All the latest UK technology news, reviews and analysis

Third attack hits Microsoft Word

by Shaun Nichols

More from this author

15 Dec 2006

Comment: 1

  • Tweet this
Microsoft
The latest Word vulnerability could allow for remote code execution

Attackers have started exploiting a new vulnerability in Microsoft Word, security vendor eEye disclosed on its Zero-day Tracker website. The vulnerability is the third active Word exploit to surface in two weeks.  

Microsoft has not confirmed the vulnerability, but a spokesman told vnunet.com that the company is investigating the reports. 

The vulnerability could allow for remote code execution, allowing an attacker to take control of a vulnerable system and steal information or install malware.

The flaw affects Word 2000, Word XP, Word 2003 and Word Viewer 2003. Microsoft also said that it has received reports of Word v.X for Mac being vulnerable to the exploit, but could not confirm the reports.

Security company Secunia lists the vulnerability as 'highly critical', the firm's highest level of security alert. 

The US Computer Emergency Readiness Team (US-Cert) said that the exploit is launched when a user opens a specially crafted Word document. 

The organisation recommends that users avoid opening any Word document that originates from untrusted sources, or files that arrive unexpectedly from trusted sources.

US-Cert also warned that filtering files by extension name (such as .doc) may not protect users from attack, because Word will open files with the correct file header information regardless of the extension name.

If confirmed, this will be the third active exploit to be released for Microsoft Word since 6 December. Neither of the other two Word vulnerabilities were addressed in last Tuesday's security patch release from Microsoft.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Order Processing Specialist

Order Processing Specialist - 12 Month Fixed Term Contract...

Inside Sales Manager - Berkshire - Global Software Co!

Great opening with one of the worlds leading information...

JAVA J2EE Developer required with RIA, web services, REST, JSON, AJAX

JAVA J2EE Developer required with RIA, web services...

Linux Administrator

Hi, Job Title : Linux Admin Location : Brussels...

To send to more than one email address, simply separate each address with a comma.