You are here: silicon.com > Software > Malware

Malware

Microsoft's five-month Office flaw exploited

Trojans ride in...

Tags: trojan horse, virus, trojan, microsoft office

By Joris Evers

Published: 3 October 2005 08:25 GMT

A new Trojan horse exploits an unpatched flaw in Microsoft Office and could let an attacker commandeer vulnerable computers, security experts have warned.

The malicious code takes advantage of a flaw in Microsoft's Jet Database Engine, a lightweight database used in the company's Office productivity software. The security hole was reported to Microsoft in April but the company has yet to provide a fix for the problem.

In a statement sent via email on Friday, a company representative said: "Microsoft is aware that a Trojan recently released into the wild may be exploiting a publicly reported vulnerability in Microsoft Office." The software maker is investigating the issue and will take "appropriate action", the representative said.

The Trojan horse arrives in the guise of a Microsoft Access file, security software maker Symantec said in an advisory. When run on a vulnerable system, it would give a remote attacker full access to a compromised computer, Symantec said. The company calls the pest "Backdoor.Hesive" and notes that it is not widespread.

Although exploits had already been released in April when HexView publicly reported the flaw, the Trojan is believed to be the first actual threat to take advantage of the security hole. Security monitoring firm Secunia rates the issue "highly critical", one notch below its most serious rating.

Secunia said in its April advisory: "The vulnerability is caused due to a memory handling error when... parsing database files. This can be exploited to execute arbitrary code by tricking a user into opening a specially crafted '.mdb' file in Microsoft Access."

Symantec advises users to be cautious when opening unknown files. The security software maker lists all recent Windows releases as vulnerable to the Trojan attack.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
IT OPERATIONS/INFRASTRUCTURE MANAGER.

A new opening is immediately available for an Infrastructure Manager to work for a leading UK company. Firewalls Unix servers - HP-UX Intel servers - ...

Database Admin DB2 Mainframe

These services include providing support of the Operating System configuration and associated file systems, log files, processes, problem ...

Server Management with linux

These services include providing support of the Operating System configuration and associated file systems, log files, processes, problem ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: