Microsoft
The attacks use specially crafted Word files to target a vulnerability in Microsoft's Jet DB

Microsoft warns of new Office attack

Attackers take aim at database component

Shaun Nichols in California

Microsoft has warned users to be vigilant after the discovery of a series of attacks on Office.

The attacks use specially crafted Word files to target a vulnerability in Microsoft's Jet DB, a database component used in the productivity suite.

Advertisement

The company issued an advisory outlining the attacks, which were classified as "very limited" and aimed at specific targets.

McAfee researcher Craig Schmugar suggested in a blog posting that the attacks could indicate a shift in strategy.

Attackers have typically exploited Microsoft Jet DB vulnerabilities through MDB files, and Microsoft has always stuck to its MDB files are unsafe story, wrote Schmugar. "Well that has changed," he added.

Microsoft said that Windows Vista and the recent Service Pack 1 upgrade are not vulnerable to the buffer overflow used in the attack. The Service Pack 2 version of Office 2003 is also immune.

The company is investigating the attacks, and has not yet decided whether to patch the flaw immediately or wait until next month's scheduled security update. Microsoft has advised users not to open files from untrusted sources.

The vulnerability allows an attacker to access the system with the rights of the current user, and Microsoft said that administrators can minimise this risk by putting controls on non-administrator accounts.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Do you agree?

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

IT white papers

Search white papers

Top categories

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

Top 10 cup

Top 10 technologies in a death spiral

A look at some technologies that may soon be departed

Thunderbird

Thunderbird 3 out this month

Open source email system gets a makeover

Best Buy to storm Blighty's stores

Now that Circuit City is gone, Best Buy's ruling the...

Internet Explorer

Europe's browser war heats up again

Mozilla and Opera demand changes to Microsoft's proposed ballot system

Primary Navigation