Wednesday December 3, 2008 2:16 AM AEST
Latest Comments
"I feel it with you guys. These irritating interruptions on privacy MUST be stopped. It is a ..."
by Jan Wilmans | Dec 2, 2008 7:11 PM
 
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM

Patched Microsoft Word exploit hits the wild

  • Email a Friend
  • Print Page
Patched Microsoft Word exploit hits the wild
By Dan Kaplan
Oct 12, 2007 10:13 AM
Tags: Patched | Microsoft | Word | exploit | hits | the | wild
The flaw, which, according to Microsoft, was being exploited in targeted attacks prior to Tuesday's fix, is rated "extremely critical" by vulnerability tracking firm Secunia. It affects Microsoft Office 2000, Office XP and Office 2004 for Mac.

Users' machines can be compromised if they open a specially crafted Office file that contains the memory corruption error, according to the Secunia advisory. The exploit drops a trojan, dubbed Mdropper.Z by Symantec.

Alfred Huger, vice president of engineering in Symantec Security Response, told SCMagazineUS.com that this scenario is nothing new. Once attackers realize their discovery has been patched, they either start spreading the attack in a widespread manner or sell the exploit code to interested buyers.

Word is an attractive target, he said.

"It has a tremendously large user base," Huger said. "We normally see any user application that has a large footprint like is going to be targeted first (after Patch Tuesday)."

Symantec researchers have only received one in-the-wild attack submission from a customer, but they believe the exploit is being heavily distributed.

Users should be wary of opening files from untrusted sources, in addition to attachments from trusted sources that they were not expecting to receive.

A Microsoft spokesperson could not immediately be reached for comment.

See original article on SC Magazine US

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Patch Management Whitepapers