New Word zero-day vulnerability used in attacks
Saturday, December 9th, 2006A security deficiency still left unfixed from different Word versions is exploited in computer attacks, has informed us Microsoft.
The attacks are “limited”, according to the company, which announced that is working out a patch to fix the vulnerability.
The vulnerability is similar with previous zero-day deficiencies that affected Office applications in the last few months. An attacker could change a Word file in such a way that could take control over a vulnerable system when the document is open.
An attacker could exploit the deficiency by hosting a web site with a malicious file or sending an e-mail with the file as attachment. In all of this cases, the victim must open the file to compromise his system.
Security experts say that low scale attacks are the most dangerous. Worms, viruses and trojans with large spreading don’t usually raise big problems, as they can be blocked. For companies however, trojans “with target” have developed into a nightmare scenario, as these are very hard to trace.
The most recently Office vulnerabilities affect Word 2000, Word 2002, Word 2003, Microsoft Word Viewer 2003, Word 2004 for Mac, Word 2004 v. X for Mac and Works 2004, 2005 and 2006, announced Microsoft. The company advised the users not to open Word files that come from unreliable sources.