• On CHOW: Sexy vampire party
December 10, 2008 3:27 PM PST

Microsoft looking into WordPad zero-day flaw

by Robert Vamosi

Microsoft is investigating reports of a flaw in the WordPad Text Converter for Word 97 files, the company said on Tuesday. A Microsoft blog stated "we are aware of very limited and targeted attacks seeking to exploit this vulnerability."

On Wednesday security researchers reported finding a zero-day flaw affecting Microsoft Internet Explorer 7.

According to Microsoft Security Advisory 960906, the flaw only affects users of Windows 2000 Service Pack 4, Windows XP Service Pack 2, Windows Server 2003 Service Pack 1, and Windows Server 2003 Service Pack 2. This issue does not affect Windows XP Service Pack 3, Windows Vista, and Windows Server 2008.

When Microsoft Office Word is installed, Word 97 documents are set by default to open using Microsoft Office Word. Microsoft said Word is not affected by this vulnerability. However, an attacker could rename any malicious file to have a Windows Write (.wri) extension; the malicious file could invoke WordPad. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user.

The flaw cannot be exploited automatically through e-mail, however. For an attack to be successful, a user must open an e-mail attachment. Microsoft notes that the .wri file type can be blocked at the Internet perimeter.

Microsoft issued its standard disclaimer stating it is investigating the issue and would act upon completion of that investigation. Among the solutions, Microsoft could issue a service pack, include a bulletin in its next monthly security update, or issue an out-of-cycle security update depending on the severity of the issue.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
advertisement
Click here!
Recent posts from Security
Microsoft to fix holes in Windows, Office
Google privacy controls: Most people won't care
Zero-day flaw found in Web encryption
Mac Game: Art project or malware?
Corporate bank accounts targeted in online fraud
Hacker breaks into jailbroken iPhones, asks for $7
Malwarebytes accuses rival of software theft
Security firm M86 acquires Finjan
Add a Comment (Log in or register) (11 Comments)
  • prev
  • 1
  • next
by Mr. Dee December 10, 2008 5:12 PM PST
I am using Windows 7, so I am more than safe. :)
Reply to this comment
by Dalkorian December 11, 2008 3:41 PM PST
lol
by Hep Cat December 10, 2008 6:17 PM PST
It's funny - I could have sworn I read an article on C|Net yesterday that said this sort of thing isn't Microsoft's fault.
Reply to this comment
by Vegaman_Dan December 10, 2008 6:18 PM PST
*.wri files? Wow, that's pretty obsolete. I wasn't aware anyone even used those. The world works with TXT and DOC files. WRI?

Might want to try to go for something a little more mainstream.
Reply to this comment
by timber2005 December 11, 2008 8:52 AM PST
But they couldn't explot those ;)
by December 11, 2008 3:41 AM PST
Microsoft engineers are hard at work as I type working on a text virus. It is about the only file type left they haven't created one for.
Reply to this comment
by ncaissie December 11, 2008 4:49 AM PST
Your an idiot
by jinx101a December 11, 2008 7:05 AM PST
I second ncaissie's thoughts.
by timber2005 December 11, 2008 8:53 AM PST
And while Microsoft is doing that, we are attemptnig to educate our youth so they don't end up as pitiful as you.

Microsoft engineers developing a virus... they have better things to do.
by patch991 December 11, 2008 8:48 AM PST
Here, here!!
Reply to this comment
by timber2005 December 11, 2008 8:58 AM PST
The solution to me seems simple.
If they are using Win2000, Sever 2003 (any SP), Microsoft needs to put out an extra security update to patch the flaw.
If they are using XP (SP0-SP2), tell them to upgrade to SP3. It's been out a year, time to move up.
Though taking the bits out of SP3 and making them a patch for this wouldn't be hard, it just seems redundant when someone does upgrade to SP3. Its supposed to be a rollup of patches and other fixes, not a bunch of fixes cut up for users who can't commit to the full package. (It does help companies though).
Reply to this comment
(11 Comments)
  • prev
  • 1
  • next
advertisement

FAQ: Buying the right Windows 7 upgrade

Readers still have lots of questions on just which version of the software they need to buy in order to upgrade their PC. CNET News tries to offer some answers.

N.Y. lawsuit details Intel's 'largesse' toward Dell

Attorney General Andrew Cuomo's federal antitrust case filed Wednesday alleges a longstanding symbiotic relationship between Intel and Dell.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right