Original URL: https://www.theregister.com/2007/02/05/0-day_office_flaw/

Hackers target unpatched Office flaw

Zero-day spectre haunts spreadsheets

By John Leyden

Posted in Channel, 5th February 2007 14:32 GMT

Microsoft has warned of an unpatched vulnerability in its Office productivity suite.

The bug, which arises from an unspecified flaw in handling strings, might be exploited to corrupt memory on a vulnerable system. The flaw allows malware to be loaded onto exposed systems providing users are tricked into opening maliciously-constructed files. Computers running Microsoft Office 2000, Office XP, Office 2003, and Microsoft Office 2004 for Mac are all potentially vulnerable.

The vulnerability is the subject of active hacking attacks albeit to a "very limited" extent, Microsoft warns. Although Excel is currently the sole vector of these zero-day attacks, other Office applications may also be affected. Users are advised not to open untrusted Office documents pending the release of patches from Microsoft. ®