Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

Microsoft Word 2000 - New unpatched vulnerability and expolit

Users should continue to be cautious and avoid all suspicious or unexpected Office documents received in email messages.

Microsoft Word 2000 - New unpatched vulnerability and expolit
http://secunia.com/advisories/23950/
http://www.frsirt.com/english/advisories/2007/0350
http://www.microsoft.com/technet/security/advisory/932114.mspx

QUOTE: A vulnerability has been identified in Microsoft Word, which could be exploited by attackers to take complete control of an affected system. This issue is due to a memory corruption error when handling a document containing a malformed string, which could be exploited by attackers to execute arbitrary commands by tricking a user into opening a specially crafted Word document.