12 Dec 2007
The US Computer Emergency Response Team (US-CERT) is warning users to be vigilant of attacks using Microsoft Access Database (MDB) files.
US-CERT said that it has received reports of attacks targeting the vulnerability in the wild. If exploited, the flaw allows an attacker to remotely execute code on the target machine.
A Microsoft spokesperson would not directly confirm the report, but said that the company is investigating reports of an attack targeting MDB files.
The spokesperson told vnunet.com that even without the vulnerability, MDB files are among those classified as 'unsafe' file types that can be used in attacks.
Though it may sound foreboding, the term simply refers to files that allow for automated actions to run on a user's machine. Other file types classified by Microsoft as 'unsafe' include executables (.exe) and Word documents (.doc).
US-CERT recommends that users reduce the risk of the vulnerability by avoiding suspicious email attachments. The group also recommends that administrators set email filters to block attached file types classified as 'unsafe'.
The reports come just as Microsoft is releasing its final scheduled security update for 2007. The company did not rule out releasing an out-of-schedule patch if the attacks persist.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
A senior C# developer is required by a leading investment...
A senior JAVA developer is required by a leading financial...
A leading investment bank are looking for an AGILE JAVA...
A senior C# WPF F# developer is required by a leading...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?