Advertising
Brought to you by SeattlePI.com: Seattle Tech Report
Our network sites seattlepi.com

Blogs

Print thisE-mail this
Microsoft Word security flaw: Be wary of that attachment

A newly discovered vulnerability in Microsoft Word is drawing high levels of attention from security experts. It's deemed a "zero-day" vulnerability, meaning that people are exploiting it on the same day it surfaces publicly, before the company has a chance to issue an update to fix the flaw. It's exploited via a Word file attached to an e-mail. Microsoft says it's working on a patch.

On Microsoft's Security Response Center blog, Stephen Toulouse has details:

Here's what we know: In order for this attack to be carried out, a user must first open a malicious Word document attached to an e-mail or otherwise provided to them by an attacker. (note that opening it out of email will prompt you to be careful about opening the attachment) So remember to be very careful opening unsolicited attachments from both known and unknown sources.

Brian Krebs of the Washington Post, in a post on his Security Fix blog, explains what can happen when the vulnerability is exploited:

According to Symantec, the Mdropper.H Trojan that exploits the new flaw may arrive in a file that looks something like this: NO.060517.doc.doc. Symantec said the Trojan appears to work in Microsoft Word 2003 and crashes Microsoft Word XP. Then the Ginwui backdoor program planted by Mdropper gathers system information and allows the attacker to access a command shell (that usually means game over for the victim PC) and take screen shots of whatever the user sees on his or her computer monitor. Ginwui also appears to connect to a Chinese server, no doubt controlled by whoever sent out the nastygram in the first place.

Also see coverage by CNet News.com, Information Week, and BetaNews.

Posted by at May 20, 2006 8:31 a.m.
Category:
Comments
#6611

Posted by EleFusion at 5/21/06 7:39 a.m.

Dem darn papermakers! {to quote an old black 'n white}

The fact we can pin-point a server & do nothing about it..ridiculous.

#6612

Posted by EleFusion at 5/21/06 7:43 a.m.

Well, I suppose not. Many hackers use those proxy programs {which are loved on a lot of hack sites.} I personally am the mind that those should be banned unless for 'corporate' use.

On the other hand, it does mean that single person has a high level of security which the Chinese Government I'm sure doesn't like.

! Login below to post a comment.

Registered users, log in here
E-mail 
Password 
Remember me
 HELP! I forget my password

Unregistered users, sign up now

Or post anonymously (About this feature)

Your comment (No HTML allowed, use these special codes instead)
Violating our Terms of Service may result in your post being removed.

Special codes
  • [b]selected text[/b] -- Display the selected text in bold.
  • [i]selected text[/i] -- Display the selected text in italics.
  • [link]www.seattlepi.com[/link] -- Creates a link to the url between the link tags.
  • [link title="Seattle Post-Intelligencer"]www.seattlepi.com[/link] -- Creates a link to the url between the link tags, uses title as link text.
  • [mail]newmedia@seattlepi.com[/mail] -- Creates a link to an email address.
Enter the code shown:
What is this?
SUBSCRIBE

RSS
Headline widget

BLOGGER BIO
photo
Joseph Tartakoff: P-I staff reporter
FEATURED COMMENT

PictureMicrosoft, you really need to start looking for revenue elsewhere. Resorting to bribing users to use your products and services is just plain embarrassing.
-- Reader on Microsoft offers 'perks' to search users

MSFT: DAILY TREND

TOPIC: WINDOWS VISTA

· Vista at One Year: Progress and Pain
· Computer shop's sales pitch: 'We remove Vista'
·
Full text: Microsoft execs on Vista problems
· All stories and posts

RECOMMENDED READING
ARCHIVES
Search this blog

Recent entries
· Microsoft exec: Mac users face hidden costs
· 'Windows 7' will be name of next Windows OS
· Microsoft says its Flash-rival gains ground
· Forget the mouse, use a tomato instead
· Microsoft sues DHL over damaged Xboxes

Browse by month
Browse by category
LINKS

Microsoft News
· WinInfo
· Microsoft Watch
· Directions on Microsoft
· WinInsider
· ActiveWin
· KOMO News: Microsoft
· NetworkWorld: Microsoft
· Google News: Microsoft
· Yahoo News: Microsoft
· Microsoft Research News
· Microsoft PressPass
· Channel 9
· OS News
· Microsoft SEC filings

Microsoft Blogs
· Mary Jo Foley: All About Microsoft
· LiveSide.net
· Download Squad
· Bink.nu
· Long Zheng, istartedsomething.com
· Beyond Binary, Ina Fried of CNet News.com
· One Microsoft Way

Microsoft Employees
· Employee Blog Portal
· S. Somasegar
· Raymond Chen
· Dare Obasanjo
· Brad Abrams
· Heather Hamilton
· Chris Anderson
· Joshua Allen
· Chris Sells
· John Porcaro
· John Montgomery
· Kevin Schofield
· Sean Alexander
· Jobs Blog
· Harry Pierson
· Mini-Microsoft

Technology Blogs
· Robert Scoble
· Paul McNamara
· Dwight Silverman
· Charlene Li
· Joel Spolsky
· Engadget
· Gizmodo
· Simon Phipps
· Paul Andrews
· Chris Pirillo

Search-related sites
· John Battelle
· Greg Linden
· Yahoo! Search Blog
· Live Search Blog
· Google Blog
· Search Engine Watch
· Google Like a Hawk

Browser-related sites
· Internet Explorer team
· mozillaZine
· Surfin' Safari
· Browser News

Antitrust info
· FindLaw: Microsoft
· DOJ Microsoft site
· Microsoft legal site
· Findings of Fact
· ComputerWorld Report
· Sun legal page
· Dan Kegel's antitrust site

TECH EVENTS

· Vint Cerf at the UW
· WTIA Legal Matters: 'China Legal Perspectives'
· WTIA Legal Matters: 'General Legal Perspectives'
*all tech events

ADVERTISING

Most recent posts
· Whidbey Island Life: John Auburn's Award Winning Cake : The Emerald City
· Horsebytes: Keep on Trucking
· Seattle 911: UW police closer to finding chief

*Would you like to blog for us?

Advertising

Seattle Post-Intelligencer
101 Elliott Ave. W.
Seattle, WA 98119
(206) 448-8000

Home Delivery: (206) 464-2121 or (800) 542-0820

Send comments to newmedia@seattlepi.com
©1996-2008 Seattle Post-Intelligencer
Terms of Use/Privacy Policy

Hearst Newspapers