Microsoft did not hint at when it would patch the Word bug, or whether it would go "out-of-band" and issue an emergency update before the next regularly-scheduled Patch Tuesday, which is April 8.
The Redmond, Wash. company rarely ships an out-of-band update unless attacks are widespread, which according to its Child's statement Monday, is currently not the case. The last out-of-band that Microsoft released was MS13-008, an emergency patch issued in January 2013 that plugged holes in IE6, IE7 and IE8 after the browsers had been exploited for several weeks.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer, on Google+ or subscribe to Gregg's RSS feed. His email address is email@example.com.
Read more about malware and vulnerabilities in Computerworld's Malware and Vulnerabilities Topic Center.