An "extremely critical flaw" in Microsoft Word 2000 is currently being exploited by malicious attackers, which could lead to remote execution of code on a user's system, security researcher Secunia advised Tuesday.
The vulnerability affects systems running Windows 2000 and occurs when processing malicious Word 2000 documents, according to Secunia's security advisory.
Security company Symantec, which several days ago detected the exploit, Trojan MDropper.Q, noted that it uses a two-step attack.
"As with other recent (Microsoft) Office vulnerabilities, documents incorporating the exploit code must be opened with a vulnerable copy of Microsoft Word 2000 for it to work," Symantec's advisory stated. "As such, it makes the vulnerability unsuitable for the creation of self-replicating network worms."
Microsoft has not yet issued a patch for the vulnerability, and users are advised to forgo opening untrusted documents.
This latest exploit of an Office vulnerability follows on the heels of a similar malicious attack in June. In that particular case, users' systems would become infected when opening a malicious Excel document called "okN.xls." That malicious file contained the Trojan horse Mdropper.J, which then dropped the Booli.A program on a user's system. Booli.A would then download more malicious files to the user's PC.
I do. At home. I have three legal copies on three machines at home. Why should I pay my own money for something newer? Please don't tell me because of this exploit vector; newer versions suffer their own vulnerabilities.
Just because there are newer versions of Microsoft Office does not mean that all companies and individuals have upgraded or even plan to. Most people do not need newer versions as Office 2000 runs well enough and has more features than most people will ever touch.
a.) You have to be running Word2k on a Win2k box b.) You have to open a "malicious" word document c.) It is not really a virus, but a backdoor allowing (probably) remote access to your PC
I don't know about you guys, but I don't make it a habit of opening random word documents off the internet that reek of malicious intent. But hey, if you DO decide to open that "10 ways to increase your potency in bed" document off of limewire, or that atachment in your e-mail inbox from LonleyWife, or HotMilf, then you deserve to have your computer infected.
I know this doesn't excuse the fact that there is a security flaw, but software development is an imperfect art. Anybody who thinks otherwise has never, ever coded a single line of code and compiled it.
If you code a simple "Hello World" you have coded at least one line. Unless the compiler has a security problem, but it's hard to code that imperfectly.
Of course much larger programs are difficult to code perfectly, but small programs can be very close to perfect if not perfect. Because of this, I prefer smaller, specialized software with fewer features in many cases.
By clicking on a link in internet explorer that links to a .doc file (rather than html), word will automatically be loaded by IE to view the document. The same happens when you click on a link to a .pdf and accrobat reader pops up. The link doesn't have to visually show the type of document you are linking to, either. For instance, the "Terms of use." link you see when entering a post links to
I post this with a big ol' smile on my face. Not because of a Microsoft exploit or because I wan't people to switch to OpenOffice or WordPerfect. The smile is because anybody who believes the need a full blown office suite or even a powerful document editor is probably just smoking something they shouldn't be.
Sure there is a need for some to use more powerful document editors, but most people don't need it. We use WordPerfect in my office, but the truth is for most of them here Wordpad would be fine. We would probably use Word, but WordPerfect works great, does all we need, and cost less than Microsoft Office. We could use OpenOffice, but we don't.
If you own Word or WordPerfect and all you do is type then you wasted your money. Next time download OpenOffice or just use wordpad.
As far a security goes I just say keep or AV upto date and your firewall active. All software has flaws, even open source ones.
This is one of the biggest mysteries of this current personal computer age. Everybody's GOTTA have Word/Office, and 99% of them use it for typing and maybe the simplest of spreadsheets. Just like they've GOTTA have the latest Intel processor and 2 gigs of RAM, running Windows. Which they use for email, web browsing, and typing. Dare to challenge their baseless assumptions about their "needs" and they'll look at you like you've lost your mind
Why would anyone made a "word processor" that can "execute code"?
This is the problem. If it was a word processor, there would be no way to execute code on it. But, since the company that put it out (we all know who that is) decides in their wisdom that their word processor should actually be some kind of high level programming language (in addition to a word processor), we get problems like this. Other companies have jumped on the bandwagon too, and now you have a hard time finding a simple ordinary word processing program. Even if you did, it wouldn't be able to open the letter you just got from your mom because she used one of the bloated popular programs. This is why the software in question will never be installed on my computer. How in the world can anyone, and I mean ANYONE, justify a WORDPROCESSOR being a security risk? This is one of the MANY reasons why I have to HOLD MY NOSE while I'm using my PC.
I'm really hoping, before I die, to see Linux with some kind of directx emulator or something. If that happened, I'd drop MS and NEVER BUY ANOTHER ONE OF THEIR PRODUCTS EVER.
Tell me a single mainstream word processor that doesn't support macros. Responding to your request I can tell you a hundred reasons why a word processor might become a security risk. Users want macros. Many NEED macros. Macros require coding. If a Word Processor allows for macros but does not SPECIFICALLY TAKE STEPS TO PREVENT MACROS THAT MIGHT DO SOMETHING EVIL (and now you try to define "doing something evil" in a computer understandable way and you win a Nobel prize) then it is a vulnerability. Happy? I thought not.
In the computing security word it is accepted that a "Critical" flaw is one that allows for automated propagation of a threat. There's no accepted definition for "Extremely Critical" but it would definitely be something more critical than "Critical". This vulnerability doesn't allow for that. In most vulnerability assessment schemes it would only rank as "Important" or something on that order. But definitely not "Extremely Critical". Now tell me why a not critical vulnerability for an extremely old version (Word XP and Word 2003 are quite major releases for Word, and Word 2007 is due in a few months) of a Word Processor is front page news...
Show me one program on the internet that has been out for 7 years, and doesnt have some kind of crack, hack, or has been comprimised in some way by the internet public, and ill show you a good company to invest in.
If you have use the affected office software, have it patched right away and get on with your life. Don't swallow the hype here at cnet where every little security flaw or exploit is celebrated like the end of the world. It's not.
How many different people in different threads have to say to you "YOU DON'T HAVE A CLUE"
* Read a bit (not only on M$ fansites) * Talk to normal people (end users) about their problems to learn their needs * Talk to people from small companies to learn their needs * Talk to people from internationals to learn their needs * Learn C/C++ and see what it can do with little resources and compare it with the same in .NET or VB * Test a lot (Try for instance a good linux distro, perhaps Gentoo? Or Borrow an old MAC (8 years old and still running, or something like that))
Combine the things you learned with an open mind, and then come back with a funded reply. I saw your name in countless ridiculous comments in the last weeks. I just can tell you 1 thing: you know jack **** about PC's
We still use Office 2000. It has all the features we need. Several of our machines have Office XP, because they shipped with it installed, but there are no compelling reasons for us to upgrade all of our machines to it. MS has extended support for Office 2000 until 2009.
Truth is that the word .doc format is pretty much an unwritten (or a formal) standard. If you want anyone to be able to read your document, then it has to be a .doc. you could write it as a .pdf feature, if you had that capability (I have it on my mac, but I dont know about PC users who dont use MS Office). Thats pretty universal too. If all office suites could gurantee formatting on all machines with all word processors, then Word would loose its monopoly. Its true that most of the features are irrelevent to most of the users and many are getting fed up of paying for bells and whistles that they neither want nor need. Not to mention the fact that the application grows every time an upgrade is done. I have Neo Office and MS Office. I try to use Neo Office whenever possible, but sometimes, I need to have gurantees about formatting so I use MS Office. With the rise of the open document format, I think that my copy of MS Office will be retiring and I will be freeing up a large chunk of disk space!
XML itself has no app-level semantics, unlike HTML. The only way you could accuse Word of using non-standard XML is if it couldn't be structurally parsed by an XML parser, which is not the case.
Just more old cut and paste "news" from the <a class="jive-link-external" href="http://www.teckmagazine.com/content/view/631/43/" target="_newWindow">http://www.teckmagazine.com/content/view/631/43/</a> "editors" at CNUT.
The Samsung Galaxy Mini 2 S6500 could make its debut at the Mobile World Congress in Barcelona later this month, according to a leaked promotional image.
The space agency powered down its last System z machine, years after IBM stopped selling them for the mathematical calculation jobs NASA originally bought them for.
You definately need a real job.
Only the South end of a North bound Jackass would
make such a comment.
mark d.
a.) You have to be running Word2k on a Win2k box
b.) You have to open a "malicious" word document
c.) It is not really a virus, but a backdoor allowing (probably) remote access to your PC
I don't know about you guys, but I don't make it a habit of opening random word documents off the internet that reek of malicious intent. But hey, if you DO decide to open that "10 ways to increase your potency in bed" document off of limewire, or that atachment in your e-mail inbox from LonleyWife, or HotMilf, then you deserve to have your computer infected.
I know this doesn't excuse the fact that there is a security flaw, but software development is an imperfect art. Anybody who thinks otherwise has never, ever coded a single line of code and compiled it.
Of course much larger programs are difficult to code perfectly, but small programs can be very close to perfect if not perfect. Because of this, I prefer smaller, specialized software with fewer features in many cases.
<a class="jive-link-external" href="http://www.cnet.com/aboutcnet/editorial/terms.html" target="_newWindow">http://www.cnet.com/aboutcnet/editorial/terms.html</a>
See? It's not all that hard.
Sure there is a need for some to use more powerful document editors, but most people don't need it. We use WordPerfect in my office, but the truth is for most of them here Wordpad would be fine. We would probably use Word, but WordPerfect works great, does all we need, and cost less than Microsoft Office. We could use OpenOffice, but we don't.
If you own Word or WordPerfect and all you do is type then you wasted your money. Next time download OpenOffice or just use wordpad.
As far a security goes I just say keep or AV upto date and your firewall active. All software has flaws, even open source ones.
This is the problem. If it was a word processor, there would be no way to execute code on it. But, since the company that put it out (we all know who that is) decides in their wisdom that their word processor should actually be some kind of high level programming language (in addition to a word processor), we get problems like this. Other companies have jumped on the bandwagon too, and now you have a hard time finding a simple ordinary word processing program. Even if you did, it wouldn't be able to open the letter you just got from your mom because she used one of the bloated popular programs.
This is why the software in question will never be installed on my computer. How in the world can anyone, and I mean ANYONE, justify a WORDPROCESSOR being a security risk?
This is one of the MANY reasons why I have to HOLD MY NOSE while I'm using my PC.
I'm really hoping, before I die, to see Linux with some kind of directx emulator or something. If that happened, I'd drop MS and NEVER BUY ANOTHER ONE OF THEIR PRODUCTS EVER.
Fat Chance.
Responding to your request I can tell you a hundred reasons why a word processor might become a security risk. Users want macros. Many NEED macros. Macros require coding. If a Word Processor allows for macros but does not SPECIFICALLY TAKE STEPS TO PREVENT MACROS THAT MIGHT DO SOMETHING EVIL (and now you try to define "doing something evil" in a computer understandable way and you win a Nobel prize) then it is a vulnerability.
Happy?
I thought not.
(what i'm getting at is you can't.)
thanks
* Read a bit (not only on M$ fansites)
* Talk to normal people (end users) about their problems to learn their needs
* Talk to people from small companies to learn their needs
* Talk to people from internationals to learn their needs
* Learn C/C++ and see what it can do with little resources and compare it with the same in .NET or VB
* Test a lot (Try for instance a good linux distro, perhaps Gentoo? Or Borrow an old MAC (8 years old and still running, or something like that))
Combine the things you learned with an open mind, and then come back with a funded reply. I saw your name in countless ridiculous comments in the last weeks. I just can tell you 1 thing: you know jack **** about PC's
(or a formal) standard. If you want anyone to be able to read
your document, then it has to be a .doc.
you could write it as a .pdf feature, if you had that capability (I
have it on my mac, but I dont know about PC users who dont
use MS Office). Thats pretty universal too.
If all office suites could gurantee formatting on all machines with
all word processors, then Word would loose its monopoly. Its
true that most of the features are irrelevent to most of the users
and many are getting fed up of paying for bells and whistles that
they neither want nor need. Not to mention the fact that the
application grows every time an upgrade is done.
I have Neo Office and MS Office. I try to use Neo Office whenever
possible, but sometimes, I need to have gurantees about
formatting so I use MS Office. With the rise of the open
document format, I think that my copy of MS Office will be
retiring and I will be freeing up a large chunk of disk space!
<firstname>: Microsoft
<lastname>: Word
On this website -->
<a class="jive-link-external" href="http://www.whotohate.com" target="_newWindow">http://www.whotohate.com</a>
<a class="jive-link-external" href="http://www.teckmagazine.com/content/view/631/43/" target="_newWindow">http://www.teckmagazine.com/content/view/631/43/</a>
"editors" at CNUT.