Business | CES | Digital audio | Gadgets | Games | Green computing | Home entertainment | Internet & broadband | Laptops | Linux | Macs | PC Peripherals & components | PC security | PCs & laptops | Mobile phones | Digital photography & video | Software | Wi-Fi & networking
AMD | Apple | BT | Dell | Google | HP | Intel | Microsoft | Nvidia | Sony
Windows XP | Windows Vista | Windows 7 | Apple iPhone | BlackBerry | Apple iPad
January 26, 2007
Hackers are exploiting a new, unpatched vulnerability in Microsoft Word that could allow them to take control of a victim's computer, Symantec has warned.
The zero-day vulnerability is the fourth in Microsoft's widely-used Word 2000 software that has not yet been patched, Symantec said in its Security Response Weblog.
A zero-day vulnerability refers to a security hole for which exploits are already available when it was discovered. This latest one affects most versions of Windows running Word, Symantec's advisory said.
Danish security vendor Secunia ApS also reported the vulnerability, and rated it as "extremely critical", its highest-level warning.
The attack comes via an infected Word document, a method increasingly used by hackers for targeted attacks. If the document is opened, it installs a Trojan horse program, called Trojan.Mdropper.W, onto the computer. The Trojan also puts other files on a computer that enable a hacker to control it.
Microsoft could not be immediately reached for comment. The company released three sets of critical patches on on January 9, including ones for Outlook, PowerPoint and Windows, but not for Word.
Users can avoid trouble by not opening unexpected Word documents attached to email. Hackers often send out thousands of spam messages with harmful attachments, such as Trojan horse programs, hoping unsuspecting victims will open them.
Trojans often look harmless and can quietly install themselves on a computer with no visible signs. The use of Word to mount an attack can be particularly effective since the file format is so widely used.
Free whitepaper: Phishing for victims - Truth, myth and cybercrime
<<newer story | back to index | older story>>
Submit to:Digg
Slashdot
Del.icio.us
Reddit
Subscribe to PC Advisor now and claim your FREE gift
Does your smartphone replace your need for a laptop when on the move?
% of PC Advisor readers agree with you
What tasks can your smartphone do that would have traditionally been done on a laptop?
Follow the conversation at @SmartphoneFocus
web browsing, search facilities, voip, email, word processing everything RT @Graham_D_C
Mainly email but getting better at spreadsheets etc, RT @IDGdan
Question of the day!
Does your smartphone replace your need for a laptop when on the move?