Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old December 6th, 2006, 06:27 AM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,210
Default Microsoft Issues Word Zero-Day Attack Alert

Quote:
Microsoft on Dec. 5 warned that an unpatched vulnerability in its Word software program is being used in targeted, zero-day attacks.

A security advisory from the Redmond, Wash., company said the flaw can be exploited if a user simply opens a rigged Word document.
Story
  #2  
Old December 6th, 2006, 09:34 AM
Mrkvonic Mrkvonic is offline
Linux Systems Expert
 
Join Date: May 2005
Posts: 7,433
Default Re: Microsoft Issues Word Zero-Day Attack Alert

Hello,
This is where OpenOffice comes into play.
Mrk
__________________
http://www.dedoimedo.com

All your base are belong to us

Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA
  #3  
Old December 6th, 2006, 09:58 AM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,210
Default Re: Microsoft Issues Word Zero-Day Attack Alert

In the meantime, keep your bases covered.

Secunia
  #4  
Old December 6th, 2006, 10:46 AM
NICK ADSL UK's Avatar
NICK ADSL UK NICK ADSL UK is offline
Administrator
 
Join Date: May 2003
Location: UK
Posts: 9,174
Default Re: Microsoft Issues Word Zero-Day Attack Alert

Microsoft Security Advisory (929433)
Vulnerability in Microsoft Word Could Allow Remote Code Execution

Microsoft is investigating a new report of limited “zero-day” attacks using a vulnerability in Microsoft Word 2000, Microsoft Word 2002, Microsoft Office Word 2003, Microsoft Word Viewer 2003, Microsoft Word 2004 for Mac, and Microsoft Word 2004 v. X for Mac, as well as Microsoft Works 2004, 2005, and 2006.

In order for this attack to be carried out, a user must first open a malicious Word file attached to an e-mail or otherwise provided to them by an attacker.

As a best practice, users should always exercise extreme caution when opening unsolicited attachments from both known and unknown sources.

Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs.

http://www.microsoft.com/technet/sec...ry/929433.mspx
__________________
Wilders
~Security Specialists~
Microsoft MVP - Consumer Security
  #5  
Old December 6th, 2006, 11:33 AM
Pedro's Avatar
Pedro Pedro is offline
Massive Poster
 
Join Date: Nov 2006
Posts: 3,492
Default Re: Microsoft Issues Word Zero-Day Attack Alert

Quote:
Originally Posted by Mrkvonic
Hello,
This is where OpenOffice comes into play.
Mrk

lol, MrK you never miss an opportunity
I guess you can't help it,
Someone
  #6  
Old December 6th, 2006, 12:10 PM
Rmus Rmus is offline
Exploit Analyst
 
Join Date: Mar 2005
Posts: 3,624
Default Re: Microsoft Issues Word Zero-Day Attack Alert

Assuming that this exploit is similar to the others, here is a description of what happens:

Microsoft Word 0-day Vulnerability FAQ - September 2006
http://blogs.securiteam.com/?p=586

Q: Are there any visual effects informing about the infection?
A: No.

Q: Are there any changes to file system made by related malware?
A: Yes. The file WINWORD.EXE is being dropped to the Windows %Systemroot% folder.

When the related worm activates it will drop the following files:
Windows\System32\clipbook.exe [30,720 bytes]
Windows\System32\clipbook.dll [33,713 bytes]
--------------------------------------------

Of course, no one would knowingly run such a .doc file

But in case of an inadvertant instance, such remote code execution is easily blocked from installing executables by many products today.

-rich


________________________________________________________________
"Talking About Security Can Lead To Anxiety, Panic, And Dread...
Or Cool Assessments, Common Sense And Practical Planning..."
--Bruce Schneier
  #7  
Old December 11th, 2006, 07:47 AM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,210
Default Re: Microsoft Issues Word Zero-Day Attack Alert

Second vulnerability .....
  #8  
Old December 14th, 2006, 02:47 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,210
Default Re: Microsoft Issues Word Zero-Day Attack Alert

Exploit Code Targets Third Microsoft Zero-Day Word Bug
Quote:
"Microsoft is investigating new public reports of a possible vulnerability in Microsoft Word [and] will continue to investigate the public reports to help provide additional guidance for customers as necessary," the spokesperson said in an e-mail. "Upon completion of this investigation, Microsoft will take appropriate action [which] may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs."
Story
  #9  
Old December 19th, 2006, 03:01 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,210
Default Re: Microsoft Issues Word Zero-Day Attack Alert

Exploit for Word also works with OpenOffice
Quote:
The exploit for the third unpatched security hole in Word reported last week also works in OpenOffice 2.1. If a prepared Word document is opened in OpenOffice Writer under Windows XP SP2, Writer crashes. The dialogue for document recovery then appears. Under Linux, the application also crashes, prompting the message that the main memory is full.
Story
  #10  
Old December 19th, 2006, 11:40 PM
Mrkvonic Mrkvonic is offline
Linux Systems Expert
 
Join Date: May 2005
Posts: 7,433
Default Re: Microsoft Issues Word Zero-Day Attack Alert

Hello,

But the second part of the article:

"It has not yet, however, been demonstrated that code can be injected via this weak point in OpenOffice. But there are unconfirmed reports that this is possible."

The program crash versus System infection ...

Mrk
__________________
http://www.dedoimedo.com

All your base are belong to us

Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:58 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums