NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Trojans Spread Via Zero-Day Word Vulnerability

Troj/DwnLdr-FXG and Troj/DwnLdr-FXH

By Marius Oiaga, Technology News Editor

7th of December 2006, 15:10 GMT

Adjust text size:


Two different pieces of malware are spreading via an unpatched Microsoft word vulnerability. The Redmond Company has published on December 5, 2006, a security advisory warning of the
detection of proof-of-concept code for a zero-day vulnerability in Word 2000, Word 2002, Office Word 2003, Word Viewer 2003, Word 2004 for Mac, and Word 2004 v. X for Mac, as well as Works 2004, 2005 and 2006.

The Redmond Company stated at that time that it was aware of limited exploits attempts targeting the vulnerability. Two days latter, security company Sophos has issued a public warning informing of the detection of two Trojan horses that spread through the Word flaw. Troj/DwnLdr-FXG and Troj/DwnLdr-FXH are being aggressively distributed via the unpatched flaw that - if successfully exploited - allows for remote code execution.

"It appears that hackers are deliberately creating malformed Word documents that result in a buffer overflow that can then run unauthorized code on the user's computer," said Graham Cluley, senior technology consultant for Sophos. "They can then tell the computer to download and run malware, such as these Trojan horses, opening the door for all kinds of malicious behavior."

Microsoft has not issued a security patch for the World vulnerability. It is possible that the software giant will address the flaw in the next monthly patch cycle scheduled for December 12, 2006. But due to the proximity of the reports concerning the zero-day vulnerability and security bulletins release date, it's also possible that Microsoft will issue an out of band release or deliver the security updates in January 2007.

"So far the vulnerability does not appear to be being widely exploited. Nevertheless, Microsoft will be keen to build at patch for the security hole as quickly as possible, and computer users should exercise caution about which Word documents they choose to open," added Cluley.
Read by 1,676 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.1/5) 6 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Yes, Sophos Already Released Vista Anti-virus Protection

Banks Should Stop Providing Temptations for Phishers

Exercise Paranoia while Shopping Online

More Than Half of the Chinese Malware Is Harvesting Passwords

Protect Windows Vista

Santa Brings Spam to Naughty Email Boxes

The First Viruses for Windows Vista

Webcam Blackmailers Arrested in Spain

Who Stands to Benefit From Vista PatchGuard?

Windows Vista Crack - Trojan Horse

Free Porn via Internet Explorer Vulnerability

Vista PatchGuard = Foul Play?

Microsoft Confirms That Vista Is Affected by Malware from 2004

McAfee Delivers Support for Windows Vista

Malicious Code Continues to Survive on Windows Vista

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM