You are here: silicon.com > Software > Security Strategy

Security Strategy

Zero-day attack strikes Office

Word of warning...

Tags: word, attack

By Joris Evers

Published: 16 February 2007 08:40 GMT

A new, yet-to-be-patched security hole in Word is being used in targeted cyber attacks, Microsoft has warned.

When a user opens a rigged Word file, it may corrupt system memory in such a way that an attacker could gain complete control over the PC, Microsoft said in a security advisory. Office 2000 and Office XP are at risk, the company said. The two recent versions, Office 2003 and 2007, are not affected.

As with most of the Office vulnerabilities, an attacker would have to trick a user into opening a malicious file to be successful. The vulnerability is being exploited in "very limited, targeted attacks", Microsoft said. A security update to repair the problem is in the works, it added.

Word of the new flaw came a day after Microsoft released updates for nine other Office-related vulnerabilities. Five of them were zero-day flaws, or security holes that have been publicly disclosed but not fixed.

Security experts have said that limited-scale attacks are the most dangerous. Widespread worms, viruses or Trojan horses sent to millions of mailboxes are typically not a grave concern, because they can be blocked. But targeted Trojan horses, especially those aimed at specific businesses, have become nightmares as they can fly under the radar.

Cyber crooks have found that they can take advantage of Microsoft's security update cycle by timing new attacks right before or just after "Patch Tuesday" - the second Tuesday of each month when the software maker releases its fixes. Some security watchers have coined the term "zero-day Wednesday" to describe that strategy.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
Senior Data Recovery Engineer - Sheffield

Recovery expertise Hard drive rebuild experience Electronics repair skills Flash Memory and memory recovery for SSD BGA experience PC3000 UDMA In ...

Translation Project Manager

Applied knowledge of HTML/Internet file formats and TRADOS or other translation memory software programs Translation Project Manager Based in Central ...

Web Tester - Penetration Tester - Staffordshire West Midlands

Candidates must have thorough experience of web application penetration testing which include both knowledge and experience in Man in the Middle ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: