Latest Comments
"trend is good antivirus software."
by jack | Dec 3, 2008 7:02 AM
 
"I feel it with you guys. These irritating interruptions on privacy MUST be stopped. It is a ..."
by Jan Wilmans | Dec 2, 2008 7:11 PM
 
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM

Researchers warn of Microsoft Access Database exploit

  • Email a Friend
  • Print Page
Researchers warn of Microsoft Access Database exploit
Targeted phishing emails are attempting to infect the machines of users' who are tricked into opening malicious Microsoft Access Database (MDB) files, US-CERTsaid in a warning this week.

The bogus files attempt to take advantage of a stack-based buffer overflow vulnerability that occurs when Microsoft Access processes specially crafted database files, according to the advisory. Should a user click on a corrupted file, their machines could be pounded with malicious software.

Microsoft considers MDB files, which allow for embedded script, unsafe.

"Various Microsoft applications prevent users from opening this type of file, or warns them before they open the file," a company spokesman told SCMagazineUS.com today in an email.

The spokesman confirmed that Microsoft was aware of public exploit reports.

Craig Schmugar, threat research manager for McAfee Avert Labs, told SCMagazineUS.com that the attacks likely take advantage of either of two unpatched Microsoft Jet Database vulnerabilities.

Researchers at McAfee have spotted the flaws being exploited in a limited manner, mostly targeting "entities related to government," he said.

Schmugar said socially engineered attacks hoping to leverage the flaw may succeed because users tend to trust certain files.

"People might think it's an Office document," he said. "They might be less apprehensive about accessing it."

Meanwhile, businesses should ensure they block MDB files at the email gateway, the US-CERT warning advised.

"While Microsoft treats them as unsafe, many companies may not," Schmugar said.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Comments: 1
Hi, Quality posting about MS access database fishing issues. These issues posseses data loss and sometime corrupt the whole database or mdb files. In this situation you can use stellar phoenix access recovery software. To see the preview of repaired database download demo version of access repair software:http://www.stellarinfo.com/access-recovery.htm Thanks
SC Magazine - comments icon Posted by martinAug 1, 2008 4:32 PM
Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Vulnerabilities & Exploits Whitepapers