Alreetas

Forums » Computer/Technology Talk » Trojan targets unpatched Word flaw (again)

Trojan targets unpatched Word flaw (again)

Deano 11 Dec 2006, 18:42
Trojan targets unpatched Word flaw (again)
Microsoft has warned of another unpatched vulnerability in Word. The unspecified code execution flaw means hackers can load malware onto targeted machines providing users are tricked into opening maliciously constructed Word files.

The latest vulnerability in Microsoft's ubiquitous Office application software follows the discovery of a similar - also unpatched - memory corruption bug in Word last week. That flaw affected Mac as well as Windows versions of Word, whereas "this week's bug" is limited to Word 2000, 2002, 2003, and Word Viewer 2003. Both flaws are being exploited in low-intensity Trojan attacks.

As a result of these attacks, Microsoft advises users "not [to] open or save Word files that you receive from un-trusted sources or that you receive unexpectedly from trusted sources". This a pretty strict injunction - which labels the common practice of sending document files by email as inadvisable - at least until Microsoft releases patches to address the flaws.

Unfortunately, Microsoft confirmed last week that this will not happen on its next Patch Tuesday, 12 December, which will see five security patches for Windows (at least one of which is critical) but no Office updates. Word users are unlikely to see a patch until the new year.
davey 11 Dec 2006, 20:37
what a surprise eh with all these trojans, I hate microsoft
rabbi grice 12 Dec 2006, 19:35
2 questions - how can a giant wooden horse fit into my 17" moniter

and why blame microsoft when its the greeks who did it???
davey 12 Dec 2006, 19:40
rabbi grice wrote:2 questions - how can a giant wooden horse fit into my 17" moniter


Same way a cock gets in an ass

BRUTE FORCE
rabbi grice 12 Dec 2006, 19:51
theres me thinking it was 8 double jamesons, some spit and a stripper

Static archive of the Alreetas forum — snapshot 30 January 2009. Posts by a member whose account was removed before the backups are shown as “Former member” — the name is lost but the posts are preserved. Email addresses and contact details are intentionally omitted.