NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


The Coordinates of an MS Word Attack

Vulnerability, Exploit and Attack

By Marius Oiaga, Technology News Editor

14th of December 2006, 11:46 GMT

Adjust text size:


The Cupertino-based security outfit Symantec revealed that the analysis of Bloodhound.Exploit.106 samples returned as a result of a heuristic method released for the zero-day Word
vulnerability (Microsoft Security Advisory 929433) resulted in the identification of a maliciously crafted Word document.

"We found a malicious Word document that was written in Portuguese and added detection for it as Trojan.Mdropper.T. The document contains an exploit that drops an executable file, which then installs a downloader threat and opens a clean Word document in an Asian language with some strange predictions about the future. The downloader then downloads a keylogger/infostealer. Detections for all of this malicious code are included in today's certified definitions," explained Amado Hidalgo, Symantec Sr. Security Response Manager.

Symantec additionally detected a copy of the original Portuguese document designed to be compatible with a free word processing application. Both documents are malformed and will crash MS Word, but the latter will also conduct to remote code execution.

"The original document is publicly available on a number of Web sites, so we suspect the malicious code writers may have stumbled upon it and used it as a "template", transforming an innocent bug into a working exploit. In fact, the final malicious Word file contains an encrypted shellcode (probably generated using the Metasploit suite) and a malicious executable file," added Hidalgo.

Read by 1,614 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.4/5) 10 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


PoC Available for Patched Microsoft Vulnerability

Second Word Zero-Day Vulnerability in a Week

Seven December 2006 Security Bulletins

Windows Print Spooler 0day DoS Vulnerability

Inspect OS and Software Security

Internet Explorer 7 Immune to October's Vulnerabilities

Windows Live OneCare Updated with Anti-phishing Technology Activation

Upgrade to IE7 Optimized for Google

Microsoft Patches - MS06-066 to MS06-071

Security Vulnerabilities in Internet Explorer 7

Trojans Spread Via Zero-Day Word Vulnerability

Free Porn via Internet Explorer Vulnerability

Internet Explorer 7 - Zero Vulnerabilities

Microsoft's "Very Limited, Targeted Attacks"

Top 10 Reasons that Recommend Windows Server 2003 SP2

Windows Server 2003 SP2 RC Available

Put the YOU in Microsoft

New Worm - Old Vulnerabilities

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM