Microsoft
The latest Word vulnerability could allow for remote code execution

Third attack hits Microsoft Word

Three's company for text editor flaws

Shaun Nichols in California

Attackers have started exploiting a new vulnerability in Microsoft Word, security vendor eEye disclosed on its Zero-day Tracker website. The vulnerability is the third active Word exploit to surface in two weeks.  

Microsoft has not confirmed the vulnerability, but a spokesman told vnunet.com that the company is investigating the reports. 

Advertisement

The vulnerability could allow for remote code execution, allowing an attacker to take control of a vulnerable system and steal information or install malware.

The flaw affects Word 2000, Word XP, Word 2003 and Word Viewer 2003. Microsoft also said that it has received reports of Word v.X for Mac being vulnerable to the exploit, but could not confirm the reports.

Security company Secunia lists the vulnerability as 'highly critical', the firm's highest level of security alert. 

The US Computer Emergency Readiness Team (US-Cert) said that the exploit is launched when a user opens a specially crafted Word document. 

The organisation recommends that users avoid opening any Word document that originates from untrusted sources, or files that arrive unexpectedly from trusted sources.

US-Cert also warned that filtering files by extension name (such as .doc) may not protect users from attack, because Word will open files with the correct file header information regardless of the extension name.

If confirmed, this will be the third active exploit to be released for Microsoft Word since 6 December. Neither of the other two Word vulnerabilities were addressed in last Tuesday's security patch release from Microsoft.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Related whitepapers

Related jobs

Most watched

standard plug

UK folding plug system in action

Inventor develops innovative answer to bulky UK plugs

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

Analysis and Reports

Continuous Availability for Microsoft SharePoint

This paper examines how to create continuous availability for Microsoft SharePoint by implementing high availability and disaster recovery solutions.

Database security: Preventing enterprise data leaks at the source

This report looks at the challenge of information protection and control (IPC) and how enterprises must adopt database security best practices

Poll

International Women’s Day poll

International Women’s Day poll

Have measures to encourage women into the IT profession been successful?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

Top 10 computer games of all time

As the game Bafta winners are unveiled, we celebrate the...

Google Street View

Google Street View under fire again

Web giant criticised for showing images of secret SAS base...

Rosalie Marshall

Government should consider monitoring PR efforts more closely

A release on tech workers' hobbies shows the government might...

Internet Explorer

MIX10: Microsoft shows browser and mobile future

Microsoft's MIX10 event showed where the firm is heading with...

Primary Navigation