NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


The Third Exploit for Microsoft Word Vulnerability

Available in the wild

By Marius Oiaga, Technology News Editor

14th of December 2006, 11:28 GMT

Adjust text size:


Attack code exploiting a Microsoft Word vulnerability is available in the wild. This is the third example of proof-of concept targeting a vulnerability across Microsoft Word 2000, Microsoft Word
2002, Microsoft Office Word 2003, Microsoft Word Viewer 2003, Microsoft Word 2004 for Mac, and Microsoft Word v. X for Mac, as well as Microsoft Works 2004, 2005, and 2006.

On December 5, Microsoft published Security Advisory (929433) informing that it was aware of limited zero-day attacks affecting the Word vulnerability. Although a successful exploit relies on users interaction and is bases on social engineering, the vulnerability is of a critical nature as it allows for remote code execution. David Marcus, security research and communications manager with McAfee Inc.'s Avert Labs, noted that a successful exploit will lead to the execution of malicious code on the victim's compromised machine.

Marcus confirmed Microsoft's reports of limited and targeted exploit attempts exemplifying with a high-profile company whose members received malicious emails containing compromised Word document attachments.

Microsoft has released seven security bulletins in December but none of them address the Word vulnerability described in Security Advisory (929433). "The patches do not contain a fix for the zero day Microsoft Word vulnerability announced last week. Microsoft is believed to still be investigating that issue," commented Sophos. In the context of an increasing volume of attacks, the most probable scenario is that Microsoft will deliver an out of band security update and will not wait until January to issue a patch.
Read by 1,565 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Poor (1.5/5) 7 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


PoC Available for Patched Microsoft Vulnerability

Second Word Zero-Day Vulnerability in a Week

Seven December 2006 Security Bulletins

Windows Print Spooler 0day DoS Vulnerability

Inspect OS and Software Security

Internet Explorer 7 Immune to October's Vulnerabilities

Windows Live OneCare Updated with Anti-phishing Technology Activation

Upgrade to IE7 Optimized for Google

Microsoft Patches - MS06-066 to MS06-071

Security Vulnerabilities in Internet Explorer 7

Trojans Spread Via Zero-Day Word Vulnerability

Free Porn via Internet Explorer Vulnerability

Internet Explorer 7 - Zero Vulnerabilities

Microsoft's "Very Limited, Targeted Attacks"

Top 10 Reasons that Recommend Windows Server 2003 SP2

Windows Server 2003 SP2 RC Available

Put the YOU in Microsoft

New Worm - Old Vulnerabilities

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM