NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Windows

Windows


Highly Critical Microsoft Word Zero-Day

Actively exploited in the wild

By Marius Oiaga, Technology News Editor

26th of January 2007, 11:08 GMT

Adjust text size:


Hot on the heels of three recent Microsoft Office Word vulnerabilities that are still unpatched from December 2006, comes another zero-day Word Unspecified Code Execution
vulnerability. At the time of this article, there was no response from Microsoft on any of the official channels in relation to the new zero-day.

"The vulnerability is caused due to an unspecified error when parsing Word documents and can be exploited to execute arbitrary code on the user's system," reveals Secunia, additionally informing that the vulnerability is being actively exploited.

Secunia has also attributed an Extremely Critical security risk to the Word Unspecified Code Execution vulnerability. The zero-day has been confirmed to impact Word 2000, but other versions of Word may also be affected. The Trojan.Mdropper.W Trojan horse has already been correlated with the exploits of the new Word zero-day.

"We've seen many threats using vulnerabilities based on Microsoft Office documents over the last year, so it's no surprise that we have recently observed new samples of a threat that follows the same theme. This threat named Trojan.Mdropper.W is using the new Microsoft Word 2000 Unspecified Code Execution Vulnerability to drop threats onto a compromised computer," explained Hon Lau / Sr. Security Response Engineer at Symantec.

Potential victims can get infected via social engineering. Users must open an infected Word document in order to compromise their system. "When the infected Word document is opened, it uses an exploit to drop some files onto the computer. These files are back door Trojans that enable an attacker to gain remote access to your computer," added Hon Lau.
Read by 1,261 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.2/5) 7 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


The Third Exploit for Microsoft Word Vulnerability

Details on Three Unpatched MS Word Vulnerabilities

Second Word Zero-Day Vulnerability in a Week

The Coordinates of an MS Word Attack

133 Critical and Important Microsoft Vulnerabilities

Microsoft Debuts the 2007 Patching Season

Trojans Spread Via Zero-Day Word Vulnerability

Internet Explorer Sinks Under 80%

Merry Vista Vulnerability!

Seven December 2006 Security Bulletins

Remove the Search Box from Internet Explorer 7

Disable Tabbed Browsing in Internet Explorer 7

Firefox 2.0 Continues to Grow in the Detriment of IE7

God Save Internet Explorer

The First Windows Vista Vulnerability

The Limitations of Extended Validation SSL Certificates

4 January Microsoft Security Bulletins Discontinued

Windows Vista Is Plagued with Vulnerabilities

Windows Vista Anytime Upgrade

284 Days - The Attack Window of IE in 2006

Internet Explorer 8.0

Internet Explorer 7 Makes It without a Scratch into 2007

Microsoft Warns of Zero-Day Attacks

8 Microsoft Security Bulletins in January

Vista Is "Best Of CES"

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM