista, Lync and older versions of Office.

The early November security advisory noted that hackers are actively attacking machines using Windows Vista and Lync, as well as Office 2003-2010 users. If attacks are successful, hackers gain the same access privileges as the user and are essentially able to control your system.

According to the blog post on Microsoft, “The exploit requires user interaction as the attack is disguised as an email requesting potential targets to open a specially crafted Word attachment. If the attachment is opened or previewed, it attempts to exploit the vulnerability using a malformed graphics image embedded in the document. An attacker who successfully exploited the vulnerability could gain the same user rights as the logged on user.”

What this means, is the hacker is sending emails to users with a Microsoft Word document attached. This document contains an image that is broken and by exploiting the bit of code that displays the image, the hacker can gain access to your system.

As stated above, this exploit will only work on systems with Windows Vista, Microsoft Office 2003-2010 and Windows Server 2008, and Lync. If you don’t use the specific versions of these, programs your systems are secure from this particular threat. The other good news about this particular vulnerability is that attacks are mostly limited to the Middle East and South East Asia. That being said, it is only a matter of time before businesses in Europe, Australia and North America are targeted.

Is there anything I can do to protect my business?

Microsoft has released a security update for this fix, and users who have automatic updates enabled on Windows Vista should be secure from it. If you haven’t updated your easiest option is to:

  1. Click Start followed by Control Panel.
  2. Select Security.
  3. Click on Check for updates and follow the prompts.

While this will work to keep your individual systems secure, you may need to update your servers and other software. Your best bet would be to contact your IT partner to see how they can help ensure an update is installed correctly.

It is also be a good idea to put some preventative measures in place.

  • Implement a firewall - Firewalls are a security measure that allow users to set rules about what type of data is allowed to enter or exit a network. This helps ensure that networks are secure and not transmitting potentially harmful data.
  • Email scanning - Many security solutions also offer email scanning. How these services work is they scan emails for either spammy content or attachments that could pose a security threat e.g., broken images, such as in the recent Microsoft exploit.
  • Keeping all systems and programs up-to-date - The best way to prevent security breaches or problems is to keep your systems and all of your programs, even the ones you don’t use, up-to-date. This is because hackers usually go after easy targets, with the easiest being systems that aren’t updated.
  • Watch your attachments - Because this exploit has to be physically introduced into your systems by a user downloading and opening the document, and it is usually attached in an email, you should tell your employees to ensure that they look at the attachments in emails and to not open them if they look suspicious.
  • Update to newer software versions - Windows 7 and 8, Office, and Server 2012 are newer systems, and for the most part remain more secure than their older counterparts. Not to mention the fact that many software developers, security included, mainly focus on the newer versions of Windows. Therefore, it may prove worthwhile updating to newer systems.

If you are looking to learn more about this security problem, how to secure your business or to upgrade to a newer version of Windows, please contact us today to see how we can help.

Computer contact management

MobileGeneral_Dec17_BAs a business owner, you probably rely on a smartphone as your main form of connection with the office. It may even be your main communication device. If you use a smartphone, you likely have a large number of contacts, and if you have ever tried to manage these on your phone then you know it’s not so easy. One useful option is to edit these contacts directly from your computer.


VoIP - 5 reasons to switch

VoIP_Dec09_BTechnology of any kind has become an important business component. While many companies are upgrading servers, virtualizing environments and even implementing the cloud, there is one function often ignored: The telephone and phone lines. One option to modernize older phone systems is to upgrade to Voice over Internet Protocol (VoIP).


Get the most out of LinkedIn

SocialMedia_Dec17_BSocial media brings many different benefits to business users, and one of the most useful is that they provide businesses with a way to connect with their customers on a deeper level. It’s true that Facebook is the most popular network, but LinkedIn is also a valuable platform that can really help users connect with other like-minded people and related businesses.


4 common password policy problems

Security_Dec09_BThe security of your systems and business in general is likely something that you are concerned, if not worried, about. While it is true that many businesses have security systems in place, the weakest link is often the password. In an effort to ensure that passwords remain secure, many companies adopt password policies. But are these policies really effective?