NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft

Microsoft


Insight on the Latest Microsoft Office Zero-Day Vulnerability

It appears to be exploiting a bug on MSO.DLL, a shared library used by Office applications

By Marius Oiaga, Technology News Editor

8th of February 2007, 09:20 GMT

Adjust text size:


Symantec has dissected the fifth unpatched zero-day vulnerability from Microsoft. The Redmond Company has acknowledged the existence of a flaw in Office that could allow remote code execution
in the eventuality of a successful exploit. But Microsoft's details were scarce to say the least, apart from pointing out that Microsoft Office 2000, Microsoft Office XP, Microsoft Office 2003, and Microsoft Office 2004 for Mac were all affected by the vulnerability.

"Security Response has analysed a sample of a malicious Microsoft Excel file that appears to be exploiting the vulnerability that is hinted at in that Advisory. Fully patched versions of Office 2000, XP, and 2003 appear to be vulnerable to this exploit," revealed Amado Hidalgo, Symantec Sr. Security Response Manager.

The vulnerability was initially associated with malformed Microsoft Excel documents. Symantec revealed that compromised files, upon execution, drop a back door Trojan onto the computer. The Cupertino based security company informed that it detects the malicious Microsoft Excel documents as the Trojan.Mdropper.Y. After infecting the computer, the back door Trojan, (detected as Backdoor.Bias) tries to contact a server in order to felicitate remote access to the victim's machine.

"It appears to be exploiting a bug on MSO.DLL, a shared library used by Office applications, so as Microsoft indicated in the advisory, it could affect other Office applications. However, to date, we have only seen it execute on Excel. As this vulnerability has not been patched yet, you should be extra careful and refrain from opening Office files received from untrusted sources," added Hidalgo.

Read by 845 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.6/5) 6 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2010 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Microsoft Confirms Fifth Office Zero-Day Vulnerability

It's Raining Word Vulnerabilities

Microsoft Debuts the 2007 Patching Season

Vista Is "Best Of CES"

Mac BU's General Manager Talks About XML Converters

Microsoft Vulnerabilities in the Front Row at Super Bowl

Highly Critical Microsoft Word Zero-Day

Microsoft Confirms Word 2000 Zero-Day

Insight on the Office 2008 for Mac

Bill Gates: Open the Door to a New World of Connected Experiences

Look for Vista Vulnerabilities and Thou Shall Find Them

Download January 2007 Security Releases ISO Image

Simplify Windows Vista and Office Deployments

Fingerprint Windows Vista

Windows Vista Is Unaffected by the VML Vulnerability

Microsoft Is Testing a Subscription-Based Payment System for Office 2003

Early Deployments of Vista and Office = High Risk

Top Security Companies Align to Support Windows Vista

Microsoft Unveils Office 2008 for Mac

The 12 to Guard Vista

Microsoft Responds to Symantec Claims of the Fifth Word Zero-Day

Microsoft Phonetically Corrects Excel Patch

Microsoft Is Already Running Internet Explorer 8.0

Gear Up for Office 2007

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM