Microsoft tells Symantec that latest exploited Word flaw is variation of older vulnerability

By
Follow google news

Microsoft has confirmed that what appeared to be a newly discovered Word flaw is actually a variant of a vulnerability revealed last year, according to Symantec.


However, numerous organisations have been targeted by exploits taking advantage of the word processor vulnerability, Eric Chien, Symantec researcher, said Thursday in a posting on the Symantec Security Response blog.

Chien said the flaw is being actively exploited in the wild, and advised customers to be careful opening Word email attachments.

The bug is a variation of a Microsoft Word flaw (CVE – 2006 -6456), revealed last year.

Chien first reported the flaw – and attacks exploiting it using the Mdropper.x trojan – on Tuesday.

A fourth Word flaw came to light last week, and is being used in limited attacks, according to Microsoft.

All of the vulnerabilities could be exploited to execute arbitrary code, allowing attackers to drop a trojan on an infected machine. Some experts predicted that Microsoft would release an out-of-cycle patch for the flaws, but so far Redmond has remained mum on its patching plans.

Click here to email Online Editor Frank Washkuch.
Got a news tip for our journalists? Share it with us anonymously here.
Tags:

Most Read Articles

Researchers detail Bluetooth headphone attack that can hijack smartphones

Researchers detail Bluetooth headphone attack that can hijack smartphones

Patients fret as ManageMyHealth data breach drama plays out

Patients fret as ManageMyHealth data breach drama plays out

Telstra used ConnectID impermissibly for months

Telstra used ConnectID impermissibly for months

Chinese cyberattacks on Taiwan infrastructure averaged 2.6 million a day in 2025

Chinese cyberattacks on Taiwan infrastructure averaged 2.6 million a day in 2025

Log In

  |  Forgot your password?