- Related Stories
-
Microsoft leaves Word zero-day holes unpatched
January 9, 2007 -
Attack code published for third Word flaw
December 14, 2006 -
No fix yet for zero-day flaw in Word
December 7, 2006 -
Word hole exploited in zero-day attacks
December 5, 2006 -
The future of malware: Trojan horses
October 13, 2006
Another previously undocumented, yet-to-be-patched security vulnerability in Microsoft Word is actively being exploited in cyberattacks, Microsoft said Thursday.
The vulnerability is the fourth zero-day vulnerability to arise in the Microsoft application in two months. Microsoft hasn't provided patches for any of the flaws, despite acknowledging that the holes are being used in attacks on its customers.
"There have been very limited attacks reported that are attempting to use the reported vulnerability at this time," a Microsoft representative said Thursday in a statement about the latest problem. The company is investigating this latest report and may issue a patch, if needed, the representative said.
The newest problem allows an attacker to hijack systems running Word 2000 and causes a crash of Word 2003 and Word XP, Symantec said in an alert Thursday. "An attacker could exploit this issue by enticing a victim to open a malicious Word file," the Cupertino, Calif.-based security company said.
Security experts have said the limited-scale attacks are the most dangerous. Widespread worms, viruses or Trojan horses sent to millions of mailboxes are typically not a grave concern because they can be blocked. Instead, especially for businesses, targeted Trojan horses have become nightmares, as they can fly under the radar.
Symantec advises people to make sure their security software is up-to-date and urges caution when opening Word documents. Businesses should put policies in place to prevent Word documents from being distributed to users, Symantec said.
See more CNET content tagged:
Microsoft Word, cyberattack, attack, Symantec Corp., vulnerability




You've got to be kidding me? Most businesses would have to shut down if they couldn't send word documents within the organization. How about a useful recommendation, like finding another word processing program, or perhaps making the same noise you do about major worms in the press and getting Microsoft to release something faster to avoid a negligence lawsuit.
http://sourceforge.net/project/showfiles.php?group_id=169337
Word's Doc files been biting people in the backside for years. If they aren't carrying a malicious payload, they are blabbing your secrets.
http://news.bbc.co.uk/2/hi/technology/3154479.stmbbing secrets.
You can put them for instance on a known/trusted file share and send the link, or better put them into a known/trusted SharePoint or web server the whole team is using, or check them in into your source control/content management database, etc.
Or if you really need to send content by mail you can simply send mail in RTF format and copy/paste from the Word/Excel doc into your message.
Someone must be insane to insist opening attached documents received in email (no matter of their formats) after all the viruses and worms that circulated in the last years...
- Stop using Microsoft will fix the problem
- by wbenton January 27, 2007 6:20 AM PST
- Critical flaws are to be patched within 24 hours.
- Like this Reply to this comment
-
(7 Comments)Non-critical flaws are to be patched within 72 hours.
Microsoft has been aware of at least 3 zero-day flaw more than a week prior to their January Security Updates... and that was 2 weeks ago.
Shows how concerned Microsoft is about the security of their users!
Bottom Line: Swap to Linux and resolve the slow patching track-record of Microsoft.
Walt