NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Microsoft Confirms Word 2000 Zero-Day

Exploits are limited

By Marius Oiaga, Technology News Editor

27th of January 2007, 09:04 GMT

Adjust text size:


Microsoft is right on track to collecting a fist full of unpatched Word vulnerabilities. The Redmond Company has confirmed yesterday the existence of another Office Word zero-day vulnerability that
comes on top of three existing flaws in the company's text editing product that are still to be patched.

Secunia has labeled the Word 2000 zero-day as highly critical, and has warned that the vulnerability is being actively exploited. Symantec has identified a backdoor Trojan that is involved with the exploits of the Word 2000 zero day. Trojan.Mdropper.W is using the Microsoft Word 2000 Unspecified Code Execution Vulnerability in order to infect systems via malformed Word 2000 files.

"We are currently investigating a report of a posting of proof of concept code which could allow an attacker to execute code on a user's machine in their security context by convincing them to open a specially-crafted Word document. We are aware of very limited, targeted attacks attempting to use the vulnerability reported," said Alexandra Huft, Security Program Manager.

The Redmond Company has informed that the zero-day vulnerability is under investigation, but failed to deliver any additional details past the fact that the flaw is limited to Word 2000. "The vulnerability cannot be exploited on Word 2003, Word Viewer 2003, Word 2007, and Word 2004 for Mac, Word v. X for Mac, Word 2002 or Works 2004, 2005, or 2006," stated Microsoft, adding that a system can get compromised only if the user opens a compromised Word 2000 file.
Read by 1,529 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.0/5) 6 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


133 Critical and Important Microsoft Vulnerabilities

The Third Exploit for Microsoft Word Vulnerability

Details on Three Unpatched MS Word Vulnerabilities

Highly Critical Microsoft Word Zero-Day

The Coordinates of an MS Word Attack

Microsoft Debuts the 2007 Patching Season

Second Word Zero-Day Vulnerability in a Week

Merry Vista Vulnerability!

Internet Explorer Sinks Under 80%

Remove the Search Box from Internet Explorer 7

The First Windows Vista Vulnerability

God Save Internet Explorer

Internet Explorer 7 - Zero Vulnerabilities

Windows Vista Is Plagued with Vulnerabilities

The Limitations of Extended Validation SSL Certificates

Seven December 2006 Security Bulletins

Internet Explorer 8.0

284 Days - The Attack Window of IE in 2006

4 January Microsoft Security Bulletins Discontinued

Firefox 2.0 Continues to Grow in the Detriment of IE7

Download January 2007 Security Releases ISO Image

100 Million Installations - Internet Explorer 7

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM