Microsoft advisory warns exploits targeting newest Word vulnerability

Powered by SC Magazine
 

Microsoft is warning Word users of attackers exploiting a newly discovered - and "extremely critical" - vulnerability.

The software titan released an advisory today for the flaw, warning PC users of limited zero-day attacks.

Microsoft advised caution in opening email attachments and viewing websites, saying that, to infect a PC, an attacker must first dupe a targeted user into opening a malicious Word file.

Alexandra Huft, Microsoft security program manager, said on the Microsoft Security Response Center blog today that her company is aware of "very limited, targeted" attacks attempting to use exploit the flaw.

Microsoft has been criticised for failing to distribute patches for three other Word flaws during recent Patch Tuesday releases.

Secunia, ranked the flaw as "extremely critical," meaning it can be exploited by remote code and exploits are in the wild.

The vulnerability is caused due to an unspecified error when parsing Word documents, according to the vulnerability-reporting clearinghouse. The flaw exists in Word 2000, but other versions may also be affected.

Researchers at Symantec disclosed the flaw, also saying the issue is "extremely critical."

"An attacker could exploit this issue by enticing a victim to open a malicious Word file," according to Symantec. "If the attack is successful, the attacker may be able to execute arbitrary code in the context of the currently logged-in user."

Click here to email Online Editor Frank Washkuch Jr.

 
 
 
Top Stories
Content, cost & constant innovation: How Foxtel plans to take on Netflix
Nell Payne inhabits the “brave new world of blue strings and networking”. Just don't ask her to put a TV screen on your microwave.
 
Sending in the drones
Margins are getting tighter in the industrial services industry, so Transfield Services' Stephen Phillips looks offshore - and to the skies - for the solutions he needs to keep pace.
 
Westpac fires starting pistol on core banking upgrade
St George readies itself for move to Celeriti.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Microsoft launches Office for Android preview
May 22, 2015
Microsoft has launched a preview of Office for Android smartphones. Pre-release versions of ...
Microsoft is working on an iOS email chat feature called Flow
May 22, 2015
Microsoft is working on a new chat app, but at the moment we know more about what we DON'T know, ...
Windows 10 free upgrade: Microsoft details who gets what
May 22, 2015
Microsoft was meant to be streamlining its OS with Windows 10, so why is upgrading so confusing? ...
Windows 10 has an edition to suit everyone's needs
May 15, 2015
Microsoft unveils a mind-melting six editions of Windows 10 ahead of its Winter 2015 launch. ...
Firefox 38 FINAL released, debuts new tab-based preferences
May 13, 2015
Mozilla has unveiled the latest version of Firefox 38.0 FINAL for desktop, with Firefox for ...
Latest Comments
Polls
Should Optus make a bid for iiNet?

   |   View results
Yes
  43%
 
No
  57%
TOTAL VOTES: 536

Vote