Unpatched Word flaw menaces civilisation
Not just Windows - Mac too
Posted in Enterprise Security, 6th December 2006 11:39 GMT
Free whitepaper – The shortcut guide to managing certificate lifecycles
Microsoft has warned of a serious - and as yet unpatched vulnerability - in Word. Hackers (albeit to a limited extent) are exploiting the zero-day flaw in its ubiquitous Office application, Redmond warns.
The flaw - which stems from an unspecified memory corruption bug - doesn't just affect Windows users. Microsoft Word 2000, Microsoft Word 2002, Microsoft Office Word 2003, Microsoft Word Viewer 2003, Microsoft Word 2004 for Mac, and Microsoft Word 2004 v. X for Mac, along with Microsoft Works 2004, 2005, and 2006 are all potentially vulnerable. Users tricked into opening maliciously constructed Word files are liable to find their systems compromised.
Pending the availability of a security fix, Microsoft advises users "not [to] open or save Word files that you receive from untrusted sources or that you receive unexpectedly from trusted sources" (our emphasis)".
This unusually strongly-worded advice amounts to using Word only to create files yourself, and confining content to local area networks, at least until the next scheduled Patch Tuesday on 12 December. ®
Free whitepaper – Securing your Apache web server with a Thawte digital certificate


The best practices guide for application security
Avoiding 7 common mistakes of IT security compliance
The starter PKI program
Airport insecurity: the case of lost laptops
The mandate for application security
Google cloud told to encrypt itself
Chinese firm hits back at cyberspy claims
BlockMaster SafeStick hardware-encrypted USB drive