December 06, 2006

Microsoft warns of new Word attack

Bug exploited by adding a string of characters in a Word file that can corrupt a PC's memory

There's now one more reason to be careful about opening Microsoft Office attachments.

Microsoft warned Tuesday of a new, unpatched memory corruption error in its word-processing software, and said that it was investigating reports of "limited" attacks that exploit the problem.

The bug can be exploited by adding a string of characters in a Word file that can corrupt the PC's memory and allow the attacker to run unauthorized software on the system, Microsoft wrote in a security advisory .

The bug affects many versions of the software, including Word 2000, 2002, and 2003, the Word Viewer 2003 and several versions of Microsoft Works.

It is rated 'critical' by the FrSIRT Web site, which compiles a list of software vulnerabilities.

As automatic security updates have become commonplace, attackers have focused more on developing attacks that leverage this kind of unpatched hole in the software, sometimes called 0day attacks. This trend has forced Microsoft to produce a growing number of software updates in recent months.

In particular, hackers turned their attention to Microsoft's Office products, which some researchers consider to be a more fruitful source of bugs than the Windows operating system.

"Cybercriminals know that 0days are very valuable and can be used to make lots of money," said Cesar Cerrudo, chief executive officer of security research firm Argeniss, in Parana, Argentina. These vulnerabilities can be exploited to install spyware or dangerous Trojan horse programs, or to add the victim's computer to a network of compromised PCs, called a botnet, which can then be used to send out spam or attack other systems, he said.

Microsoft's next set of security updates is due to be released on December 12.

Close

On Twitter now

Application development

Powered by Twitter
additional resources
White Paper - How to Improve Delivery of Advanced Web Applications

White Paper

Virtual Workforce: The Key to Expanding The Business While Cutting Costs

Get the independent advice and expertise you need to support a virtual workforce.

Go inside:
The three-step approach to making a virtual workforce a reality.
The four flavors of client virtualization technologies.
The three key initiatives that solve IT challenges.
Download now »
White Paper: Successfully Secure Your Wireless LAN With Wi-Fi firewalls.

White Paper

Addressing Linux Threats Leveraging Fewer Resources

The increase in Linux popularity has increased the frequency and sophistication of malware attacks. Read this 2 page white paper now to learn how you can protect your Linux environment with real-time protection that is certified by all major Linux vendors.

Download now »
White Paper - The 2009 Handbook of Application Delivery

White Paper

The 2009 Handbook of Application Delivery

Ensuring acceptable application delivery will become even more difficult over the next few years. As a result, IT organizations need to ensure that the approach that they take to resolving the current application delivery challenges can scale to support the emerging challenges. This handbook elaborates on the key tasks associated with planning, optimization, management and control and provides decision criteria to help IT organizations choose appropriate solutions.

Download now »
White Paper - Is Your Backup System Outdated?

White Paper

Mid-range Storage Considerations

A common misconception is that mid-range storage requirements are dramatically different than that of a larger enterprise. Mid-range storage users may require less capacity, but they have similar functionality and management requirements. This ESG paper examines mid-range storage needs and reviews a new solution that adjusts size while retaining value, performance and functionality.

Download now »

Sign up to receive InfoWorld Resource Alerts

Subscribe to the Developer World Newsletter

Receive a weekly roundup about the art and science of software development.

©1994-2010 Infoworld, Inc.