You are here: silicon.com > Software > Security Strategy

Security Strategy

Attackers hitting yet another Word flaw

File under insecurity...

Tags: cyber attack flaw, microsoft, word, flaw

By Joris Evers

Published: 26 January 2007 08:25 GMT

Another previously undocumented, yet-to-be-patched security vulnerability in Microsoft Word is actively being exploited in cyber attacks.

The vulnerability is the fourth zero-day vulnerability to arise in the Microsoft application in two months. Microsoft hasn't provided patches for any of the flaws, despite acknowledging the holes are being used in attacks on its customers.

A Microsoft representative said in a statement about the latest problem: "There have been very limited attacks reported that are attempting to use the reported vulnerability at this time." Redmond is investigating this latest report and may issue a patch, if needed, the representative said.

The newest problem allows an attacker to hijack systems running Word 2000 and causes a crash of Word 2003 and Word XP, Symantec said in an alert. "An attacker could exploit this issue by enticing a victim to open a malicious Word file," it said.

Security experts have said the limited-scale attacks are the most dangerous. Widespread worms, viruses or Trojan horses sent to millions of mailboxes are typically not a grave concern because they can be blocked. Instead, especially for businesses, targeted Trojan horses have become nightmares, as they can fly under the radar.

Symantec advises people to make sure their security software is up-to-date and urges caution when opening Word documents. Businesses should put policies in place to prevent Word documents from being distributed to users, Symantec said.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Technical Author - Contract - London

Technical procedures and diagrams must be produced using Microsoft Word and Visio to enable the support teams to maintain the documents once ...

HR Systems Analyst - Reading, Berkshire

Excel, Word, Visio and Project - Presentation and influencing skills - Solid project management skills - Strong attention to detail, quality ...

Service Desk Analyst with strong Service Desk and ITIL experien

Your must have strong Service Desk, Microsoft Word, and Excel experience. My client is looking for a Service Desk Analyst. This is working for an end ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: