ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

New security hole found in MS Word

Joris Evers CNET

Published: 22 May 2006 09:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new, yet-to-be-fixed security hole in Microsoft Word exposes computer users to cyberattack, Symantec warned Friday.

Would-be intruders already have attempted to compromise PCs at a Japanese government entity by exploiting the flaw, Vincent Weafer, the senior director at Symantec Security Response, said in an interview. In response, Symantec has raised its ThreatCon to Level 2, which means an outbreak is expected.

"What we're seeing is a continuation of the targeted threat using zero-day vulnerabilities," Weafer said. Zero-day flaws are ones for which no patch exists. "We got it from a single large customer inside Japan. We have not seen anyone else get it."

Microsoft is readying a security update for Word that repairs this vulnerability, a company representative said in an emailed statement. The fix is scheduled to be released as part of the 13 June security updates, or sooner, if warranted, the representative said.

The malicious software arrives as a Microsoft Word file attachment to an email. When the document is opened by the user the vulnerability is triggered. In the Japanese case the Word document actually displayed some text related to a treaty with China, but while the text was displayed a backdoor was installed on the system, Weafer said. Backdoor software allows intruders to enter computers surreptitiously.

"The backdoor in turn pings an IP address located in Asia. It just pings to say it is available, but then, of course, you have a backdoor on your system," he said.

The vulnerability was confirmed in Word 2003, Symantec said. The malicious file caused Word 2000 to crash, but did not run the malicious payload, it added.

Exploitation of the security hole so far is only known as part of a single, targeted attack, Symantec said. "However, with the disclosure of this previously unknown vulnerability, new attackers may begin to exploit it in a widespread manner," the security company said in an advisory to customers.

The targeted attack can bypass spam filters, and Symantec's antivirus software doesn't yet detect the particular Word file as malicious, Weafer said. "We are looking at the vulnerability itself, in terms of generic blocking," he said, adding that the security software does detect the backdoor and the installer of the backdoor.

Microsoft and Symantec urged caution in the opening of Word documents received as an unexpected email attachment.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
39 out of 95 people found this useful



Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

System Test Analyst - Interview slots for tomorrow!

Free for an interview tomorrow? Want a six month contract with possible extensions? If you have the skills below contact KYLIE CLARK at Real IT. The ...

PHP Developer - Urgent - Interview Slots Booked

You will be well versed with: -PHP 5 - MySQL - Linux - CSS - JavaScript and XML This requirement is urgent and interview slots are booked throughout ...

3rd Line Support Role, Merseyside, North West -AD, Windows 2003 server

Sites and Subnets, Replication, GPOs etc) Exchange 2003(High level Exchange 2003 Support and implementation mostly at Organizational level, ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment