Microsoft advisory warns exploits targeting newest Word vulnerability

Powered by SC Magazine
 

Microsoft is warning Word users of attackers exploiting a newly discovered - and "extremely critical" - vulnerability.

The software titan released an advisory today for the flaw, warning PC users of limited zero-day attacks.

Microsoft advised caution in opening email attachments and viewing websites, saying that, to infect a PC, an attacker must first dupe a targeted user into opening a malicious Word file.

Alexandra Huft, Microsoft security program manager, said on the Microsoft Security Response Center blog today that her company is aware of "very limited, targeted" attacks attempting to use exploit the flaw.

Microsoft has been criticised for failing to distribute patches for three other Word flaws during recent Patch Tuesday releases.

Secunia, ranked the flaw as "extremely critical," meaning it can be exploited by remote code and exploits are in the wild.

The vulnerability is caused due to an unspecified error when parsing Word documents, according to the vulnerability-reporting clearinghouse. The flaw exists in Word 2000, but other versions may also be affected.

Researchers at Symantec disclosed the flaw, also saying the issue is "extremely critical."

"An attacker could exploit this issue by enticing a victim to open a malicious Word file," according to Symantec. "If the attack is successful, the attacker may be able to execute arbitrary code in the context of the currently logged-in user."

Click here to email Online Editor Frank Washkuch Jr.

 
 
 
Top Stories
Can the ATO use IT to shed its old-school reputation?
Inside the ‘reinvention’ at the hands of new management.
 
JB Hi-Fi's new CIO gets 'clean slate' for change
New AusPost, Tabcorp exec to get his hands dirty.
 
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
The 5 Windows 10 privacy issues you should be aware of
Jul 31, 2015
There are a few unsettling details when it comes to Windows 10 privacy
Windows 10 is here! (For some)
Jul 29, 2015
Delivery of the free upgrade versions of Windows 10 began today - have you got yours yet?
Microsoft reveals Microsoft Send, a new enterprise chat app to rival Slack
Jul 27, 2015
Microsoft Send is MSN Messenger for grownups, and you could be using it at work very soon
Developers offered $500,000 grants to find HoloLens uses
Jul 8, 2015
Can augmented-reality end up in business?
Microsoft Tossup: The planning app for unorganised groups of friends
Jul 8, 2015
App allows friends to research venues, vote on plans and chat. And depending on how you run your ...
Latest Comments
Polls
Should law enforcement be able to buy and use exploits?



   |   View results
Yes
  14%
 
No
  51%
 
Only in special circumstances
  18%
 
Yes, but with more transparency
  18%
TOTAL VOTES: 832

Vote