NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Patches and Vulnerabilities

Patches and Vulnerabilities


Microsoft Warns of Office Word Exploits in the Wild

But targeting only Office Word 2002 SP3

By Marius Oiaga, Technology News Editor

9th of July 2008, 14:03 GMT

Adjust text size:


Office
Enlarge picture
The ubiquity of the Office productivity suite along that of Windows makes Microsoft's flagship products some of the preferred targets for attacks. In this regard, the Redmond giant warned Office users of new exploits identified in the wild targeting Microsoft Office Word 2002 SP3. Bill Sisk, Microsoft
Security Response Center Communications Manager, was reserved in throwing the blame on Office and revealed that a vulnerability in the Word component of the productivity suite has yet to be confirmed.

Sisk referred only to a "possible vulnerability within Microsoft Office Word which could allow for remote code execution. Our investigation this far has shown that this vulnerability affects Microsoft Office Word 2002 Service Pack 3 only. At this time, we are aware of limited, targeted attacks attempting to use the reported vulnerability, but we will continue to track this issue".

The attack is carried out through malicious .DOC files which the victim has to execute in order for an attacker to successfully exploit the issue. Microsoft did not reveal the entire impact of the exploits as the investigation is still underway, but it is clear that users are dealing with a Critical vulnerability. According to the software giant, exploits of the security flaw will also cause Office Word 2000 to crash but, in this case, the attacks are limited to denial of service scenarios.

"Our initial investigation indicates that customers who use all other supported versions of Microsoft Office Word, Microsoft Office Word Viewer, Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats, and Microsoft Office for Mac are not affected," Microsoft informed.

More specifically, Word in Office 2000 SP3, Office 2003 SP2 and SP3, Office 2007 SP1, Office for Mac 2004 and 2008, as well as Office Word Viewer 2003, and Office Compatibility Pack for Office 2007 are not affected by the issue. As a workaround, Microsoft is advising users of Word 2002 SP3 to access Office Word 2003 Viewer or Office Word 2003 Viewer SP3 in order to open and view .DOC files.

"We will continue to monitor the situation and post updates to the advisory and [will provide updates] as we become aware of any important new information. In the meantime, we encourage customers to review the advisory and implement the workarounds," Sisk added.

TAGS:

Office 2002 | Office Word 2002 | vulnerability
Read by 1,209 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
NOT RATED 0 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Microsoft Warns of New Attacks Targeting ActiveX

Download Free Windows Server 2003, Office 2007 and Visual Studio 2008

Microsoft Equipt: Office 2007 and Windows Live OneCare Bundled Together

Bi-Monthly Office Cumulative Updates Will Not Impact Service Packs

Select Plus, a New Way of Purchasing Vista SP1 at a Discount

Bill Gates: Windows 7 - Amazing Things

Life After Windows - Microsoft Midori Operating System

Vista SP1 Solution Accelerator Available for Download

Microsoft Office Live Small Business - 1 Million Subscribers

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM