Symantec warns of Microsoft Word vulnerability

COMMENT ON THIS ARTICLE

Hackers are exploiting a new, unpatched vulnerability in Microsoft Corp. Word that could allow them to take control of a victim’s computer, Symantec Corp. has warned.

The zero-day vulnerability is the fourth in Microsoft’s widely-used Word 2000 software that has not yet been patched, the security company said in its Security Response Weblog.

A zero-day vulnerability refers to a security hole for which exploits are already available when it was discovered. This latest one affects most versions of Windows running Word, Symantec’s advisory said.

Danish security vendor Secunia ApS also reported the vulnerability, and rated it as “extremely critical,” its highest-level warning. Microsoft, however, said the attacks are “very limited.”

The attack comes via an infected Word document, a method increasingly used by hackers for targeted attacks. If the document is opened, it installs a Trojan horse program, called Trojan.Mdropper.W, onto the computer, Lau wrote. The Trojan also puts other files on a computer that enable a hacker to control it.

Microsoft released three sets of critical patches on Jan. 9, including ones for Outlook, PowerPoint and Windows, but not for Word.

Users can avoid trouble by not opening unexpected Word documents attached to e-mail. Hackers often spam out thousands of messages with harmful attachments, such as Trojan horse programs, hoping unsuspecting victims will open them.

Trojans often look harmless and can quietly install themselves on a computer with no visible signs. The use of Word to mount an attack can be particularly effective since the file format is so widely used.

COMMENT ON THIS ARTICLE

Would you recommend this article?

Share

Thanks for taking the time to let us know what you think of this article!
We'd love to hear your opinion about this or any other story you read in our publication.


Jim Love, Chief Content Officer, IT World Canada

Featured Download

Featured Articles

Cybersecurity in 2024: Priorities and challenges for Canadian organizations 

By Derek Manky As predictions for 2024 point to the continued expansion...

Survey shows generative AI is a top priority for Canadian corporate leaders.

Leaders are devoting significant budget to generative AI for 2024 Canadian corporate...

Related Tech News

Tech Jobs

Our experienced team of journalists and bloggers bring you engaging in-depth interviews, videos and content targeted to IT professionals and line-of-business executives.

Tech Companies Hiring Right Now